Internal control
Also known as: Control activity, Mitigating control, Safeguard
A mechanism, policy, or procedure implemented by an organization to provide reasonable assurance that business objectives are achieved and risks are mitigated. These processes prevent errors, detect fraud, and ensure compliance with laws like GDPR or SOX. They can be manual, such as a physical signature on an invoice, or automated, such as a system-enforced password complexity requirement.
Why it matters
Without these checks, organizations face systemic failures like unauthorized data access or financial misstatement. An auditor discovering their absence concludes there is a "material weakness" in the control environment. Such gaps often result in regulatory fines from bodies like the SEC or the loss of an ISO 27001 certification. Ultimately, the Board of Directors and C-suite executives are held legally and professionally accountable for these failures.
In practice
During a compliance assessment, an external auditor reviews the Control Matrix to identify which checks exist for specific risks. They perform "walkthroughs" with system owners early in the engagement to observe the workflow in real time. Evidence requested typically includes screenshots of configurations, signed approval logs, or change request tickets from Jira. This process produces two primary artifacts: a Test of Design (ToD) and a Test of Effectiveness (ToE). In first-year engagements, auditors focus heavily on documenting how the control is structured; in repeat years, they prioritize verifying that it operated consistently throughout the entire audit period.
Worked example
FinTechFlow Inc. implemented a "Four Eyes" review policy for all wire transfers exceeding $10,000 to prevent internal fraud. During a 2023 year-end audit, the auditor requested a sample of 25 high-value transactions from January to December. They found that in three instances, the same user initiated and approved the transfer because they held dual permissions. This was flagged as a control failure due to lack of segregation of duties. The result was a "qualified" audit opinion requiring FinTechFlow to rewrite their Access Control Policy by Q1 2024.
Common mistakes
- Confusing a policy with a control; stating that employees "should be honest" is a goal, not a verifiable check.
- Relying on verbal confirmation instead of documented evidence, which provides no audit trail for the reviewer.
- Implementing controls that are too rigid, leading staff to create unofficial "workarounds" that bypass security entirely.
- Failing to update the process after a system migration, leaving a gap where the old manual check is irrelevant to the new software.
Frequently asked questions
What is the difference between a preventive and detective control?
Preventive controls stop an error before it happens, such as requiring a password to access a database. Detective controls find errors after they occur, such as a monthly bank reconciliation report that flags discrepancies.
How does an internal control differ from a policy?
A policy is a high-level statement of intent or rule, whereas a control is the specific action taken to enforce that rule. For example, a "Password Policy" says passwords must be complex; the "Control" is the system setting that rejects simple passwords.
How do I design an effective internal control?
Start by identifying the risk you want to mitigate and then create a repeatable step that produces evidence. Ensure there is a clear owner responsible for performing the check and a designated reviewer to verify it.
What counts as valid evidence for a control test?
Valid evidence must be objective and timestamped, such as system-generated logs, signed PDFs, or ticket history in ServiceNow. Screenshots are acceptable if they show both the configuration setting and the date of capture.
When should internal controls be tested during the year?
While many organizations test at year-end, "interim testing" performed mid-year is more effective. This allows management to remediate gaps before the final external audit begins.
More terms
Material weakness · Readiness assessment · CE marking · SOC 1 · Subprocessor · Sampling · Products with digital elements · Going concern