Internal control is not about stopping work with excessive approvals. It reduces the likelihood or impact of error, misuse or uninformed decisions to an accepted level while keeping the workflow practical and reviewable.
When staffing limits separation of duties
One employee can create a supplier, change bank details, approve an invoice and execute payment. Another signature on a monthly report does not directly address this concentration of authority. Separating beneficiary changes from transfer approval makes an incorrect payment more likely to receive independent scrutiny.
Some businesses lack enough staff to separate every task. The owner could instead review new beneficiaries and bank-detail changes before payment, comparing the transfer list with approved invoices. A compensating review needs evidence and sufficient detail: a quick signature against the batch total cannot reveal a changed account number.
In sales, examine cancellations, unusually large discounts and cash refunds. An exception is not automatically misconduct, but patterns by user, time and product can identify issues worth investigating. Warehouse transfers are another vulnerable point when the sender can also confirm receipt without verification at the destination.
Test each control with a practical question: if the error occurred tomorrow, who would see it, when and using which document? “We hope the accountant notices” is not a defined procedure. Give legitimate exceptions an authorised route as well, so ordinary work does not lead to shared passwords or routine use of an all-powerful account.
Control where a loss can occur
A control may prevent, such as restricting supplier bank changes; detect, such as a change report; or correct through a resolution route. Separating creation, approval and payment helps, while small teams may need documented compensating review.
A valid permission can be misused when nobody reviews context. A cashier may legitimately issue refunds, but repeated refunds without returned goods deserve investigation. Connect the financial movement to return evidence, assign approval for exceptions and examine their pattern rather than treating user permissions as sufficient assurance.
Controls that fit daily operations
- Identify priority risks and the outcome to prevent or detect.
- Give each risk a control, owner, frequency and evidence.
- Test overrides, emergencies and who reviews them.
- Review effectiveness and update when the process changes.
What makes an alert useful?
Sending every transaction to every manager often means none receives attention. Choose specific events: a new beneficiary before payment, a discount beyond a user's limit or a change affecting a closed period. Assign a reviewer, response time and evidence of resolution.
Review alert quality after launch. Excessive low-value warnings weaken attention, while very high thresholds can miss repeated small amounts with a large combined effect. Consider both value and frequency. Test a known example to establish that the control actually detects it rather than relying on an enabled setting as proof of effectiveness.
Sources & further reading
Visit the original source to explore the concept and its wider context.
General educational content. Appropriate treatment depends on your business and accounting policies; consult your accounting professional when applying it to business records.

