The topic of internal controls in an organization might seem to be one that needs no introduction or explanation. Having an internal controls policy becomes an integral part of both managing risk and meeting compliance requirements in our fast-paced business world that is constantly looking for an edge.
The definition of internal controls as defined by COSO is
“a process, effected by an entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance.”
As an aside, this Substack publishes articles on the pursuit of business opportunity through the lens of risk governance. Likewise, the COSO Internal Controls Framework was started to drive thought leadership on these topics:
Improve organizational performance and governance
Internal controls, risk management and fraud deterrence
Part of the challenge of implementing and sustaining an internal control environment at an organization is the concept of control, the fear of being controlled, or perhaps, the fear of suppressing the collective creative and entrepreneurial spirit to solve problems. After all, humans are drawn toward freedom and autonomy, and often great work comes from that environment. While we tend to strive for freedom and independence in a wide variety of settings (i.e., like political, religious), the reality is that no system functions without boundaries or governance.
Absolute freedom to operate within the business as leaders and employees see fit can lead to operational issues related to consistency, productivity and quality which result in how the market perceives and ultimately trusts the company. In an organizational context, internal controls are the mechanisms that enforce those boundaries to make operations sustainable and trustworthy by channeling individual freedom and accountability into collective reliability.
To be clear, there are certainly forms and levels of control that are burdensome in nature and counter productive to the goals and benefits of operating a business in a controlled manner.
Autonomy without constraint leads to chaos - When individuals operate with full autonomy but without shared standards or boundaries, business outcomes become inconsistent and unpredictable.
Autonomy with constraint leads to order - When individuals are empowered to act, but within clearly defined structures and aligned behavior, business outcomes become consistent and scalable outcomes lead to greater efficiency and market trust.
According to a 2024 Association of Certified Fraud Examiners (ACFE) report, over 50% of occupational frauds are caused by lack of internal controls or management override of an existing control. These situations, combined with extreme management or market pressure to perform, can create a motive for fraud on the part of an employee; essentially creating two sides (opportunity, pressure) of the fraud triangle. All that is left is the rationalization of the employee to feel like they have no choice or are entitled to the fraudulent activity.
The COSO framework defines five key principles or components that an effective internal control program should have:
Control Environment - Establishes the basis for internal controls through organizational structure, assignment of authority and responsibility, and the application of appropriate policy and procedures that are aligned to ethics, integrity and company values.
Risk Assessment - Requires that organizational objectives be established with risks identified to achieve these objectives assessed against the operating environment and the organization’s risk appetite with appropriate controls put in place to effectively mitigate these risks.
Control Activities - Development of controls that ensure policies and management directives pertaining to risk mitigation are designed, in place, and operating as expected to protect the integrity of the business process.
Information and Communication - Clearly articulating control activity responsibility in terms of design, ownership, and execution of the control along with timely distribution of financial and operational data that is complete and accurate.
Monitoring Activities - Processes put in place to determine the adequacy and effectiveness of the internal control system over time through a variety of parties’ independent review of the process.
The Three Lines Model is a practical and accepted model for the assignment of responsibility when it comes to the design, implementation, execution, monitoring and independent testing of an individual control in the context of an internal controls system.
2nd Line Function - Designs and implements controls to mitigate risks to the business process operating effectively.
1st Line Function - Executes the control within the business process as the 2nd Line Function designed and implemented.
2nd Line Function - Monitors that the control has been executed as designed and implemented.
3rd Line Function - An independent function, generally Internal Audit, that tests to ensure that the controls defined by management are designed and operating effectively.
Explore the Three Lines Model in more detail in the Revisiting the IIA’s Three Lines Model article.
The Internal Control policy and the program behind it can be stood up and communicated by a compliance or finance function looking to stay compliant (with say SOX requirements), but it really has to be owned, understood and executed by the leadership of the organization as each of the five COSO components noted above rely on the participation of the leadership team.
Executive and operational leaders have an immense responsibility and influence on the success of a business process operating in a controlled manner. Beyond their personal approach to supporting the internal control environment, leaders should ensure the following activities are in place and keeping up with the life of the business.
Process Documentation - Ensure business processes are documented in updated flowcharts and/or narratives.
Risk Assessment - Identify and understand the risks associated with the business process not operating effectively in relation to meeting the objectives of the organization.
Risk and Control Matrix - A spreadsheet or software tool that captures a list of business processes, key risks and the controls put in place to mitigate risk.
Organizations should also consider the following concepts in designing, standing up and operating an Internal Control program:
Define individual employee responsibility in performing their duties in accordance with any established internal control policies and procedures.
Identify and include key outsourced business process and software in the documentation of business processes, risks, and controls and determine how you will compel or otherwise satisfy evidence that the process is also operated in a way that is consistent with your business process, contractual and regulatory obligations.
Determine how joint ventures entered into by the organization will stand up an internal controls program that will effectively design, implement, execute, monitor, and report as needed to support contractual and regulatory obligations.
Determine how merger, acquisition, or divestiture agreements entered into by the organization will consider internal controls that will effectively design, implement, execute, monitor, and report as needed to support contractual and regulatory obligations of the resulting entities.
Does your organization have an internal controls policy that defines an expectation and assigned responsibility of operating the business in a controlled manner?
Does your organization perform a periodic risk assessment?
Does your organization maintain a risk and control matrix that identifies key risks to the business and the controls implemented to mitigate the risk?
What is the biggest challenge to your organization in implementing or maintaining internal controls?
Would you like to discuss this topic further? Contact Brian Howell from Crestview.io
Find this article helpful? Thank you for sharing Risk Governance by Crestview.io with others!
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.