Most small business owners already have some version of internal controls in place. They just don’t call them that. If you personally sign every check above a certain dollar amount, that’s a control. If your bookkeeper can enter a bill but can’t approve it, that’s a control. Internal controls are the policies and procedures a company uses to protect its assets, produce reliable financial information, and stay compliant with the rules and regulations that apply to its business and industry.
What Are Internal Controls?
Even a well-designed system provides reasonable assurance, not a guarantee — controls are built and operated by people, and people make mistakes, take shortcuts, and occasionally collude. The goal isn’t a perfect system, but a system where errors are either prevented or caught quickly, and where no single person can both create a transaction and conceal it. Controls can be either preventive or detective in nature. Preventive controls exist to prevent errors or fraud before they happen, and detective controls serve to find them after the fact. A properly designed control system employs both types.
Why Internal Controls Matter
The Association of Certified Fraud Examiners studies thousands of occupational fraud cases every two years. Its 2026 report1 puts the median loss at $104,000 per case, with the typical scheme running about 12 months before anyone catches it. The most relevant finding for a small accounting department: more than half of all cases involved either a lack of internal controls or an override of the controls that did exist. Fraud is rarely sophisticated. It usually just goes unnoticed, because the person who could have noticed it was the person doing it.
But fraud is only the headline. Controls also determine whether you can trust your own numbers. Is management making operational decisions using inaccurate financial information? Control weaknesses tend to surface at the worst possible moments: when a lender asks how disbursements are approved, when an insurer asks about payment verification procedures, or when a buyer’s diligence team starts asking questions you can’t answer quickly. Additionally, good controls protect honest employees, by making sure that when something does go wrong, no one has to wonder who was responsible.
Basic Controls Every Accounting Department Should Have
The foundational principle is segregation of duties: the person who authorizes a transaction shouldn’t also be the same person who disburses the cash, records it in the books, or reconciles the account afterward. Many small businesses don’t have the headcount to adequately segregate these functions. The answer isn’t to pretend otherwise; it’s to accept that certain duties can’t be fully separated and to build compensating controls around the gap — most often, direct owner involvement at the points where a second set of eyes is missing. In practice, that means:
Bank Reconciliations (detective control): If no one else at an appropriate level is available to review the work of the person preparing the bank reconciliation, then the owner should personally review each month’s bank reconciliations. Pull the bank statement directly from the bank website rather than accepting a copy — if it passes through the person you’re checking on first, you’re reviewing a document they had the opportunity to change. Look closely at the disbursements and the payees, watching for names you don’t recognize, checks you didn’t approve, and amounts sitting just below your threshold. This control should be non-negotiable for all small and large businesses.
Cash Controls (preventive control): Every cash disbursement, unless it’s a trivial amount (for example, $15), should require approval from a second authorized person before it goes out. No single employee should be able to sign and issue a check or send an ACH or wire transfer without receiving the appropriate approval. Limit access to the company’s bank accounts to a select few employees (for example, the Owner and the CFO or Controller if the company has one). Any blank check stocks should be locked away and accounted for.
Positive Pay (preventive control): Positive pay involves sending your bank a list of approved, issued checks on an ongoing basis. When a check is presented to the bank by a payee, the bank compares the check to the check list provided by the company. If the check is not on the list or contains discrepancies, the company has the opportunity, usually within 12–24 hours, to reject the check. This same protection can be extended to digital payments, such as an ACH. This control helps prevent counterfeiting and the cashing of unauthorized checks.
Vendor and Payroll Controls (preventive control): Whenever a new vendor or employee is added to the system, or an existing record is changed, it should require approval from the owner (or CFO, if the company has one). This prevents any one person from creating a payee that only they know about, effectively reducing the likelihood of vendor and payroll fraud. Before approving a new vendor or a change to an existing one, confirm the details — banking information above all — by contacting the vendor directly. Before each payroll is disbursed, review the corresponding payroll report. Confirm that you recognize every name on it, that the pay amounts match what you approved, and that the total agrees with the cash going out for the period.
Systems Access (preventive control): Employees should have access only to the systems necessary for performing their jobs, and only at the level their role requires. An employee in the HR department shouldn’t have access to the company’s accounting systems, and accounting employees shouldn’t have access to the company’s HR database of employee records. Each employee should have their own log-in credentials, and upon termination of employment those credentials should be revoked immediately to prevent any future access to the company’s systems. Current NIST guidance (SP 800-63B, Revision 4)2 advises against forcing routine password changes on a fixed schedule, directing instead that a password be changed when there is evidence it has been compromised. Favor longer passwords over complex ones, and enable multi-factor authentication on your banking and accounting systems.
Expense Reimbursement (preventive control): Put your expense policy in writing and communicate it periodically to your employees: what’s reimbursable, what documentation is required, who approves, and when employees are reimbursed. Every reimbursement should be reviewed and approved before payment by someone other than the person requesting it, with an itemized receipt attached. The same applies to company credit cards. Review the statement monthly against itemized receipts instead of just approving the total. Watch for non-recurring items, expenses that sit just under the stated threshold, and anything that looks abnormal. This process should occur regularly, and can be implemented as part of your company’s month-end financial close.
Financial Close (detective control): This control process should occur monthly and at year-end. The financial close involves updating the accounting records and making sure the books are complete and accurate. As part of this process, all significant balance sheet accounts should be reconciled to supporting documentation, a month-over-month analysis performed to identify unexpected movements, and the period locked down after final approval from the owner (or CFO, if the company has one). Best practice is to close the books within 7 to 10 days after month-end. Year-end will likely take longer — 14 to 21 days.
Assessing Your Company’s Control Environment
Most small businesses don’t have written control policies to review, and the ones that do often find that the document describes a company they no longer are. The first step is to identify the controls you do have in place and document them in detail. This is often called a process narrative. If your company has already documented its control procedures, then review that documentation to see whether it is actually up to date and being followed. The most direct way is to trace a transaction from its origin to the point it’s recorded in the company’s books. Were the controls related to this transaction operating as they should (e.g., second-level review)? Are relevant controls missing (e.g., approval)? Pay particular attention to the difference between the control process you designed and the process that runs today. Controls not only have to be properly designed; they also have to be implemented and maintained to be effective.
After assessing your controls and identifying the weaknesses, it’s important to take corrective action. In accounting terms, controls that are improperly designed, never implemented, or missing altogether are referred to as control deficiencies. Once you’ve identified them, design and implement either an updated control or a new one to address each deficiency. Reassess your control environment periodically as well, to confirm the system you have is still working as intended — businesses change, and controls that fit last year may not fit now.
Key Takeaways
-
Internal controls are the foundation for producing reliable financial information and safeguarding company assets. Every company should have a basic set properly designed and implemented (e.g., bank reconciliations, cash controls, systems access controls).
-
If headcount makes true segregation of duties impossible, the owner should step in and perform their own review. This is a compensating control.
-
Document how each process actually works today in a process narrative, and give the employees who perform the work access to it.
-
Periodically reassess your company’s control environment to ensure existing controls are actually being followed and are still sufficient, as businesses evolve over time.
-
Take corrective action when control deficiencies are identified, update your process narratives, and communicate all changes in procedures to everyone affected.
AsuraTrust offers internal controls consulting services for small businesses looking for professional assistance in designing, documenting, and implementing an effective and efficient control system within their company. If this type of service would benefit your company, we encourage you to set up a consultation with our Firm to discuss further.
References
- Association of Certified Fraud Examiners. Occupational Fraud 2026: A Report to the Nations. acfe.com/fraud-resources/report-to-the-nations. ↩
- National Institute of Standards and Technology. Digital Identity Guidelines: Authentication and Authenticator Management, NIST SP 800-63B-4 (July 31, 2025). csrc.nist.gov. ↩
