Internal control failures, fraud and errors
What internal controls are
- Internal controls are the checks a business builds into its own processes to prevent errors and fraud, and to make sure its records are accurate.
- They are internal operations doing a defensive job — and when they fail, the consequences reach the whole business.
The main controls
Separation of duties.
- The person who orders goods should not be the person who receives them, who should not be the person who pays for them.
- Fraud usually requires one person to control a whole cycle. Splitting the cycle means it takes collusion, which is far rarer.
Authorisation limits.
- Spending above a set amount requires a second signature or manager approval.
Reconciliation.
- Bank statements are matched against the business's own records regularly, and differences are investigated.
- Stock counts are matched against system records.
Access controls.
- Only the people who need access to a system, a till or a stockroom have it, and access is removed when someone changes role or leaves.
Audit.
- Internal audit — the business checks itself. External audit — an independent accountant checks the financial statements.
- Even the possibility of a check changes behaviour.
Documentation.
- Every transaction supported by an order, an invoice and a receipt, so the record can be traced.
How control failures become critical
- Direct loss of money. Fraud can run for years before discovery, and the amount taken is often far larger than the business expected.
- Decisions made on wrong numbers. Errors mean management plans with inaccurate figures — pricing, budgeting and investment decisions are all made wrongly.
- Loss of trust. Banks, investors and large customers rely on the business's financial information; if it proves unreliable, credit terms tighten and contracts are re-examined.
- Reputation. A publicised fraud damages the brand and unsettles staff, who wonder who else was involved.
- Staff morale. Honest employees resent both the fraud and the intrusive controls that arrive afterwards.
- Legal exposure. Directors have obligations regarding proper accounting records; serious failures can have personal consequences.
Solutions
- Separate duties, especially around ordering, receiving, paying and reconciling.
- Require dual authorisation for payments over a threshold.
- Reconcile frequently — monthly at minimum, and investigate every difference rather than writing small ones off.
- Rotate duties and require staff to take leave, because ongoing frauds usually need the perpetrator present to maintain them.
- Restrict and review system access, and remove it immediately when someone leaves.
- Use an external audit or an independent review, which brings a professional eye and is a deterrent in itself.
- Provide a way to report concerns confidentially, since most frauds are discovered through a tip-off rather than an audit.
- Balance cost against risk — a control that costs more than the loss it prevents is not worth having, and in a small team perfect separation of duties may be impossible, in which case owner review substitutes for it.