Chapter 6: Internal Control Processes
This chapter explains what internal control is, why it exists, and how organizations design, implement, and
evaluate it. The central message is that internal control is not merely about preventing fraud—it is the entire
system that helps an organization achieve its objectives efficiently, legally, and reliably.
I. The Concept of Internal Control
What is Internal Control?
Internal control refers to the processes established by management, overseen by the board, and performed by
employees to provide reasonable assurance that organizational objectives will be achieved.
Unlike external control (owners, regulators, auditors), internal control comes from within the organization.
Simple Illustration
BOARD
↓
Management
↓
Employees
↓
Business Processes
↓
Achievement of Objectives
Internal control therefore involves everyone, not only accountants or auditors.
II. Evolution of Internal Control
The concept has evolved significantly over time.
Period Focus
Early years Internal check (cross-checking work)
AICPA (1948) Safeguarding assets and accounting records
COSO (1992) Entire management process supporting organizational objectives
COSO ERM (2004) Integrated internal control with enterprise risk management
Earlier definitions focused mainly on financial records, while modern definitions encompass operations,
compliance, governance, risk management, ethics, and organizational culture.
III. Committee of Sponsoring Organizations of the
Treadway Commission (COSO) Framework
COSO was formed by five major professional organizations to sponsor the Treadway Commission's work and later
developed the widely used COSO Internal Control – Integrated Framework (1992) and the Enterprise Risk
Management (ERM) Framework.
The Five Sponsoring Organizations
1. American Accounting Association (AAA)
2. American Institute of Certified Public Accountants (AICPA)
3. Financial Executives International (FEI)
4. Institute of Internal Auditors (IIA)
5. Institute of Management Accountants (IMA)
The Treadway Commission refers to the National Commission on Fraudulent Financial Reporting, which was
established in 1985 to study the causes of fraudulent financial reporting and recommend improvements in corporate
governance, internal control, and financial reporting.
The COSO Framework is the most widely accepted internal control framework worldwide and serves as the basis
for most auditing standards.
COSO - Internal control is a process designed to provide reasonable assurance regarding:
1. Effectiveness and efficiency of operations
2. Reliability of financial reporting
3. Compliance with laws and regulations
IV. Reasonable Assurance
One of the most tested concepts in auditing.
Reasonable assurance does not mean absolute assurance.
No internal control system can eliminate every risk because:
• Human error exists.
• Fraud and collusion can occur.
• Circumstances change.
• External events cannot always be controlled.
Instead, controls should reduce risk to an acceptable level.
Example
A cashier counts cash daily.
Does this guarantee zero theft?
No.
It only provides reasonable assurance that shortages will be detected quickly.
V. Responsibilities for Internal Control
Party Responsibility
Board of Directors Oversees internal control
Management Designs, implements, and maintains controls
Employees Perform the controls
Internal control is everyone's responsibility—not only the internal auditor.
VI. The Five COSO Components (Most Important)
These five components are the foundation of almost every audit.
CONTROL ENVIRONMENT
↓
RISK ASSESSMENT
↓
CONTROL ACTIVITIES
↓
INFORMATION &
COMMUNICATION
↓
MONITORING
1. Control Environment
Often called the foundation of internal control, it represents the organization’s:
• ethics
• integrity
• leadership
• culture
• organizational structure
• accountability
A weak control environment weakens every other component.
Example
If top management ignores company policies, employees will likely ignore them too.
This is called "tone at the top."
2. Risk Assessment
Organizations must identify and evaluate risks before they can control them.
Risk assessment involves:
• identifying risks
• analyzing likelihood and impact
• prioritizing risks
• determining responses
Risk assessment is continuous because risks change over time.
Example
A university begins accepting online payments.
New risks include:
• hacking
• fake receipts
• duplicate transactions
New controls must therefore be designed.
3. Control Activities
These are the actual control procedures.
Examples include:
• approvals
• reconciliations
• segregation of duties
• physical safeguards
• password controls
• reviews
• authorizations
Policies tell people what should happen, while procedures explain how it should happen.
4. Information and Communication
Good decisions require good information.
Information must be:
• accurate
• complete
• timely
• relevant
• communicated to the correct people
Communication flows:
• upward
• downward
• horizontally
• externally
Poor communication weakens internal control.
5. Monitoring
Monitoring ensures that controls continue to operate effectively.
Methods include:
• management review
• internal audit
• audit committee oversight
• control self-assessment
• follow-up of deficiencies
Monitoring also determines whether controls remain appropriate as conditions change.
VII. Other Internal Control Frameworks
Although COSO dominates globally, several alternative frameworks exist.
Main Emphasis
Framework
COSO Comprehensive internal control
Turnbull Risk management and board responsibility
CoCo Human behaviour and organizational culture
Turnbull
Developed in the UK.
Places stronger emphasis on:
• board responsibility
• risk management
• annual review of controls
It is very similar to COSO but is less detailed.
CoCo Framework
Developed in Canada.
Focuses more on people than procedures.
Its four components are:
Purpose
Commitment
Capability
Monitoring & Learning
Unlike COSO, CoCo emphasizes employee behavior, commitment, and learning.
VIII. Systems (Cybernetics) Model
This model views internal control like a machine that constantly compares actual performance with desired
performance and makes corrections when necessary.
Example
Thermostat analogy
Desired Temperature
↓
Measure Actual Temperature
↓
Compare
↓
Difference?
YES
↓
Air conditioner turns ON
Business controls work similarly.
➢ Management compares:
➢ Actual sales vs Budget
➢ Actual expenses vs Budget
➢ Actual inventory vs Records and makes corrective action.
IX. Control by Division (Segregation of Duties)
One of the simplest yet most effective control concepts is dividing responsibilities so no single person controls an
entire transaction.
Important divisions include:
Division Purpose
Duties Cross-check work
Authorization Separate approval from execution
Custody Separate asset custody from accounting
Operations Separate conflicting functions
Data Restrict access rights
Authority Multiple approvals
Time Delays and after-the-fact approvals
Classic Example
Purchasing Officer
↓
Orders goods
Receiving Officer
↓
Receives goods
Accounting
↓
Records transaction
Cashier
↓
Pays supplier
No single employee controls the entire process.
X. Categories of Controls
The chapter classifies controls according to their purpose.
Type Purpose Example
Preventive Prevent problems Segregation of duties
Pre-emptive Approval before action Purchase approval
Directive Ensure required action Safety rules
Performance Encourage objectives Productivity targets
Detective Discover problems Bank reconciliation
Corrective Fix problems Disaster recovery
Investigative Determine causes Fraud investigation
Easy Memory Trick
Before → During → After
Preventive → stops problems
Detective → finds problems
Corrective → fixes problems
These three are the most commonly tested.
XI. Objectives of Internal Control
Different organizations classify objectives differently, but they all pursue the same overall goal: helping the
organization achieve its objectives.
The most widely accepted objectives (COSO) are:
Meaning
Objective
Operations Efficient and effective operations
Financial Reporting Reliable financial information
Compliance Obey laws and regulations
Other frameworks may additionally include safeguarding assets, governance, or risk management, but these are
essentially different ways of organizing the same objectives.