Effective internal controls do more than satisfy auditors. They help organizations reduce risk, improve financial reporting, strengthen compliance, ensure critical processes operate consistently, deter fraud, and create accountability across operations. For state and local governments and nonprofits, well-designed controls also make audits and internal control assessments more efficient because organizations can clearly demonstrate that key risks are being managed.
The difference lies in design. Effective controls begin with identified risks, are written clearly enough to be performed consistently, and are supported by documentation that demonstrates what occurred. Organizations that take this approach often strengthen day-to-day operations while avoiding common control deficiencies.
This article outlines practical strategies for designing, documenting and evaluating internal controls that improve operations and better prepare organizations for audits and internal control assessments.
Start with the risk
Effective controls should be designed around risk, not around existing processes or a checklist of control activities. The first question should always be: What could go wrong?
For example, during invoice processing, one risk is that an invoice could be paid without proper approval, resulting in an unauthorized or fraudulent payment. Once that risk is identified, organizations can implement controls such as:
- System-based approval workflows
- Three-way invoice matching
- Periodic reviews of payment activity
These controls directly address the identified risk rather than simply adding review steps.
Being specific about risk also improves control design. Consider these two risk statements:
- “The invoice is not approved before payment.”
- “An invoice is paid without documented approval from an authorized individual confirming that the goods or services were received, the amount is accurate and the payment is appropriate.”
The second statement provides enough detail to design a targeted, repeatable control.
Organizations should also avoid assuming every process already contains effective controls. A process describes what gets done. A control explains how the organization verifies that the process was completed correctly, consistently and in accordance with policy. Controls that are not tied to a specific risk often become unnecessary, difficult to perform consistently or provide a false sense of assurance.
Write controls that are clear and testable
Once risks have been identified, control descriptions should clearly explain how those risks are mitigated.
Vague statements such as:
- “Management reviews activity.”
- “Finance checks for accuracy.”
- “Approved as needed.”
provide little guidance and are difficult to evaluate because they do not explain:
- Who performs the control
- What is reviewed
- How often it occurs
- What information is used
- What review criteria are applied
- Where evidence is retained
- How exceptions are documented and resolved
Instead, control descriptions should answer each of those questions.
For example, another weak control statement is: “The grant reimbursement is reviewed before submission.”
A stronger version is: “Each month, the Grants Manager compares the reimbursement request to the approved grant budget, supporting invoices and allowable cost criteria. Exceptions are documented in a tracker and resolved before submission. The signed checklist and reimbursement package are retained in the grant file.”
This version clearly identifies the responsible individual, review procedures, supporting documentation, exception handling and evidence retention, making the control easier to perform consistently and easier to test.
Document controls so the evidence stands on its own
Organizations often perform controls but cannot demonstrate that they occurred because documentation is incomplete. Documentation should allow someone unfamiliar with the process — including an auditor — to understand exactly what happened without relying on verbal explanations.
Strong documentation answers five questions:
- Who performed and reviewed the control?
- When was it performed and what period did it cover?
- What transactions, reports or reconciliations were reviewed?
- What criteria were applied?
- How were exceptions identified and resolved?
Documentation should also be supported by current policies and procedures so controls can be performed consistently despite staffing changes or turnover. For example, a signature indicating approval rarely provides sufficient evidence by itself. Documentation should identify what was reviewed, the criteria used and how any exceptions were addressed.
Continuously monitor controls to ensure they remain effective
Even well-designed controls can become ineffective over time if they are not periodically evaluated. Organizations often heavily invest in designing and documenting controls, then assume they will remain effective indefinitely. Personnel changes, system upgrades, evolving business processes and competing priorities can all weaken a control that once functioned as intended.
A useful way to think about internal controls is to compare them to a gate protecting a staircase. When the gate is first installed, you may give it a quick shake to ensure it is secure. Over time, however, continued use affects its reliability. Internal controls require the same mindset. Organizations should periodically “jiggle the gate” by performing monitoring activities, walkthroughs, control self-assessments or targeted testing to confirm controls continue to operate as designed.
Effective control environments require ongoing verification as risks, processes and personnel evolve.
Address common control gaps
Organizations can strengthen their control environment by proactively addressing common weaknesses before they become audit findings.
Frequently observed gaps include:
- Vague control descriptions.
- Unclear ownership and accountability.
- Undefined control frequency.
- Missing review criteria.
- No documentation of exceptions or corrective actions.
- Segregation of duties conflicts without compensating controls.
- Insufficient evidence supporting control performance.
- Outdated or undocumented procedures.
Many of these issues stem from inconsistent documentation rather than ineffective processes. Organizations may already be performing the right activities but have not clearly defined responsibilities, documented expectations or retained sufficient evidence. Addressing these gaps improves consistency, strengthens accountability and reduces surprises during audits and internal control assessments.
Prepare before the assessment begins
Organizations receive greater value from an internal control assessment when they prepare before fieldwork begins.
Preparation starts with understanding the assessment scope, including the programs, departments, grants or compliance requirements that will be reviewed. Organizations should also identify the appropriate process owners and ensure they can explain how controls operate in practice. Gathering documentation in advance — including policies, procedures, reconciliations, approvals, reports, organizational charts, system screenshots and prior audit findings — helps assessments proceed more efficiently.
Organizations should also communicate known issues early. Whether a process has changed, relies heavily on manual procedures or lacks documentation, discussing those circumstances upfront provides valuable context and allows the assessment to focus on the highest risks.
During interviews and walkthroughs, process owners should be prepared to explain:
- Who performs each control
- Who reviews it
- How often it occurs
- What information is used
- What evidence is retained
- How exceptions are identified and resolved
The most valuable assessments are collaborative discussions about risk management, operational effectiveness and opportunities for improvement, not simply document collection exercises.
The bottom line
Effective internal controls should strengthen operations, not create unnecessary work.
Organizations achieve the greatest value when controls are designed around identified risks, written clearly enough to be performed consistently, supported by sufficient documentation and evaluated regularly for continued effectiveness.
When these elements are in place, state and local governments and nonprofits are better positioned to safeguard assets, improve financial reporting, support compliance, deter fraud and approach audits and internal control assessments with greater confidence.
Sikich’s Yellow Book Session #7, Designing and Documenting Effective Internal Controls, will explore these concepts in detail, plus much more. During the session, we will discuss what makes controls effective, how to practically connect controls to risks, and how to document controls in a way that stands up to testing.
Join us on August 19 for a practical discussion on building internal controls that work in the real world.
About our authors
Jesse Laseman, MAS, CIA, CRMA, CFE, is an Internal Audit Manager on the Governance, Risk and Compliance (GRC) team. He has experience executing audit engagements in industries such as financial services, government, nonprofit and professional services. His expertise includes operational audits, data analysis and interpretation, internal control testing, and the development and implementation of internal control recommendations. Jesse.laseman@sikich.com
Steve Randall, MBA, is a senior executive and governance, risk, and compliance leader with more than 30 years of experience advising boards of directors, audit committees, and executive management on enterprise risk, corporate governance, internal audit, regulatory compliance, financial controls, cybersecurity, and emerging technologies. He is a recognized thought leader and frequent speaker on risk, governance, and organizational performance, and is passionate about helping organizations strengthen resilience, enhance accountability, and achieve sustainable growth. Steve.randall@sikich.com
Tim Leitz, CIA, CRMA, leads the GRC team. He has more than 25 years of experience in internal audit, enterprise risk management, regulatory compliance, and process improvement. As a former CAE of a $6B healthcare organization, Tim has built best-practice audit functions, is a national speaker, and a subject-matter expert. Tim.leitz@sikich.com
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.