Internal Control for Growing Businesses Using the COSO Framework
Published Sep 1, 2026
For many growing businesses, internal control starts informally. The owner reviews the bank account, a bookkeeper enters transactions, payroll is processed through an outside platform, bills are approved by email, customer payments are deposited electronically, and financial statements are reviewed at the end of the month. That may work when the business is small, but as the company grows, the financial environment becomes more complicated.
As an organization grows, its financial environment may include multiple bank accounts, credit cards, employees, payroll systems, payment platforms, accounting applications, approval workflows, remote users, automated integrations, and increasingly AI assisted processes. This increased complexity requires management to establish clear responsibility for sensitive activities such as vendor creation and maintenance, changes to banking information, payment authorization, payroll changes, journal entry posting, and user access administration. Effective internal control also requires defined review procedures for bank reconciliations, exception investigation, and the ongoing evaluation of automated accounting processes to determine whether they continue to operate as intended.
These are internal control questions. Internal control is sometimes reduced to requiring two signatures on a check or separating certain accounting duties. Those may be controls, but they are not the entire system. A well designed system of internal control considers how people, responsibilities, financial processes, technology, information, authorization, review, and monitoring work together to reduce risk.
The Committee of Sponsoring Organizations of the Treadway Commission, commonly known as COSO, provides one of the most widely recognized frameworks for organizing this process. COSO's Internal Control—Integrated Framework (“COSO Framework”) organizes internal control around five integrated components supported by 17 principles:
- Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring Activities
---
For a growing private business, the objective is not to recreate the internal control infrastructure of a Fortune 500 company. The objective is to establish a system appropriate to the organization's size, complexity, technology, personnel, and risks. Internal control also provides reasonable assurance rather than absolute assurance. People make mistakes, employees may collude, management can override procedures, technology can fail, and business conditions change. Controls are therefore intended to reduce significant risks to a reasonable level rather than guarantee that every error, fraud, or system failure will be prevented.
Management retains ultimate responsibility for internal control. An outsourced controller may assist in evaluating risks, designing procedures, monitoring control activities, identifying deficiencies, and recommending improvements. However, outsourcing the controller function does not transfer responsibility for the company’s accounting records, financial statements, significant assumptions and estimates, or the overall effectiveness of its internal control system.
This responsibility is made clear in the COSO Framework’s definition of internal control:
Internal control is a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives related to operations, reporting, and compliance.
With those foundational concepts established, the next step is to examine how internal control is structured in practice. The COSO Framework provides a useful model for doing so. Its five components provide a disciplined way to evaluate how a growing company establishes accountability, identifies risk, designs control procedures, communicates information, and monitors whether those controls continue to operate effectively.
CONTROL ENVIRONMENT
The control environment establishes the foundation for the entire internal control system.
It reflects the standards, expectations, and organizational practices that influence how internal control is understood and carried out throughout the company. Within this component, management establishes expectations for conduct, assigns authority and responsibility, develops competent personnel, provides appropriate oversight, and reinforces accountability. COSO’s five principles within the control environment address integrity and ethical values, oversight responsibility, organizational structure and authority, competence, and accountability.
Tone at the Top
The effectiveness of internal control is influenced significantly by management behavior. Formal policies may establish clear requirements, but those requirements can be undermined when management routinely disregards them in practice. For example, a company may require supporting documentation before significant payments are released. If the owner regularly instructs accounting personnel to issue payments first and obtain the documentation later, the weakness extends beyond a single unsupported transaction. Management has effectively communicated that established procedures may be bypassed when they become inconvenient.
Over time, this type of behavior can weaken the broader control environment. Similar problems arise when management routinely overrides approval limits, accepts incomplete reconciliations, permits unsupported accounting adjustments, or allows recurring exceptions to remain unresolved. The same concern exists when policies are enforced for employees but disregarded by senior management. These practices create inconsistent expectations and reduce the likelihood that employees will view internal control procedures as meaningful requirements.
Technology cannot compensate for this type of cultural weakness. Sophisticated accounting systems may restrict access, automate approvals, and create detailed audit trails, but their effectiveness still depends on management’s willingness to respect and enforce the controls embedded within them. A strong control environment therefore begins with consistent management behavior that demonstrates that established procedures apply throughout the organization, including to those with the greatest authority.
Responsibilities and Authority Should Be Clear
Small businesses can operate successfully for years with responsibilities that are understood informally rather than formally assigned. As an organization grows, however, increasing transaction volume, additional personnel, and more complex systems can make these informal arrangements a source of internal control risk. Statements such as “I thought someone else reviewed it,” “the bookkeeper normally handles that,” or “nobody told accounting about the change” often reflect an underlying weakness in the assignment and communication of responsibility.
A sound control environment establishes clear authority and accountability for important accounting and financial activities. Employees should understand not only the tasks they are expected to perform, but also the limits of their authority and the circumstances that require review or escalation. This includes responsibility for initiating and recording transactions, approving activity, performing reconciliations, safeguarding assets, reviewing results, and resolving exceptions. The objective is not to create unnecessary bureaucracy, but to ensure that important responsibilities are clearly assigned and understood throughout the organization.
Clear responsibility becomes particularly important when duties that should provide checks on one another are concentrated in a single individual. For example, an employee who can create a vendor, enter invoices, modify the vendor’s banking information, release payments, and subsequently reconcile the bank account controls nearly every stage of the transaction cycle. The resulting weakness extends beyond the absence of a single approval. The concentration of incompatible duties eliminates independent checks that might otherwise detect errors, unauthorized transactions, or fraudulent activity.
Competence Is Part of Internal Control
Effective internal control depends not only on properly designed procedures but also on the competence of the individuals responsible for carrying them out. Permissions, approvals, and review requirements have limited value when employees lack the knowledge necessary to recognize whether transactions have been recorded appropriately or whether financial information is reasonable.
This risk can arise in several forms. A bookkeeper who lacks sufficient knowledge of accrual accounting may record transactions incorrectly even while following established procedures. An employee responsible for reviewing financial information may fail to recognize unusual balances or relationships that warrant investigation. Similarly, a system administrator may alter an accounting workflow or automated process without understanding how the change affects transaction processing, financial reporting, or existing controls.
For this reason, checklists and documented procedures cannot substitute for appropriate accounting and operational knowledge. Competence should be considered when employees are hired, responsibilities are reassigned, new systems or automated processes are implemented, and the organization encounters increasingly complex accounting matters. As the business evolves, the knowledge and capabilities of the individuals responsible for financial processes must develop with it.
Accountability Makes Controls Real
A control is effective only when it operates as intended. Written policies and documented procedures provide structure, but they do not by themselves establish that a control is functioning. For example, a company may require bank reconciliations to be completed by the tenth business day of each month. If those reconciliations are routinely delayed until month end and the delays are neither identified nor addressed, the control exists in form but not in effective operation.
Accountability helps bridge the gap between documented expectations and actual performance. Management should establish clear expectations for the timely completion of control activities and should identify instances in which those expectations are not met. When a control is missed or performed late, the response should extend beyond simply reminding the responsible employee to complete the task.
Recurring control failures may indicate a broader weakness in the underlying process. Repeated delays, incomplete reviews, or unresolved exceptions can signal that responsibilities are unclear, staffing is insufficient, deadlines are unrealistic, or the control itself has been poorly designed. Effective accountability therefore includes not only addressing individual failures, but also determining whether persistent problems require changes to the process, the assignment of responsibility, or the design of the control itself.
RISK ASSESSMENT
Risk assessment asks what could prevent the organization from achieving its objectives. COSO's principles within this component address establishing suitable objectives, identifying and analyzing risks, considering fraud risk, and identifying significant changes that may affect the internal control system.
Controls should not be created randomly. They should respond to identifiable risks.
A useful way to think about the process is:
Objective → Risk → Control
If the objective is to pay only legitimate vendors, one risk is that a fictitious vendor could be created. A possible response is independent approval of new vendors before payments can be made. If the objective is to pay employees only authorized compensation, risks might include fictitious employees, unauthorized raises, diverted direct deposits, or terminated employees continuing to receive payroll.
This risk based approach is substantially more useful than simply collecting procedures because "good companies have controls."
Objectives Must Be Understood First
A company cannot meaningfully assess risk without understanding what it is trying to accomplish. Accounting and financial reporting objectives may include recording all material liabilities, issuing only authorized payments, recording revenue in the appropriate period, paying only valid employees, supporting balance sheet accounts, applying accounting policies consistently, and producing financial information within a defined timetable.
Once the objective is clear, management can identify the circumstances that could prevent it from being achieved.
Fraud Risk Requires Separate Consideration
Fraud prevention is not the sole purpose of internal control, but fraud risk represents an important and distinct element of the risk assessment process. In a growing business, potential exposures may arise from fictitious vendors, altered payment instructions, payroll manipulation, unauthorized customer refunds, abusive expense reimbursements, inappropriate journal entries, asset misappropriation, or management override of established controls.
Fraud differs from ordinary error because it involves intentional conduct. A control designed primarily to detect accidental mistakes may therefore be less effective when an individual is deliberately attempting to circumvent procedures, conceal activity, or act in collusion with others. For this reason, management should consider fraud risk explicitly rather than assume that controls designed for routine errors will necessarily address intentional misconduct.
The assessment should also recognize that individuals with greater authority may have a greater ability to override established procedures. Strong controls at the transaction level are therefore not sufficient if senior personnel can routinely bypass them without independent review or accountability.
Consider a mid-sized company in which the senior marketing executive exercises substantial influence over employees outside the marketing department. Her leadership style is forceful and authoritarian, and employees have become accustomed to complying quickly with her requests rather than challenging them.
On several occasions, she enters the accounts payable department, places an invoice on the desk of an AP clerk, and states that the invoice must be paid immediately because the matter is urgent. She provides little additional explanation and leaves before the clerk has an opportunity to ask questions. The invoice appears legitimate. It bears the name of a professional marketing services company, includes a description of work allegedly performed, is formatted consistently with invoices the company normally receives, and even references an internal project number. Nothing on the face of the document immediately suggests that it is fraudulent. When the clerk attempts to enter the invoice, however, the vendor does not exist in the accounting system. Because the company has not established an independent vendor approval process, the clerk is permitted to create new vendors as part of routine AP processing. The clerk therefore creates the vendor record, enters the invoice, processes the payment, and releases the funds without obtaining independent confirmation that the vendor is legitimate or that the services were actually performed.
The apparent vendor is, in fact, an LLC legally formed by the marketing executive and her spouse. The company itself is a valid legal entity, but it has not provided the marketing services described on the invoices. Payments made by the employer are deposited into a bank account controlled by the LLC, allowing the marketing executive and her spouse to receive company funds for fictitious services. Over time, additional invoices are submitted using similar descriptions and project references resulting in thousands of dollars of fraudulent payments being made indirectly to the marketing executive. Because the same AP employee can establish the vendor, enter the invoice, and initiate payment, no independent control exists to challenge the transaction before the funds leave the company. The executive’s position and management style further reduce the likelihood that employees will question the urgency of the requests or seek confirmation from another member of management.
Fraud does not depend on an obviously suspicious invoice. To the contrary, its effectiveness depends on the transaction appearing routine. The principal weakness is the absence of controls surrounding vendor creation, invoice approval, payment authorization, and conflicts of interest. The company has also allowed management pressure to override the normal skepticism that should accompany transactions involving new vendors.
A stronger control structure would separate vendor establishment from invoice processing and payment authorization. New vendors would be subject to independent verification and approval. Significant expenditures would require documented approval by someone other than the individual requesting the payment. Periodic review of vendor master data and related party relationships could also identify unusual or undisclosed connections.
The scenario illustrates that fraud can occur even when supporting documents appear complete and the underlying legal entities are real. When one individual can initiate a transaction, influence the approval process, and rely on subordinates to process the payment without independent verification, a seemingly ordinary invoice can become an effective vehicle for misappropriating company funds.
Business Change Creates Control Risk
Risk assessment is not a one time exercise because the organization itself is continually changing. Growth, acquisitions, new locations, employee turnover, remote work arrangements, changes in payment methods, new banking platforms, ERP implementations, automated integrations, and AI assisted processes can alter both the nature and significance of existing risks.
Consider a business that historically paid vendors by check, with the owner personally reviewing and signing each payment. If the company later adopts an accounts payable platform that issues payments electronically, the underlying business expense may remain unchanged, but the control environment surrounding the transaction has changed substantially. Vendor creation, banking information changes, invoice approval, payment release, workflow configuration, and system overrides may now occur within the application rather than through a manual process.
The change in technology creates new points of access and new opportunities for both error and unauthorized activity. Control design should therefore evolve with the process. A control that was appropriate for a manual payment environment may no longer address the risks created by an automated one.
A Practical Risk Review for a Growing Business
A growing business does not need an elaborate enterprise risk management function to apply these concepts effectively. Management can begin by reviewing significant accounting and financial processes in a structured manner. For each process, the organization should identify the objective being pursued, the events that could prevent that objective from being achieved, and the potential significance and likelihood of those events.
The analysis should then consider which controls are intended to address the identified risks and whether those controls are actually operating as designed. This distinction is important. The existence of a documented procedure does not establish that the underlying risk is being managed if the procedure is routinely bypassed, performed inconsistently, or no longer suited to the process.
This type of structured review creates the link between risk assessment and the next COSO component. Once management understands the risks that require attention, it can determine the specific control activities necessary to address them.
CONTROL ACTIVITIES
Control activities are the policies and procedures designed to respond to identified risks. Within this component, COSO addresses the selection and development of appropriate control activities, the establishment of general controls over technology, and the implementation of controls through policies and procedures.
This is the component in which many of the procedures commonly associated with internal control become visible. Approvals, reconciliations, access restrictions, authorization thresholds, supervisory reviews, and segregation of duties are all examples of control activities. Their purpose, however, is not simply to add procedural steps to a business process. Each control should respond to a particular risk identified through the organization’s risk assessment process.
The effectiveness of a control activity therefore depends on the relationship between the underlying risk and the procedure designed to address it. A control that does not meaningfully reduce the identified risk may add administrative work without materially strengthening the internal control system.
Preventive and Detective Controls
Control activities are often described as either preventive or detective. Preventive controls are designed to reduce the likelihood that an inappropriate transaction or event will occur in the first place. Examples include requiring approval before payments are released, restricting system access according to job responsibility, establishing purchasing limits, independently approving new vendors, requiring dual authorization for significant electronic payments, and limiting the ability to post journal entries.
Detective controls operate differently. Rather than preventing an event, they are designed to identify errors, unauthorized activity, or other exceptions after they have occurred or while they are occurring. Bank reconciliations, variance analysis, payroll change reports, reviews of manual journal entries, duplicate payment reports, exception reports, and reviews of changes to vendor master data are common examples.
An effective control structure frequently uses both types of controls because they address different aspects of the same risk. A company may, for example, require approval before an electronic payment is released and subsequently perform an independent bank reconciliation. The approval reduces the likelihood that an unauthorized payment will be made, while the reconciliation provides an additional opportunity to identify a payment that nevertheless occurred improperly.
The presence of a preventive control therefore does not eliminate the value of subsequent review. Likewise, a detective control should not be viewed as a substitute for reasonable measures that could prevent a significant error or unauthorized transaction before company assets are affected.
Segregation of Duties
Segregation of duties is one of the most familiar control activities, but its purpose is sometimes misunderstood. The objective is not merely to involve additional employees in a transaction. Rather, segregation separates responsibilities that, when combined, would give one individual excessive control over the initiation, execution, recording, and subsequent review of an activity.
The functions most commonly considered include authorization, custody of assets, recordkeeping, and reconciliation. Ideally, one individual should not be able to authorize a transaction, control the related asset, record the transaction in the accounting records, and independently verify the result. Separating these responsibilities creates opportunities for one person’s work to be reviewed or constrained by another.
Accounts payable illustrates the concept particularly well:
Create vendor → Enter invoice → Approve payment → Release payment → Reconcile bank
If a single employee controls every stage of this process, the weakness extends beyond the absence of a particular approval. That individual may have the ability both to initiate an improper transaction and to conceal it afterward through control of the accounting records and reconciliation process.
Payroll presents a similar concentration of risk:
Add employee → Change compensation → Change direct deposit → Process payroll → Reconcile payroll
In a larger organization, responsibilities such as these may be divided among human resources, payroll personnel, accounting staff, treasury, and management. Smaller organizations often lack sufficient personnel to achieve that degree of separation. The underlying risk, however, does not disappear merely because the organization has fewer employees.
Compensating Controls in a Small Business
The practical limitations of a small accounting department require a different approach to control design. A business with one bookkeeper and an owner cannot create several additional accounting positions solely to achieve textbook segregation of duties. The inability to separate every incompatible responsibility does not eliminate the need for internal control; instead, it requires management to identify alternative procedures that address the same underlying risks.
Compensating controls can provide this additional oversight. Their purpose is to introduce an independent review or authorization at a meaningful point in the process when complete segregation of duties is impractical. The emphasis should remain on the risk being addressed rather than on mechanically adding another review step.
For example, if a bookkeeper prepares payments, the owner may independently review and authorize their release. When the bookkeeper also performs the bank reconciliation, an owner or outsourced controller may subsequently review the completed reconciliation and related bank activity. If one employee processes payroll, management may independently examine payroll change reports and the final payroll register before or immediately after processing.
The same principle can be applied to other areas of the accounting system. An employee who maintains vendor master data may be subject to an independent review of newly established or modified vendors. Where journal entry responsibilities cannot be fully segregated, a controller may review significant manual entries and their supporting documentation. In a small accounting department more generally, periodic independent examination of unusual or higher risk transactions can provide oversight that the organizational structure itself cannot provide.
The effectiveness of a compensating control depends on whether it addresses the actual exposure created by the lack of segregation. Simply placing an additional review somewhere in the process does not necessarily reduce the risk.
Accounts Payable and Cash Disbursements
The fictitious vendor scenario described earlier illustrates how weaknesses in accounts payable can convert management override and inadequate segregation of duties into an actual loss of company assets. The invoice appeared legitimate, but the absence of independent vendor approval and payment authorization allowed a fraudulent transaction to move through the accounting system as though it were an ordinary business expense.
Accounts payable and cash disbursements present several related risks because the process ultimately results in the transfer of company funds. Potential exposures include fictitious vendors, duplicate invoices, unauthorized purchases, altered banking instructions, unsupported invoices, and improper payment releases.
Control activities should therefore address both the legitimacy of the obligation and the authorization of the payment. New vendors may require independent approval before becoming eligible for payment, while changes to existing vendor banking information may require separate verification. Invoice documentation, duplicate invoice detection, payment approval thresholds, restricted access to payment release functions, and independent bank reconciliation can provide additional layers of control.
Changes to vendor banking information warrant particular attention because a transaction can appear entirely legitimate while the destination of the payment has been altered. An employee may receive what appears to be a genuine request from a vendor to change ACH instructions. If the accounting system is updated solely on the basis of that communication, future payments may be directed to an unauthorized account. A stronger process independently verifies the requested change through a previously established contact method before the vendor record is modified.
The important point is that the control should address the particular risk presented by the transaction. Invoice approval alone, for example, may not protect the company if an unauthorized individual can subsequently change the bank account to which the approved payment will be sent.
Accounts Receivable and Cash Receipts
Accounts receivable involves a different set of risks because the organization is receiving and recording funds rather than disbursing them. Potential problems include unrecorded receipts, incorrect application of customer payments, unauthorized write offs, improper refunds, and manipulation of customer balances.
Appropriate controls may include reconciling recorded cash receipts to bank deposits, reviewing accounts receivable aging, requiring authorization for write offs, independently approving significant credit memos and refunds, and reconciling information between billing systems and the general ledger. These procedures help establish that amounts received have been recorded completely and applied appropriately and that reductions in customer balances have been properly authorized.
The appropriate design will depend on how the business actually receives money. A company that receives substantial amounts of cash or paper checks faces different custody and recording risks from a company whose customers pay almost entirely through electronic payment processors. Control activities should therefore reflect the business model rather than assume that the same procedures are appropriate for every organization.
Payroll
Payroll combines accounting, personnel information, and cash disbursement, making changes to employee data particularly important. Relevant risks may arise from unauthorized employee setup, compensation changes, bonuses, direct deposit modifications, employee terminations, and the approval and release of payroll itself.
One useful detective control is an independent review of a payroll change report that identifies new employees, terminated employees, changes in pay rates, and changes to bank account information. Concentrating review on these changes and other exceptions can be more effective than attempting to examine every field in the payroll system with equal intensity.
The objective is to direct management attention toward activity that has altered the existing payroll environment. A stable employee record may present relatively little new risk from one pay period to the next, while a newly added employee, a significant compensation adjustment, or a changed direct deposit account may warrant additional scrutiny.
Journal Entries
Manual journal entries deserve appropriate control because they can directly affect the amounts and classifications reported in the financial statements. The objective is not to eliminate manual entries, since many legitimate accounting adjustments necessarily require them. Rather, the control structure should provide reasonable assurance that significant entries are authorized, supported, appropriately classified, and recorded in the proper accounting period.
Possible procedures include restricting journal entry posting access, requiring supporting documentation, obtaining independent approval for significant entries, reviewing entries posted directly to sensitive accounts, examining unusual period end activity, and analyzing manual entries that fall outside expected patterns.
The degree of review should reflect the nature and potential significance of the entry. Routine recurring entries supported by established procedures generally present a different risk from unusual manual adjustments posted near the end of a reporting period. Effective control design recognizes that distinction rather than treating every journal entry as equally significant.
Corporate Cards and Employee Expenses
Corporate cards and employee reimbursements create additional opportunities for company funds to be used for purposes outside established policy. Potential risks include personal purchases, unsupported expenditures, duplicate reimbursements, and purchases that exceed an employee’s authority.
Controls may include card specific spending limits, receipt and documentation requirements, identification of the business purpose of expenditures, supervisory approval, monthly account reconciliation, and review of unusual merchants or transaction patterns. These procedures should be proportionate to the significance of the expenditure and the nature of the risk.
Control intensity should therefore vary with the transaction. A routine $40 office supply purchase ordinarily does not require the same level of authorization, documentation, and review as a $1,800 first class airline fare. A well designed control structure directs greater attention toward transactions for which the potential financial or operational consequences are more significant.
Technology Controls Are Accounting Controls Too
Modern accounting information rarely resides within a single application. Financial data may move among banking systems, payroll applications, payment processors, customer relationship management platforms, expense applications, accounts payable software, inventory systems, ERP platforms, and automated integrations. As these systems become more interconnected, the reliability of financial information increasingly depends on the controls governing the technology through which that information is processed.
A fundamental issue is whether system access corresponds to job responsibility. Employees should generally possess only the access necessary to perform their assigned functions. Risk increases when former employees retain active accounts, users receive unnecessary administrator privileges, shared credentials prevent individual activity from being identified, or personnel are able to modify transactions outside their normal responsibilities.
Depending on the system and the significance of the information involved, appropriate controls may include multifactor authentication, restricted privileged accounts, controlled user provisioning, prompt termination of access when responsibilities change, and periodic review of existing permissions. Access control alone is not sufficient, however, because the configuration of the system can also affect financial processing. Management should understand who has authority to modify approval workflows, account mappings, user roles, automated thresholds, posting logic, and integration settings. A process that is effectively controlled today may become materially weaker after an apparently routine configuration change.
Technology administration should therefore be viewed as part of the accounting control environment rather than as an exclusively technical responsibility.
Interfaces and Automated Processes
Automation can improve efficiency and consistency, but it also changes the nature of internal control risk. When large volumes of transactions move automatically between systems, individual transactions may receive little or no direct human attention.
Consider an e commerce platform that transfers thousands of transactions into the accounting system automatically. Management must have a basis for determining whether all transactions were transferred, whether any were duplicated, whether account mappings operated correctly, whether failed transactions were identified, and whether exceptions were resolved appropriately.
These questions address the completeness and accuracy of the automated process rather than the appearance of its final output. A professionally formatted financial statement does not demonstrate that the underlying information is complete or accurate. Accounting systems can produce polished reports from incomplete, duplicated, or incorrectly classified source data. The effectiveness of automation therefore depends on controls over the information entering the process, the processing rules applied to that information, and the identification and resolution of exceptions.
AI Changes the Control Design
Artificial intelligence adds another layer to the increasing automation of financial processes. AI assisted accounting applications may classify transactions, extract information from invoices, propose journal entries, analyze reconciliations, identify unusual activity, prepare supporting schedules, explain variances, and respond to questions about accounting data. These capabilities can increase efficiency, but they do not remove the need for internal control. Instead, they change the points at which control must operate.
Consider an AI enabled accounts payable process that receives an invoice, identifies the vendor, extracts transaction information, proposes a general ledger classification, routes the invoice for approval, and ultimately participates in initiating payment. In such an environment, management must understand the information entering the process, the actions performed automatically, the manner in which confidence thresholds and exceptions are handled, the points at which human approval is required, the individuals authorized to change system configuration, and the availability of an adequate audit trail.
The control objective remains fundamentally the same even though the processing method has changed. Management still needs reasonable assurance that transactions are legitimate, authorized, accurately recorded, and properly reflected in the accounting records. Automation therefore changes the control problem rather than eliminating it. When a manual error occurs, its effect may be confined to a single transaction. When an automated process is configured incorrectly, the same error may be repeated systematically across hundreds or thousands of transactions. As automation becomes more powerful, effective control over system configuration, exception handling, review, and accountability becomes correspondingly more important.
INFORMATION AND COMMUNICATION
The fourth COSO component addresses whether relevant information is obtained, developed, and communicated to the people who need it. The principles within this component address the use of quality information, effective internal communication, and communication with appropriate external parties.
Even a well designed internal control system can fail when information does not move effectively through the organization. Controls depend on people receiving information that is sufficiently reliable and timely to perform their responsibilities. The issue is therefore broader than whether information exists. Management must consider whether the appropriate information reaches the appropriate individuals in a form and at a time that allows them to act on it.
Information Quality Matters
Accounting and financial processes depend on information that is sufficiently complete, accurate, timely, relevant, and traceable for its intended purpose. When critical information is missing or delayed, the effectiveness of the related accounting process can deteriorate even when established procedures are otherwise followed.
For example, a controller cannot properly evaluate the accounting implications of an unusual customer arrangement if accounting personnel never receive the underlying contract. Payroll cannot ensure that compensation ceases appropriately when an employee’s termination is not communicated. Similarly, management cannot respond effectively to deteriorating customer collections if accounts receivable information is produced but never meaningfully reviewed.
The same principle applies to automated processes. A system may process information exactly as configured and still produce an incorrect accounting result when the underlying data is incomplete, inaccurate, or inappropriate for the process. Automation can improve the consistency with which information is processed, but it cannot make deficient source information reliable. Information quality should therefore be considered throughout the accounting process, from the original source of the information through its eventual use in transaction processing, financial reporting, and management analysis.
Internal Communication
Internal communication provides the means by which accounting policies, responsibilities, expectations, and exceptions are understood throughout the organization. Effective communication may include accounting policies, close calendars, approval thresholds, assignments of responsibility, escalation procedures, system changes, and recurring management reporting processes.
The objective is not merely to distribute policies or instructions. Employees should understand their responsibilities, the limits of their authority, and the appropriate response when circumstances fall outside established procedures. A control can become ineffective when an employee understands the normal process but has no guidance for dealing with an exception.
Consider an employee who knows that invoices above a specified amount require management approval. If the designated approver is unavailable and no alternative approval or escalation procedure has been established, the employee is left with two undesirable choices. Either delay a legitimate transaction indefinitely or circumvent the control in order to complete the payment. Neither outcome reflects effective control design. Clear internal communication should therefore address both routine responsibilities and the treatment of exceptions. Employees should know not only what the normal procedure requires, but also where questions should be directed and how unusual circumstances should be escalated.
External Communication
Information relevant to internal control also originates outside the organization. Businesses routinely communicate with banks, lenders, attorneys, tax advisers, auditors, outsourced accounting professionals, regulators, customers, vendors, and other external parties. Information received through these relationships can have direct consequences for accounting, financial reporting, compliance, and business operations.
A lending agreement, for example, may establish financial covenants that require ongoing monitoring. Legal counsel may provide information concerning litigation or other contingencies that affect financial reporting. A tax adviser may identify an adjustment arising from a tax position or transaction, while a financial institution may alert management to unusual or potentially unauthorized activity. The effectiveness of these communications depends on whether significant external information reaches the individuals responsible for evaluating its accounting or operational consequences. Information received by one department provides little control benefit if the employees who must respond to it are unaware that it exists.
External communication is also reciprocal. Organizations must be able to provide reliable information to outside parties when required and should establish appropriate channels through which customers, vendors, advisers, and other parties can communicate matters that may affect the company’s internal control system.
How This Relates to Useful Financial Information
The COSO framework and FASB’s conceptual framework address different purposes and should not be treated as interchangeable. COSO provides a framework for designing, implementing, and evaluating internal control, while FASB Concepts Statement No. 8 establishes concepts that underlie financial accounting and reporting. Concepts Statement No. 8 is not authoritative GAAP, but it provides an important framework for understanding the objectives and characteristics of useful financial information.
Chapter 1 of Concepts Statement No. 8 establishes the objective of general purpose financial reporting, from which the remaining elements of the conceptual framework flow. Chapter 3 identifies relevance and faithful representation as the fundamental qualitative characteristics of useful financial information, with comparability, verifiability, timeliness, and understandability enhancing its usefulness. Chapter 5 further addresses recognition and derecognition, including when economic events should be incorporated into the financial statements.
Internal control is not itself a qualitative characteristic of financial information, nor does the existence of a control determine the appropriate accounting treatment for a transaction. Well designed controls can, however, support the accounting processes through which transactions are identified, recognized, measured, recorded, reviewed, and ultimately reported.
For example, reconciliations and independent review can support verifiability by providing evidence that recorded amounts have been compared with underlying records. Appropriate cutoff procedures can support faithful representation by helping ensure that transactions are recognized in the proper reporting period. Consistent application of accounting policies can enhance comparability, while disciplined close procedures can improve timeliness. Controls over transaction identification and completeness can also help ensure that economic events requiring recognition are captured by the accounting system rather than omitted entirely.
The relationship is therefore important but indirect. Internal control supports the processes used to produce financial information; the FASB conceptual framework describes the objectives and characteristics that make that information useful. The objective is therefore not simply to create more reports, distribute more policies, or generate additional data. Effective information and communication processes help ensure that relevant and sufficiently reliable information reaches the people who need it and can be used appropriately for financial reporting, management oversight, and other organizational purposes.
MONITORING ACTIVITIES
Monitoring activities evaluate whether the internal control system continues to operate as intended over time. Within this component, COSO addresses both ongoing and separate evaluations of internal control, as well as the timely communication of identified deficiencies to the individuals responsible for corrective action.
An internal control system should not be viewed as static. Even well designed controls can lose effectiveness as the organization changes. Personnel turnover, new systems, shifting responsibilities, increased transaction volume, informal workarounds, additional integrations, and changing business practices can gradually alter the environment in which a control operates. A procedure that adequately addressed risk when it was implemented may therefore become less effective as the underlying process evolves. Monitoring provides management with a means of determining whether those changes have affected the design or operation of existing controls.
Controls Need to Be Revisited
Control deterioration often occurs gradually rather than through a single obvious failure. Former employees may retain system access after leaving the organization. Bank reconciliations may continue to be prepared each month while the independent review that once accompanied them quietly disappears. Close deadlines may become progressively less disciplined, approval thresholds may no longer reflect the size of current transactions, and exception reports may continue to be generated even though no one meaningfully reviews them.
Technology can create similar changes. A new integration may automate a process that was previously subject to manual review, or a system configuration change may alter an established approval workflow without a corresponding reassessment of the underlying risk. These conditions do not necessarily indicate that the original control was poorly designed. In many cases, the organization has simply changed while the control has remained unchanged.
Monitoring activities should therefore provide a structured means of identifying when the control environment has drifted from its original design. Depending on the nature of the business, this may include periodic reviews of user access, unresolved exceptions, monthly close performance, account reconciliations, significant transactions, control walkthroughs, and management financial reviews. Significant business or system changes should also prompt reconsideration of whether previously established controls remain appropriate.
Finding the Error Is Not Enough
Effective monitoring extends beyond identifying and correcting individual accounting errors. A recurring error may indicate that the underlying control is not functioning effectively or that the process itself requires redesign.
Consider a bank reconciliation that contains the same stale reconciling items month after month. Removing those items may correct the current reconciliation, but the correction does not explain why the condition continues to recur. The underlying cause may involve unclear responsibility, insufficient training, improper cutoff, incomplete review, an application configuration issue, or a weakness in the process used to record cash activity.
A stronger response therefore examines the cause of the deficiency rather than treating each occurrence as an isolated accounting problem. Management should evaluate the associated risk, communicate the issue to the appropriate personnel, modify the process or control where necessary, and subsequently determine whether the corrective action has been effective. This distinction is fundamental to monitoring. Correcting an accounting error addresses the immediate result; correcting the control weakness addresses the condition that allowed the error to occur.
Control Evidence Matters
Monitoring is more effective when significant control activities leave sufficient evidence that they were actually performed. Without such evidence, management may have difficulty distinguishing between a control that operated as intended and one that existed only as an undocumented expectation. Appropriate evidence will vary according to the nature and significance of the control. It may include workflow approval histories, reconciliation signoffs, review comments, records of exception resolution, system audit trails, documentation of access changes, or support for significant journal entries.
The objective is not to impose unnecessary documentation on every activity performed by a small business. Documentation should remain proportionate to the significance of the underlying risk. Important controls, however, should generally provide enough evidence to establish what was reviewed, who performed the review, when it occurred, which exceptions were identified, and how those exceptions were resolved. This evidence serves more than an administrative purpose. It allows management to evaluate whether controls are being performed consistently and provides a basis for investigating failures when they occur.
Monitoring Automated and AI Assisted Processes
Automated processes require monitoring for the same reason as manual processes, conditions can change after implementation. Interfaces can fail, transaction volumes can shift, system configurations can be modified, and exceptions can accumulate without receiving appropriate attention. Management should therefore evaluate whether automated processes continue to operate within expected parameters. Relevant indicators may include increasing interface failures, rising exception volumes, frequent approval overrides, unresolved reconciliation differences, unexpected changes in automated classifications, or modifications to system configuration that were not independently authorized or reviewed.
The monitoring challenge becomes more significant when accounting processes incorporate artificial intelligence. An AI assisted process that performed appropriately when first implemented should not be assumed to remain reliable indefinitely. Changes in source data, software configuration, model behavior, workflows, or the underlying business environment may alter the quality or consistency of the resulting output.
Monitoring should therefore consider not only whether the process continues to operate, but whether its output remains appropriate for the accounting objective it is intended to support. Technology changes the methods available for monitoring, but it does not eliminate the need for continuing evaluation.
How a Virtual Outsourced Controller Can Help Monitor the Environment
Many monitoring activities can be performed effectively in a virtual environment when the outsourced controller has appropriate authorized access to accounting systems, supporting documentation, relevant personnel, and management. Remote access can allow the controller to review account reconciliations, journal entries, user access, bank activity, payroll changes, exception reports, close completion, unusual transactions, and automated workflows without being physically present at the client’s location.
The role of the virtual outsourced controller is generally to evaluate the design and operation of financial controls, identify deficiencies, and communicate matters requiring management attention. This may include reviewing whether reconciliations are completed timely, whether significant journal entries are adequately supported, whether user permissions remain appropriate, or whether recurring exceptions suggest a broader weakness in the underlying process.
Some control activities, however, are inherently physical. Custody of inventory, cash handling, receiving activities, physical check custody, and access to company facilities require participation by personnel who are physically present. Those responsibilities remain with appropriate client employees or management.
The existence of physical controls does not prevent a virtual controller from contributing to the monitoring process. The controller may evaluate the design of those procedures, review documentation supporting their performance, analyze resulting financial activity, and identify patterns or deficiencies that warrant further investigation. The distinction is therefore not between controlled and uncontrolled activities, but between controls that can be directly observed remotely and those that must be performed physically while remaining subject to financial review and oversight.
A PRACTICAL INTERNAL CONTROL MATRIX
Once the five COSO components are understood, a business can begin translating the framework into individual risks and controls. One practical approach is to identify the process being evaluated, determine what could go wrong, and then establish a control that responds to the identified risk.
Vendor Setup
Risk: Fictitious vendor created
Example control: Independent vendor approval
Control type: Preventive
Primary COSO component: Control Activities
---
Accounts Payable
Risk: Invoice paid twice
Example control: Duplicate invoice review
Control type: Detective
Primary COSO component: Control Activities
---
Banking
Risk: Unauthorized payment
Example control: Payment approval and release controls
Control type: Preventive
Primary COSO component: Control Activities
---
Payroll
Risk: Unauthorized pay change
Example control: Payroll change review
Control type: Detective
Primary COSO component: Control Activities
---
Journal Entries
Risk: Unsupported accounting adjustment
Example control: Independent journal entry review
Control type: Preventive and detective
Primary COSO component: Control Activities
---
Bank Reconciliation
Risk: Unauthorized activity is not identified
Example control: Monthly bank reconciliation with independent review
Control type: Detective
Primary COSO component: Control Activities
---
System Access
Risk: Former employee retains system access
Example control: Timely termination of access combined with periodic access review
Control type: Preventive and detective
Primary COSO components: Control Activities and Monitoring Activities
---
System Integration
Risk: Transactions fail to transfer completely or accurately between systems
Example control: Exception reporting combined with source to general ledger reconciliation
Control type: Detective
Primary COSO components: Control Activities and Monitoring Activities
---
AI Assisted Process
Risk: Unsupported or inappropriate output is accepted without adequate review
Example control: Human review before significant accounting entries, payments, or other consequential actions are accepted or executed
Control type: Preventive
Primary COSO component: Control Activities
---
Financial Reporting
Risk: A significant financial variance remains unexplained
Example control: Management financial review with documented investigation and follow up
Control type: Detective
Primary COSO component: Monitoring Activities
---
The matrix is illustrative rather than prescriptive. Appropriate controls depend on the organization’s actual risks, systems, personnel, transaction volume, complexity, and reporting requirements. A smaller number of well designed controls that employees understand and consistently perform will generally provide greater value than an extensive collection of procedures that exists primarily on paper.
Management Should Understand Key Control Responsibilities
A practical internal control review begins with management understanding how authority, responsibility, and oversight are distributed throughout the organization. Management should know who has the ability to establish or modify vendors, change payment information, authorize and release disbursements, add employees or modify payroll data, and post significant manual journal entries. The same level of understanding should extend to review and monitoring responsibilities. Management should know who performs bank reconciliations, who independently reviews them, who can modify accounting system permissions, which reports or system alerts identify unusual activity, and who is responsible for investigating and resolving exceptions.
The purpose is not merely to document who performs each task. Management should understand whether important responsibilities have been assigned deliberately and whether adequate independent oversight exists where incompatible duties or concentrated authority create additional risk. A lack of clarity in these areas does not necessarily indicate that a serious control failure has already occurred. It may, however, suggest that responsibilities have developed informally, that important risks have not been fully evaluated, or that existing processes are not sufficiently understood. For many growing businesses, establishing this basic understanding is an appropriate starting point for a broader internal control review.
The Bottom Line
Internal control is not intended to create unnecessary bureaucracy. Its purpose is to establish a financial environment in which responsibilities are understood, significant risks are identified, transactions are appropriately authorized and recorded, relevant information is communicated effectively, and problems are detected and addressed before they become more significant.
The appropriate control structure will differ substantially from one organization to another. A business with twelve employees does not require the same infrastructure as a company with five hundred employees, and controls designed for a manual payment environment may be inappropriate for a business that relies primarily on electronic disbursements. A small accounting department may depend heavily on compensating management review, while an organization using integrated applications, automated workflows, or AI assisted accounting processes may require controls over technology and system configuration that were unnecessary in a more traditional environment.
The objective is therefore not to replicate the internal control structure of a large public company. Controls should be proportionate to the organization’s size, complexity, systems, personnel, transaction volume, and exposure to risk.
The COSO framework provides a useful structure for making those decisions. The control environment establishes the foundation for responsibility and accountability. Risk assessment identifies the events and conditions that could interfere with organizational objectives. Control activities provide specific responses to those risks, while information and communication help ensure that relevant information reaches the people responsible for acting on it. Monitoring activities provide continuing evaluation of whether the overall system remains appropriately designed and continues to operate as intended.
A controller can help management connect these components within the organization’s actual accounting environment. This may involve identifying significant financial risks, improving segregation of duties, designing compensating controls where complete segregation is impractical, strengthening payment and system access procedures, evaluating accounting applications and automated workflows, reviewing exceptions, and assessing whether established controls continue to address the risks for which they were designed.
The strength of an internal control system should not be measured by the number of procedures an organization has documented. A smaller number of well designed controls that address significant risks and are understood and consistently performed will generally provide greater value than an extensive collection of procedures that receives little meaningful attention. Effective internal control ultimately depends on whether the organization understands its important risks and responds to them with practical controls appropriate to its circumstances.
Sources
- COSO - Internal Control—Integrated Framework: https://www.coso.org/internal-control
- COSO - Achieving Effective Internal Control Over Generative AI: https://www.coso.org/generative-ai
- FASB - Concepts Statement No. 8, Conceptual Framework for Financial Reporting: https://www.fasb.org/page/document?pdf=Concepts_Statement_No_8.pdf
- Gomez CPA - The Business Value of an Outsourced Controller in 2026: https://gomezcpa.com/insights/Outsourced_Controller.html
© 2026 Gomez CPA. All rights reserved.