Internal Controls in Small and Medium-Sized Enterprises

Internal Controls in Small and Medium-Sized Enterprises

When we talk about internal controls, we might think of them as a concept reserved for large corporations, which have compliance departments and audit committees. However, gaps in the controls of small and medium-sized businesses can be costly for them and are often driven by a lack of understanding of risks, understaffed teams, and procedures that are frequently poorly implemented—or not implemented at all. Furthermore, many measures are implemented in response to an incident, when prevention could have averted the situation.

What is internal control ?

Internal control is simply a measure put in place to ensure that financial information is reliable, that the company’s assets are protected, and that operations are conducted in accordance with company policies.

These measures do not have to be complex. An expense approval policy, a monthly review of bank statements, or the segregation of access rights in accounting software are all internal controls that are simple and effective when rigorously enforced.

Risks and Internal Controls

Before implementing controls, you must first identify the risks specific to the company. A risk is the possibility that an undesirable event will occur and harm the organization—whether it be an error, fraud, a process failure, or inaccurate financial information.

To assess a risk, two factors must be considered: the probability of its occurrence within the context of the business and its impact if the event were to occur. A risk that is likely to occur and has a significant impact will require rigorous control; a low-risk event may be accepted or simply monitored. Each entity will determine its own risk tolerance or risk aversion.

Common Weaknesses in Small and Medium-Sized Businesses

  1. A single person oversees the entire financial cycle.

When a single employee can create a vendor in the system, approve an invoice, and make the payment—all at the same time—the risk of fraud or undetected errors is very high—even if you trust that person completely.

The principle of segregation of duties involves dividing the functions of authorization, recording, reconciliation, and physical custody among several people. In small and medium-sized businesses (SMEs), where teams are often small, this principle can be adapted: for example, management authorizes new suppliers, and the assistant handles the payments.

  1. Bank reconciliations are not being performed or reviewed.

Bank reconciliation is a control in and of itself that helps detect discrepancies caused by fraud or errors. However, it loses all its value if the same person is responsible for both making payments and reconciling accounts. In such cases, it can take months—or even years—to detect an error or embezzlement.

Ideally, the reconciliation should be performed by someone who is not involved in the payments, or at the very least reviewed and signed by management on a monthly basis.

  1. Expenses are approved retroactively.

In many small and medium-sized businesses, purchases are made first, and approval comes afterward—or not at all. A prior approval policy, even a simple one, significantly reduces risks and also allows for better financial control and adherence to budgets. For example, a company could require written approval from a member of management prior to any purchase exceeding a certain threshold (such as $1,000).

  1. No one is updating the list of active employees

Payroll fraud is more common than people realize. Ghost employees, inaccurate pay rates, and overtime approved without supervision. These situations arise when a single person manages the entire payroll without anyone else periodically verifying the list of active employees, their terms of employment, and the amounts paid.

Why Is Your Accountant Interested in Your Internal Controls ?

During an audit or review engagement, the accounting professional will take your control environment into account in their work. The strength of your internal controls will influence the reliability of your financial statements and, consequently, the scope of the necessary audits. Robust internal controls that are tailored to the risks and carefully implemented will allow for greater reliance on your internal processes.

Some tips for getting started:

  • Conduct a risk assessment for your business
  • Review your bank statements yourself every month
  • Limit access to banking and accounting platforms to what is strictly necessary
  • Require two signatures for payments exceeding a threshold you set
  • Validate the payroll, the hourly rate, and the number of hours for each period
  • Ask your accounting professional to assist you in assessing risks, designing appropriate internal controls, and implementing them

An article by Catherine Riendeau
forthe certification team

For further reading :