Internal Controls Overview
Background
Internal control is the term used to describe the various plans, methods and procedures that an organisation uses in order to meet its declared business objectives. For the purpose of this book, it is important to note that internal control is often viewed as the first line of defence for safeguarding assets and preventing and detecting fraud, errors, waste, abuse and mismanagement. However, management will use it to achieve various other essential objectives too: to bring order and efficiency; to ensure that the policies of the board are followed; to ensure the completeness and accuracy of records; and to ensure compliance with the law and all relevant regulations.
Above all, internal control helps an organisation to manage its risks. Every control should be designed in a way that is proportionate to the risk in question. One of the problems for mature organisations, those companies or public sector bodies that have existed for decades, is that their internal control systems will often pre-date their adoption of formalised risk management procedures of the type we discussed in Chapter 4. So individual controls, methods of working and customs and practices may well have evolved without using risk as a reference point at all. Controls against fraud risk are a classic example of this and they often appear to be haphazard and ineffective as a result.
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access