Internal Control Failure Examples: Fraud, IT, and Governance

Examples of internal control failure fall into four practical categories: financial reporting manipulations that mislead outsiders, asset-safeguarding breakdowns that let insiders steal, IT control gaps that compromise the systems recording everything, and governance failures that give silent permission for the rest. More than half of all occupational fraud cases trace back to either missing controls or someone overriding the controls that exist.1ACFE. 2024 Report to the Nations The specific breakdowns below have destroyed companies, sent executives to prison, and produced restatements measured in billions of dollars.

How Severity Is Ranked

Not every control failure carries the same weight, and the label matters because it determines what has to be disclosed. Auditors sort failures into three tiers. A simple deficiency means a control is poorly designed or isn’t operating as intended, but probably won’t cause a major misstatement. A significant deficiency is more serious and warrants attention from those overseeing financial reporting. A material weakness sits at the top: there’s a reasonable possibility that a significant error in the financial statements won’t be caught in time.2Public Company Accounting Oversight Board. AS 2201 An Audit of Internal Control Over Financial Reporting

The distinction has teeth. Material weaknesses trigger mandatory public disclosure at public companies. Lesser deficiencies get communicated privately to the audit committee. A disclosed material weakness routinely moves a company’s stock price and puts management under immediate scrutiny.

Financial Reporting Failures

Reporting failures share a common root: insufficient segregation of duties. When one person can initiate, record, and reconcile a transaction, the independent check that would catch an error or a fraud simply doesn’t exist.

Revenue Recognition Schemes

Revenue is the number investors watch most closely, which makes it the number most often manipulated. Under ASC 606, revenue should be recognized only when a company has satisfied its performance obligations. Control failures here involve booking sales before the goods ship, before the customer accepts them, or before the company has done anything at all.

Channel stuffing is the classic version. A company pressures distributors into accepting more product than they can sell, then records the inflated shipments as revenue. The SEC charged Elanco Animal Health with exactly this in 2024, and the company settled for $15 million. The underlying control failure is straightforward: nobody independent of the sales team reviews whether revenue recognition criteria are actually met before the entry posts.

Fictitious revenue pushes further. Management creates invoices for customers that don’t exist, or records returned merchandise as a fresh sale. Without a control requiring someone to match shipping documents against recorded invoices, phantom revenue inflates the top line unchecked. These schemes are almost always driven by pressure from above to hit earnings targets.

Inventory Overstatement

Inventory sits on the balance sheet as an asset, so overstating it inflates assets and understates cost of goods sold at the same time, making profits look better than they are. The most basic failure is skipping independent physical counts. If nobody walks the warehouse to compare what’s on the shelves to what’s in the system, quantities in the perpetual records can be inflated with little risk of detection.

Valuation failures are subtler. Accounting rules require inventory to be carried at the lower of cost or net realizable value. When controls don’t flag obsolete, damaged, or slow-moving stock for write-down, the asset stays inflated. The correction, when it eventually comes, hits earnings all at once.

Improper Capitalization of Expenses

Capitalizing a cost spreads it across years through depreciation. Expensing it hits the income statement immediately. When a company capitalizes routine operating expenses, it pushes today’s costs into the future and inflates current earnings.

WorldCom turned this into one of the largest frauds in history. Beginning in 2001, senior management directed employees to reclassify billions of dollars in ordinary line-cost expenses as capital assets, without any supporting documentation and in violation of basic accounting principles. Over five quarters, the improper capitalizations totaled roughly $3.8 billion. The SEC’s complaint described “chronic and pervasive failures to follow GAAP standards, and to mandate and institute appropriate internal controls.”3SEC. Complaint SEC v WorldCom Inc The missing control was independent verification that expenditures met the company’s capitalization policy before being booked as assets.

Asset-Safeguarding Failures

Financial reporting failures aim to mislead outsiders. Asset-safeguarding failures let insiders steal. They involve physical assets and cash rather than accounting entries, and they tend to go undetected for long stretches because no one is looking at the right reconciliation.

Cash Skimming

Skimming is theft of cash before it ever enters the accounting system. The classic setup: the same person opens incoming mail, receives customer payments, and records the receipts. That person can pocket a check and simply never create a corresponding entry. Because the cash was never recorded, a standard financial audit won’t find it.

Point-of-sale environments face a different version. Without sequentially numbered receipts or a system that logs every transaction automatically, an employee can accept a customer’s payment, delete the transaction, and pocket the cash. The fix is conceptually simple: total cash deposited must match total recorded sales, verified daily by someone other than the person handling the money.

Ghost Employees on the Payroll

A ghost employee is a fictitious person or a former employee who still appears on the payroll and continues to receive paychecks. The money goes to the fraudster who set up the scheme, and these cases typically run about 18 months before anyone catches on.

The failure is almost always the same: a single person can add new hires to the payroll system and approve their timecards or salary. Effective control separates those functions so the hiring manager, HR, and payroll processor are distinct people with limited system access. Add a periodic reconciliation of the active-employee list against the payroll disbursement file and ghost employees get flagged quickly. Without that reconciliation, the scheme can run indefinitely.

Procurement Fraud and Kickbacks

Procurement fraud starts when someone can create a new vendor in the system without independent verification. An employee sets up a shell company, steers purchase orders to it, and approves payment for goods or services that never arrive. Kickback schemes work similarly: a real vendor overcharges, and the employee approving the inflated invoices takes a cut.

The primary defense is the three-way match, which requires the purchase order, receiving report, and vendor invoice to agree before payment is released. When a payment approver can override or ignore mismatches, the door opens. Organizations lose an estimated five percent of annual revenue to fraud, and procurement schemes account for a meaningful share.

IT Control Failures

IT general controls underpin everything else. If someone can alter the system that records transactions, no amount of manual oversight downstream will catch the manipulation.

Excessive User Access

Granting employees more system access than their jobs require is the digital equivalent of a segregation-of-duties failure. A system administrator with unrestricted access can bypass application-level controls, alter records, and cover the tracks. The problem isn’t that someone has administrative privileges; it’s that nobody reviews whether those privileges still match the person’s actual role.

Terminated employees who retain active credentials are worse. A former employee can log in remotely, extract sensitive data, or plant malware. The catching control is a periodic access review, ideally automated, that compares user privileges against current job functions and flags terminated accounts that are still live.

Uncontrolled Changes to Production Systems

Change management controls govern how modifications to software, databases, and operating systems move from development into live production. When a programmer can push code directly to production without independent testing and formal sign-off, the risk of introducing errors into financial calculations rises sharply. An unapproved change could alter how the system calculates tax withholdings, processes customer orders, or posts journal entries.

The fix requires strict separation between development and production. Changes get created in development, tested in a staging environment, and approved before they touch live data. That process is the reason a single developer’s mistake at 2 a.m. doesn’t quietly corrupt three months of financial records.

Backups That Don’t Actually Work

When backup and recovery controls fail, the consequences are existential. Code Spaces, a cloud hosting company, was destroyed in 2014 after attackers infiltrated its AWS control panel and deleted both the primary data and the cross-region backups that were supposed to be the safety net. The company never recovered. TravelEx, a foreign-currency exchange operating in 30 countries, was hit by ransomware in 2020 and couldn’t restore normal operations even after paying the attackers. It effectively went out of business.

These failures follow a pattern. Backups weren’t performed frequently enough, weren’t isolated from the production environment, or were never tested to confirm they could actually be restored. A backup that can’t survive a test restoration isn’t a backup. Organizations that haven’t rehearsed recovery under realistic conditions discover their plan doesn’t work during an actual crisis.

Governance and Management Override

Every failure above involves a specific control that broke down. But controls work only when the people at the top of the organization insist they work. A weak control environment is the root cause behind most large-scale corporate frauds, because it gives silent permission for every other control to be circumvented.

Management Override

Management override is the most destructive category because the people responsible for enforcing controls are the ones subverting them. Lower-level controls become meaningless when a CFO can bypass the required approval chain for a journal entry or direct subordinates to book fictitious entries.

HealthSouth shows how far this can go. Senior accounting personnel held regular meetings to decide which false entries to record so that reported earnings would match Wall Street expectations. They reduced a contra-revenue account called “contractual adjustment” because the amounts booked there were estimates with limited paper trails, making false entries harder for auditors to trace. Each inflation was designed to flow through multiple intermediary journal entries specifically to obscure the manipulation, and forged documents were produced when auditors asked questions.4SEC. Complaint HealthSouth Corporation and Richard M Scrushy

Enron followed a different pattern with the same governance breakdown. A Senate oversight report found that the board approved complex related-party transactions without sufficient diligence and then failed to monitor them. The resulting accounting manipulations included roughly $7–8 billion in improperly recorded liabilities and cash flow, nearly $4 billion in undisclosed contingent liabilities, and a $1 billion reduction in shareholder equity. Arthur Andersen, the external auditor, failed to raise internal control concerns about these transactions with the board.5GovInfo. Financial Oversight of Enron The SEC and Private-Sector Watchdogs

Wirecard reinforced the same lessons internationally. The German company acknowledged in 2020 that €1.9 billion in reported bank balances didn’t exist. Every line of defense failed: internal controls, the supervisory board, the external audit, financial reporting oversight bodies, and the market regulator BaFin.

A Weak or Sidelined Internal Audit Function

A strong internal audit department provides independent, ongoing evaluation of whether controls are working. That independence evaporates when the function reports to the wrong person. The Institute of Internal Auditors recommends that the Chief Audit Executive report administratively to the CEO and functionally to the audit committee, precisely so internal audit is not positioned within an operation it might need to examine.6The Institute of Internal Auditors. Implementation Guide Standard 1110 Organizational Independence When the CAE reports to the CFO, internal audit is subordinate to a function it’s supposed to scrutinize.

The problem deepens when findings are routinely ignored. An audit committee that receives reports detailing control deficiencies and takes no corrective action has effectively announced that compliance is optional. An internal audit team without resources, authority, or protection from retaliation produces reports nobody reads, which is worse than having no audit function at all because it creates a false sense of security.

A Broken Whistleblower Channel

Tips from employees catch 43% of occupational fraud cases, more than three times the rate of any other detection method.1ACFE. 2024 Report to the Nations When employees fear retaliation for using the hotline, the organization loses its best sensor. Federal law protects whistleblowers at public companies from discharge, demotion, suspension, threats, or harassment for reporting conduct they reasonably believe violates securities laws or SEC rules. An employee who prevails in a retaliation claim is entitled to reinstatement, back pay with interest, and compensation for litigation costs and attorney fees.7Office of the Law Revision Counsel. 18 USC 1514A Civil Action to Protect Against Retaliation in Fraud Cases

What Control Failures Cost the People Responsible

At public companies, internal control failures aren’t just financial risk. They trigger specific legal obligations and criminal exposure under the Sarbanes-Oxley Act, which Congress enacted in 2002 largely in response to Enron and WorldCom.

Under SOX Section 302, the CEO and CFO of every public company must personally certify in each quarterly and annual report that they are responsible for establishing and maintaining internal controls, that they have evaluated those controls within 90 days of the report, and that they have disclosed all significant deficiencies and material weaknesses to the auditors and audit committee. They must also disclose any fraud involving management or employees who play a significant role in internal controls, regardless of whether the fraud is material.8Office of the Law Revision Counsel. 15 USC 7241 Corporate Responsibility for Financial Reports

SOX Section 404 requires each annual report to contain a formal management assessment of whether internal controls over financial reporting are effective. For accelerated and large accelerated filers, the external auditor must independently attest to that assessment.9Office of the Law Revision Counsel. 15 USC 7262 Management Assessment of Internal Controls A material weakness disclosed under Section 404 becomes public information that investors, analysts, and regulators use to judge the company’s reliability.

SOX Section 906 attaches criminal penalties to the certification. A CEO or CFO who certifies a financial report knowing it doesn’t comply with SEC requirements faces up to $1 million in fines and 10 years in prison. If the false certification is willful, the penalties jump to $5 million and 20 years.10Office of the Law Revision Counsel. 18 USC 1350 Failure of Corporate Officers to Certify Financial Reports A knowing violation means the officer was aware the report was noncompliant. A willful violation means the officer deliberately certified it anyway. Both are federal crimes, and the willful version carries penalties heavy enough to end both a career and a liberty.