Internal control over financial reporting covers the everyday procedures a company uses to keep its financial statements accurate: approvals before money goes out, reconciliations that catch errors after transactions post, system rules that block bad data, and separations of duty that make fraud harder to pull off. The clearest way to understand these controls is to see them at work inside the transaction cycles that produce the numbers. Below are the main categories and concrete examples of internal control over financial reporting, organized so you can place any control you encounter into the right box.
The Two Axes That Classify Every Control
Before the examples, two classifications do most of the work. Every control activity can be sorted by when it operates and by how it operates.
Preventive vs. Detective
Preventive controls stop errors before they enter the financial records. Requiring a manager’s approval before a purchase order above a set dollar threshold is preventive: the unauthorized spend never gets into the system. Segregation of duties is another classic. Splitting the ability to authorize transactions, record them, and handle the related assets across different people makes it much harder for any single person to commit and conceal fraud.
Detective controls catch errors after they’ve already been recorded. A monthly bank reconciliation is the textbook example. Someone compares the company’s cash ledger to the bank statement and investigates every difference. The error has already happened, but the reconciliation finds it in time for correction before the financial statements are finalized. Supervisory review of journal entries works the same way, with a manager examining supporting documents for unusual postings after the entries have been made.
Manual vs. Automated
Manual controls rely on a person’s judgment or physical action. A warehouse team counting inventory is a manual control. Verifying a new vendor’s taxpayer identification number through the IRS’s online TIN matching tool before issuing the first payment is another.1Internal Revenue Service. Taxpayer Identification Number (TIN) Matching Tools Manual controls are flexible but depend on the person remembering to perform them correctly every time.
Automated controls are programmed into IT systems and execute without human intervention once configured. An ERP system that blocks a sales order when the customer’s receivable balance exceeds their credit limit is an automated preventive control. A system that rejects a vendor invoice when the amount deviates from the purchase order by more than a set tolerance is another. Automated controls are highly consistent, but they’re only as reliable as the IT environment supporting them.
Revenue Cycle Examples
Revenue controls focus on making sure sales are real, recorded in the right period, and valued correctly. Segregation of duties is central here: the person who records a sale should not be the same person who handles the cash receipt, and whoever authorizes a credit memo should not also process the sales adjustment.
Before goods ship, many companies run a three-way comparison of the sales order, shipping document, and invoice. The system won’t generate the invoice until the shipping document confirms the goods have left the warehouse. On the cash side, daily reconciliation of cash received to the amount deposited catches discrepancies quickly.
For companies with complex pricing arrangements, a separate control layer addresses revenue recognition. This means documented analysis of variable consideration (discounts, rebates, and contingent pricing) and formal sign-off when contract modifications occur. Cross-functional review involving sales, legal, and finance helps ensure performance obligations are identified correctly, because the salespeople who negotiated the contract often understand its economics better than the accountant recording it.
Expenditure Cycle Examples
Expenditure controls ensure the company pays only for goods and services it actually received, at prices it actually agreed to. The anchor control is the three-way match. Every vendor invoice is compared against the purchase order (what was ordered) and the receiving report (what arrived). When those three documents don’t agree within a small tolerance, the system flags and holds the payment.
Before a new vendor is added to the master file, an independent person verifies the vendor’s legitimacy and a separate manager approves the addition. This prevents fictitious vendors, one of the more common fraud schemes. Larger payments often require escalating approval authority; a payment above $50,000, for example, might need the treasurer’s digital signature. As a detective control, someone independent of accounts payable periodically reviews the payable listing for anomalies like long-outstanding debit balances or duplicate payments.
Cloud-based software subscriptions create a modern wrinkle. Unlike a one-time purchase, a SaaS contract auto-renews and the spending can sprawl across departments without centralized visibility. Effective controls include maintaining a centralized subscription register, requiring IT security and compliance review before procurement, monitoring actual usage against licensed seats, and flagging upcoming renewals for renegotiation. Without these controls, companies routinely pay for duplicate tools and unused licenses for months before anyone notices.
Payroll Cycle Examples
Payroll controls guard against fictitious employees, unauthorized pay rate changes, and incorrect payments. A key preventive control requires that every new hire and every pay rate change be formally approved by a supervisor who is independent of both HR and the payroll processing function. Time records need manager approval before payroll runs.
On the detective side, comparing each payroll register to the prior period’s register is one of the simplest and most effective checks available. Any significant jump in total payroll dollars or headcount triggers an investigation. The bank reconciliation for the payroll disbursement account should be performed by someone who wasn’t involved in preparing or approving the payroll run. That separation makes it extremely difficult for a single person to add a ghost employee and pocket the payments undetected.
Inventory and Fixed Asset Examples
These controls verify that the physical assets a company claims to own actually exist and are valued correctly on the balance sheet. The foundational control is the periodic physical inventory count, typically performed annually, with results reconciled to the perpetual records.2Public Company Accounting Oversight Board. AS 2510 – Auditing Inventories All significant variances between the physical count and the records must be investigated, approved by management, and adjusted. Companies with strong perpetual inventory systems and good IT controls can supplement annual counts with cycle counting throughout the year.
For fixed assets, disposals and sales require formal authorization documenting the reason and the expected proceeds. Sale proceeds are then reconciled to the authorized disposal form and the asset’s recorded net book value. Periodic physical inspections of high-value equipment confirm that assets are where the records say they are. RFID tagging and automated tracking systems have made this far more practical for companies with large, dispersed asset bases, allowing real-time location monitoring and faster detection of missing items.
IT General Controls
Every automated control described above depends on the integrity of the IT systems running it. If someone can change a program’s logic, access data they shouldn’t see, or bypass an approval workflow, the automated controls built on top of that system become unreliable. IT general controls (ITGCs) protect the technology infrastructure itself, and auditors evaluate them as part of every ICFR assessment.3Public Company Accounting Oversight Board. Auditing Standard No. 12 – Identifying and Assessing Risks – Appendix B
ITGCs fall into four categories. Access controls restrict system access so employees can only reach what their job requires; this includes password policies, role-based access provisioning, promptly disabling terminated employees’ accounts, and restricting privileged administrator access to a small number of authorized personnel. Change management controls how software and system configurations are modified, with changes going through a formal request, testing, approval, and migration process; the person who writes the code should not be the same person who moves it into production. Program development controls govern how new systems are built or acquired, requiring documented requirements, testing against those requirements, and formal acceptance before going live. Computer operations controls keep systems running reliably through job scheduling, backup and recovery procedures, and incident monitoring; a nightly batch job that transfers HR termination data to the access management system is an ITGC that supports access controls across every other application.
ITGC failures cascade. If change management is weak, someone could alter the three-way matching logic in accounts payable and the automated control would stop catching mismatches without anyone realizing. That’s why auditors often start their ICFR work by evaluating ITGCs before testing the process-level controls that depend on them.
Entity-Level and Process-Level Controls
Controls also sort by the level at which they operate. Entity-level controls (ELCs) span the entire organization rather than targeting a specific transaction type. They set the conditions under which every other control operates. Examples include the company’s code of conduct, the whistleblower hotline, the internal audit function’s reporting relationship to the audit committee, and management’s formal risk assessment process.4The Institute of Internal Auditors. Internal Audit Oversight – The Audit Committee Strong ELCs don’t replace the granular controls, but weak ELCs undermine them. A code of conduct that leadership visibly ignores signals to employees that the detailed controls don’t really matter either.
Process-level controls (PLCs) are the granular, transaction-specific activities described throughout the business cycle examples above. The three-way match in accounts payable, the daily cash reconciliation in the revenue cycle, and the payroll register comparison are all PLCs. Their design flows directly from the entity-level risk assessment: management identifies a risk, then builds a process-level control to address it.
The COSO Framework Behind These Categories
Almost every U.S. public company uses the framework published by the Committee of Sponsoring Organizations of the Treadway Commission (COSO) to design and evaluate its controls. The framework organizes internal control into five components: the control environment (organizational culture around integrity and accountability), risk assessment (identifying what could go wrong), control activities (the concrete examples covered above), information and communication (getting the right data to the right people, including whistleblower channels), and monitoring activities (ongoing reviews confirming controls still work).5Committee of Sponsoring Organizations of the Treadway Commission. Internal Control – Integrated Framework SEC rules require management to base its annual ICFR evaluation on a “suitable, recognized control framework,” and COSO is the one virtually every U.S. public company selects.6eCFR. 17 CFR 240.13a-15 – Controls and Procedures
When a Control Fails
Not every failure is equally serious, and the severity determines who has to be told. A deficiency exists when a control’s design or operation doesn’t allow employees to catch or prevent misstatements in the normal course of their work. A deficiency in design means a necessary control is missing or won’t achieve its objective even if performed perfectly. A deficiency in operation means a properly designed control isn’t being executed correctly or by someone with the right authority.7Public Company Accounting Oversight Board. AS 2201 – An Audit of Internal Control Over Financial Reporting That Is Integrated with an Audit of Financial Statements
A significant deficiency is more serious than a standalone deficiency but less severe than a material weakness. It’s important enough that the people overseeing financial reporting, typically the audit committee, need to know about it.
A material weakness is the most severe classification. It means there’s a reasonable possibility that a material misstatement in the financial statements won’t be caught in time. When a material weakness exists, management must disclose it publicly in the company’s annual report on Form 10-K and cannot conclude that ICFR is effective. The company must also disclose material changes to its controls on a quarterly basis as it works through remediation.8U.S. Securities and Exchange Commission. Office of the Chief Accountant and Division of Corporation Finance The market tends to punish these disclosures harshly, which is why remediation speed matters as much as remediation quality.