An internal check is a procedural safeguard that splits financial tasks across multiple people so that no single employee can process a transaction from start to finish without someone else reviewing the work. One person’s output automatically becomes another person’s input to verify, which catches errors and blocks fraud at the transaction level. The system rests on three components: segregation of duties, independent verification and reconciliation, and physical and access controls.
How an Internal Check Differs From Internal Controls
The two terms get used interchangeably, but they aren’t the same thing. “Internal controls” is the umbrella term for every policy and procedure governing a business. An internal check is narrower. It zooms in on the cross-verification, reconciliation, and authentication of financial data and physical assets at the point where transactions actually happen.
Put differently, internal checks sit inside the broader internal control framework and do specific work within it. That framework, as recognized by the COSO Internal Control–Integrated Framework and the U.S. Government Accountability Office’s Green Book, has five components: control environment, risk assessment, control activities, information and communication, and monitoring.1U.S. Government Accountability Office. The Green Book: Standards for Internal Control in the Federal Government Internal checks live mainly in the control activities and monitoring layers.
The purpose is practical. Internal checks protect cash, inventory, and proprietary data. They give management reliable numbers to work from, because when data is cross-checked before it’s finalized, everything downstream is more trustworthy. And they standardize how work gets done: when every accounts payable clerk follows the same approval steps, there’s less ambiguity, fewer corrections, and a clear trail showing who did what.
Segregation of Duties
Segregation of duties is the single most important component. The rule is that three core functions should always be handled by different people: authorizing transactions, recording those transactions, and having physical custody of the related assets.2Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet When one person controls all three, both mistakes and fraud become dramatically easier.
A concrete example makes it clear. The employee who approves vendor invoices for payment should not also maintain the accounts payable ledger, and neither of them should be the person who signs checks. If one person did all three, they could create a fictitious vendor, approve fake invoices, record payments to that vendor, and pocket the checks. Separating those responsibilities means any attempt at fraud requires collusion between multiple people, which is harder to pull off and easier to detect.
The same logic applies across every transaction cycle. In cash receipts, the person who opens the mail and logs incoming payments should not be the one making the bank deposit or posting to customer accounts. In payroll, the person who adds new employees to the system should not also approve timesheets or distribute paychecks. The goal never changes: force a second pair of eyes onto every step that involves money or assets.
Independent Verification and Reconciliation
Segregation prevents one person from controlling a whole process. Independent verification goes further by actively checking whether the recorded numbers match reality. This is the detective layer that catches what the preventive layer missed.
Bank Reconciliations
The most familiar example is the bank reconciliation. Someone independent of the cash receipts and disbursement process compares the company’s cash ledger against the bank’s statement to confirm they agree. Standard practice calls for performing this reconciliation at least monthly. The person doing the reconciliation should not be involved in recording cash transactions. That independence is what gives the reconciliation its value as a control.
Three-Way Matching
Before paying a vendor invoice, many businesses run a three-way match comparing the original purchase order authorizing the buy, the delivery receipt confirming the goods arrived, and the vendor’s invoice requesting payment. All three must agree on quantities, prices, and descriptions. Any mismatch freezes the payment until someone investigates. This simple comparison catches duplicate invoices, overbilling, and deliveries that don’t match what was ordered.
Physical Inventory Counts
For inventory and fixed assets, independent verification means periodic physical counts performed by people who don’t manage the inventory records or have custody of the goods. When the actual count doesn’t match what the records say, the discrepancy signals potential theft, damage, or recording errors. Auditing standards recognize that well-kept perpetual inventory records checked periodically against physical counts provide reliable inventory data, and the auditor’s role includes evaluating whether those counting procedures are effective.3Public Company Accounting Oversight Board. AS 2510 Auditing Inventories
Physical and Access Controls
The third component is restricting who can physically get to valuable assets. That includes locked safes for cash deposits and negotiable instruments, keycard-restricted access to inventory warehouses, and sign-in logs tracking who enters and leaves secure areas. Physical controls work hand in hand with segregation of duties: the duties separate responsibility for recording, while the physical barriers protect what’s being recorded.
In a digital environment, access controls serve the same function. User permissions should limit each employee to only the systems and records their job requires. Financial software should maintain automated audit trails that log every login, transaction, modification, and deletion, with timestamps and user IDs that can’t be altered after the fact. Digital signatures add a layer of authentication, and failed login attempts should be tracked alongside successful ones. These IT controls have become just as important as the locked safe, because most financial records now exist only as data.
Preventive Versus Detective Checks
Internal checks split into two categories, and the difference matters when you’re designing a system or evaluating whether yours has gaps.
Preventive checks stop errors and fraud before they happen. Segregation of duties is the classic example. By splitting responsibilities, you keep a single person from completing a fraudulent transaction on their own. Access restrictions, approval requirements above a certain dollar amount, and automated spending limits all fit here. The three-way match is preventive too, because it blocks payment before money goes out the door.
Detective checks find problems after they’ve occurred. Bank reconciliations, physical inventory counts, surprise audits, and budget-to-actual variance reviews all fall into this category. They don’t prevent the initial error or theft, but they catch it quickly enough to limit damage and trigger an investigation. Most effective systems layer both types, so when a preventive check fails, a detective one picks it up.
What This Looks Like in Practice
The components above have to be tailored to each area of the business. Cash handling demands the tightest checks because cash is the easiest asset to steal and the hardest to trace. Sales, inventory, and payroll each carry their own risk profiles.
Cash Receipts and Disbursements
For cash coming in, the key principle is immediate recording. When mail arrives with customer payments, two people should open it and create a log of every check before anything moves to the deposit process. The person preparing the bank deposit should not be the same person posting receipts to customer accounts in the ledger.2Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet This separation is designed to prevent skimming, where an employee pockets a cash payment before it ever hits the books, and lapping, where an employee steals a payment and covers the shortfall by applying the next customer’s payment to the first account.
For cash going out, dual authorization on payments above a set threshold is common and effective. Two managers must approve the payment before it’s released. All checks and payment documents should be pre-numbered sequentially so any gap in the sequence is immediately visible and traceable.4U.S. Government Accountability Office. Internal Control Management and Evaluation Tool Voided checks should be retained, not destroyed. Blank check stock belongs in a locked location with restricted access.
Sales and Accounts Receivable
Checks in the sales cycle make sure goods ship only to creditworthy customers and that every shipment gets billed accurately. Before extending credit above a set dollar limit, an independent credit review should confirm the customer’s ability to pay. Keeping credit approval separate from the sales function prevents salespeople from overriding credit limits to close deals, which is a common source of bad debt.
The billing department should match the customer’s order, the shipping documentation, and the approved price list before generating an invoice. Any mismatch halts invoicing until someone resolves the discrepancy. Credit memos and sales returns need their own checks: every credit memo should require approval from someone outside the sales team and be evaluated against the customer’s account balance and the company’s credit policy. Without this step, credit memos become an easy way to siphon money, because an employee can issue a fraudulent credit to a customer’s account and pocket the refund.
Inventory and Fixed Assets
Inventory controls address both physical security and accurate valuation. Access to storage areas should be limited to a small group of authorized custodians, with a log or electronic system tracking everyone who enters and exits. Periodic physical counts, conducted by people independent of inventory custody and record-keeping, are the primary detective check. Reconciling those counts against recorded balances highlights shrinkage, damage, or recording errors that need immediate investigation.
Fixed assets need their own ledger and periodic verification that each recorded asset actually exists and remains in use. Companies with large equipment or vehicle fleets often discover through these checks that assets were disposed of or transferred without updating the records, which distorts both the balance sheet and depreciation expense.
Payroll
Payroll is one of the most fraud-prone areas in any organization, and the most damaging scheme is the ghost employee: a fictitious person added to the payroll whose checks get funneled to the fraudster. Industry data shows payroll fraud schemes typically run for roughly 30 months and cause median losses around $90,000 before anyone catches them.
The core checks mirror the general principles. The person who adds new employees to the payroll system should not also approve timesheets or distribute payments. HR should independently verify that every name on the payroll corresponds to a real, active employee, checking for duplicate Social Security numbers, employees no one in the office recognizes, and multiple employees sharing the same bank account for direct deposit. Regular reconciliation of payroll reports against headcount records and performance evaluations catches the gaps that ghost employee schemes create.
When You Don’t Have Enough Staff to Separate Duties
Everything above assumes enough staff to separate duties cleanly. Most small businesses don’t have that. When three people run the entire finance function, you can’t assign authorization, record-keeping, and custody to three different individuals because you only have three individuals doing everything.
This is where compensating controls come in. They don’t replace segregation of duties, but they reduce the risk when full separation isn’t possible.
- The business owner personally reviews bank statements monthly, examines canceled checks, and looks for unfamiliar payees or amounts. The simple fact that employees know this review happens acts as a deterrent.
- Even in a three-person office, requiring two people to approve any payment above a certain amount limits the damage a single employee can do.
- Hiring an outside bookkeeper or accountant to perform bank reconciliations and spot-check transactions adds an independent set of eyes the internal team can’t influence.
- Expense management software that enforces spending limits, automated invoice matching that flags discrepancies, and accounting systems that require approval workflows before posting entries can all substitute for the human separation that larger organizations enjoy.
The underlying principle for small businesses is transparency. When you can’t separate every function, compensate by making every transaction visible to someone who isn’t the person who initiated it.
Keeping the System Working
Designing internal checks is the first step. Keeping them working is the harder part. The system needs to be formalized in a procedures manual that documents each transactional process, assigns responsibilities, and identifies every verification point. That manual guides employees through their daily work and gives auditors a benchmark for testing whether the checks are operating as intended.
Employees need recurring training on these procedures, not just during onboarding but periodically after. People forget steps, shortcuts creep in, and turnover brings new staff who may never have seen the manual. Training reinforces that the checks exist for a reason and that circumventing them has consequences.
The system also needs independent review. An internal audit team or external accounting firm should regularly test whether the checks are functioning as designed, which means not just confirming that procedures exist on paper but verifying through sample testing that people are actually following them. When testing reveals a check that’s been bypassed or rendered ineffective, and eventually it will, the deficiency has to be fixed, the procedures updated, and the fix retested to confirm it holds. Internal checks are not a set-it-and-forget-it proposition. They need the same ongoing attention as the financial records they’re designed to protect.