Back to Glossary

Entry · Accounting

Detective Control

A detective control is a procedure designed to find errors, fraud or policy breaches after they have already occurred. Reconciliations, exception reports, stock counts and internal audits are all detective controls, because each looks backwards at completed activity to see what went wrong.

They sit alongside preventive controls, which try to stop problems happening in the first place.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

Internal control frameworks split safeguards into three broad types. Preventive controls block a bad transaction before it happens, detective controls find it afterwards, and corrective controls fix the damage and stop a repeat.

A healthy finance function needs all three, because no preventive control catches everything. Detective controls matter because prevention is never complete and is often expensive.

Requiring two approvals on every payment is preventive but slows the business down, whereas a monthly review of all payments above a threshold catches the same problems at a fraction of the operational cost. The trade-off is time: the error has already happened and money may already have left the building.

The typical detective controls in a business are bank reconciliations, supplier statement reconciliations, physical stock counts against system records, exception reports for duplicate invoices or out-of-hours logins, and management review of variances against budget. Each works the same way, by comparing two independent records of the same reality and investigating any difference.

If the comparison is not independent, the control is close to worthless. Auditors care about detective controls because they generate evidence.

A reconciliation performed, signed, dated and reviewed leaves a trail that an auditor can test, whereas an undocumented review leaves nothing behind. This is why control design almost always insists on a record of who performed the check and what happened to the exceptions found.

The nuance worth carrying is that a detective control only works if the exceptions it produces are actually investigated. Plenty of organisations run reports nobody opens, or reconcile accounts and then write off unexplained differences to a suspense account.

A control that detects and then ignores is a control in name only. The frequency question is where judgement enters.

Running a detective control daily catches problems while they are small but consumes resource, while running it annually is cheap and lets errors compound for eleven months. Most teams tune frequency to the value flowing through the process and the speed at which a problem would become unrecoverable.

In practice

Real-world examples.

1

Example

A hotel group reconciles its point-of-sale takings against bank deposits every morning. A recurring $340 daily shortfall at one property is identified within a week, and the investigation uncovers a till procedure being bypassed at shift change.

2

Example

A software company runs a monthly exception report listing every user account with system access but no corresponding record in the payroll system. Three accounts belonging to contractors who left months earlier are found and disabled.

3

Example

A distributor performs quarterly cycle counts on its highest-value stock lines instead of one annual full count. A 40-unit discrepancy in a $900 component is caught in the second quarter rather than being discovered eight months later.

Formula

Calculation

Exception rate = (Exceptions found / Items tested) x 100. Net benefit of the control = Estimated annual value of exceptions detected - Annual cost of running the control. A finance team runs a monthly detective review over supplier invoices. In one month it tests 1,200 invoices and finds 18 exceptions, giving an exception rate of 18 / 1,200 x 100 = 1.5%. The 18 exceptions have a combined value of $27,000, so the average exception is $27,000 / 18 = $1,500. If that month is representative, the annual number of exceptions is 18 x 12 = 216, with an estimated annual value of 216 x $1,500 = $324,000. The review takes one analyst roughly a week each month, costing about $60,000 a year fully loaded. The net benefit is $324,000 - $60,000 = $264,000, which is the figure a finance director would use to defend keeping the control in place.

Case study

Seen in the real world.

Ardley Components is an illustrative, fictional electronics distributor that relied almost entirely on preventive controls in its purchasing process. Every purchase order needed two approvals, which the team believed made errors close to impossible, so no routine detective review of supplier payments existed.

Over fourteen months the company paid the same supplier twice for eleven separate shipments, totalling just over $190,000. The duplicate payments passed both approvals every time, because each individual payment looked entirely legitimate on its own; the problem was only visible by comparing payments across time, which nothing in the process ever did. The issue surfaced only when the supplier itself flagged a credit balance.

Ardley introduced a monthly detective control that matched supplier payments against invoice numbers and amounts and flagged near-duplicates for review. The report took an analyst two days a month to work through and recovered a further $31,000 in its first quarter. The fictional example shows the specific gap detective controls fill: catching patterns that no single-transaction approval can ever see.

Watch out

Common mistakes.

  • Assuming strong preventive controls make detective controls unnecessary, when many errors are only visible by comparing transactions across time.
  • Running exception reports that nobody reviews, which produces the appearance of control without any of the substance.
  • Letting the person who processes the transactions also perform the reconciliation, which removes the independence the control depends on.

Questions

People also ask.

What is the difference between a preventive and a detective control?

A preventive control stops a problem before it happens, while a detective control identifies it after the fact so it can be corrected.

Are detective controls enough on their own?

No, because they find problems only after money or data has already moved, so they work best paired with preventive and corrective controls.

How often should a detective control run?

Match the frequency to the value and speed of the process, so high-value daily transactions warrant daily or weekly review while low-risk areas may need only quarterly checks.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.