What it means
Controls are usually grouped into preventive controls, which stop something going wrong in the first place, and detective controls, which find problems after they occur. Requiring approval before a purchase order is raised is preventive; reconciling the supplier ledger at month end is detective.
A well designed system uses both, because prevention is never perfect and detection alone leaves losses to be recovered rather than avoided. Three ideas do most of the work in practice.
Segregation of duties splits a task so no single person can both create and approve a transaction, authorisation limits define who can commit the business to what, and reconciliation compares two independent records to confirm they agree. Almost every control failure that ends in a loss traces back to a weakness in one of these three.
Controls also depend heavily on the culture around them, often called the control environment. If senior managers routinely override approval limits or sign off on incomplete documentation, staff learn that the rules are decorative.
Tone from the top is not a soft concept here; it is what determines whether a control operates or merely exists on paper. Cost matters as well.
Every control consumes time and slows something down, so the sensible test is whether it costs less than the risk it addresses. A $5 approval threshold in a company that processes thousands of small purchases creates queues without meaningfully reducing exposure, while the same principle applied at $5,000 might be exactly right.
Growth is where control systems most often break. Arrangements that worked when the founder personally saw every payment stop working at thirty staff, and the gap usually shows up as a duplicate payment, a misstated stock figure or an unpleasant surprise at audit.
Reviewing controls when headcount, systems or transaction volumes change materially is far cheaper than discovering the gap afterwards. Evidence is the other thing that separates a working control from a claimed one.
If a manager says invoices are reviewed before payment but there is no signature, system approval record or dated note showing it happened, an auditor will treat the control as absent no matter how diligent the manager actually is. Building the evidence into the workflow, usually through approvals recorded in the accounting system, avoids the tedious job of reconstructing it later.
In practice
Real-world examples.
Example
A wholesaler requires that new supplier bank details are confirmed by a phone call to a previously known number before any payment is released. When a convincing email asks for account details to be changed on a $46,000 invoice, the call to the supplier stops the fraud.
Example
A restaurant group reconciles till takings to bank deposits daily and investigates any variance above $50. The routine surfaces a pattern of small unexplained shortfalls at one site, which turns out to be a refund process being misused.
Example
A charity separates the person who records donations from the person who banks them, and has a third person review the monthly summary. The arrangement means no individual can divert income and conceal it in the records.
Think of it
“Internal control is the system preventing errors and fraud-processes to keep things right.
Case study
Seen in the real world.
Copperfield Interiors is a fictional furniture retailer used here as an illustrative example. As a ten person business the founder approved every payment personally, which functioned well enough as an informal control.
By the time headcount reached forty five, payments were being processed by two staff and the founder was signing batch approvals without reviewing individual lines. A duplicate supplier invoice for $18,000 was paid twice over three months before anyone noticed, and only because the supplier flagged the credit balance.
Copperfield introduced three specific controls: automated duplicate invoice detection in the accounting system, a rule that the person who set up a supplier could not approve payments to it, and a monthly supplier statement reconciliation. In this invented account the changes took a fortnight to implement and recovered their cost within the first quarter.
Watch out
Common mistakes.
- Writing controls into a procedure manual and assuming they operate, when nobody checks whether the approval or reconciliation actually happens each month.
- Allowing senior managers to bypass controls for convenience, which quietly signals to everyone else that the rules are optional.
- Adding more controls after every incident until the process is so slow that staff invent workarounds, which creates new risks rather than removing old ones.
Questions
People also ask.
What is segregation of duties?
It is splitting a process so that the person who initiates a transaction is not the person who approves or records it, which makes concealed fraud much harder.
Can a very small business achieve segregation of duties?
Not fully, but it can compensate with owner review of bank statements, dual bank authorisation and periodic independent checks of key records.
Do internal controls guarantee that fraud will not happen?
No, they provide reasonable assurance rather than certainty, because collusion and management override can defeat even well designed controls.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%