What Are Internal Controls?

Internal controls are the policies, procedures, practices, and mechanisms that an organisation puts in place to manage risk, safeguard assets, ensure the reliability of its financial and operational information, and comply with applicable laws and regulations. They are the practical mechanism through which risk management moves from a register entry to something that actually happens in daily operations.
5 min read time

Internal controls are the policies, procedures, practices, and mechanisms that an organisation puts in place to manage risk, safeguard assets, ensure the reliability of its financial and operational information, and comply with applicable laws and regulations. They are the practical mechanism through which risk management moves from a register entry to something that actually happens in daily operations.

The Committee of Sponsoring Organisations of the Treadway Commission defines internal control as a process, effected by the entity's board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives relating to operations, reporting, and compliance. Three elements of that definition deserve attention. It is a process, not a document or a policy. It is effected by people at every level of the organisation, not only by a compliance function. And it provides reasonable assurance, not certainty.

No control system eliminates risk entirely. The question is whether the controls in place are adequate to reduce the risks they address to within the organisation's risk appetite.

Why Internal Controls Exist

The Three Objectives

The COSO framework organises the objectives that internal controls support into three categories: operations, covering the effectiveness and efficiency of the organisation's activities; reporting, covering the reliability of internal and external financial and non-financial reporting; and compliance, covering adherence to applicable laws and regulations.

Each objective type has different primary stakeholders. Operations controls primarily serve management, ensuring that activities run as intended and that resources are used effectively. Reporting controls primarily serve the board, investors, and regulators, providing the assurance needed to rely on financial and operational information. Compliance controls serve both internal and external stakeholders, demonstrating that legal and regulatory obligations are being met.

The Governance Chain

Controls connect to governance through the three lines model. The IIA's Three Lines Model places operational management in the first line, responsible for designing, implementing, and operating controls as part of running the business. The risk and compliance function in the second line provides oversight, challenge, and consolidated assurance. Internal audit in the third line provides independent verification that the controls the first and second lines claim are in place are actually working.

The board and audit committee receive assurance from this chain and use it to exercise governance. A board that relies on management assertions about control effectiveness without independent verification is not exercising adequate governance.

Types of Internal Controls

Preventive Controls

Preventive controls are designed to stop a risk event from occurring before it happens. They act before the failure, making it difficult or impossible for the identified risk to materialise. Segregation of duties, where two or more people must be involved in a sensitive transaction, prevents a single individual from both initiating and approving an action. Access controls that restrict system functions to authorised users prevent unauthorised activity. Input validation rules that reject incorrect data formats before they enter a system prevent data integrity failures.

Preventive controls are generally preferable to detective ones where they are practical, because prevention avoids the harm entirely. However, no set of preventive controls can address every possible failure mode, and preventive controls can themselves be circumvented or fail. Detective controls provide the second layer.

Detective Controls

Detective controls identify that a risk event has occurred or is occurring, enabling investigation and remediation. A bank reconciliation comparing two independent data sources and flagging discrepancies is a detective control. Exception reports that surface transactions outside defined parameters are detective controls. Monitoring of access logs to identify unusual system activity is a detective control.

The value of a detective control depends entirely on what happens when it detects something. A detective control that consistently identifies exceptions but triggers no meaningful investigation has not reduced the risk. It has produced evidence of failure without remediation. Detection is only valuable when it leads to timely and effective response.

Directive Controls

Directive controls set expectations for how people should behave: policies, procedures, code of conduct commitments, and standards. They are the foundation on which other controls are built, providing the rules that preventive and detective controls enforce. A segregation of duties policy defines what must be separated. A data handling standard defines how sensitive information must be managed. An authorisation policy defines what approvals are needed.

Directive controls are necessary but not on their own sufficient. A policy that no one follows is not a functioning control. The implementation and consistent application of directive controls is what gives them governance value.

Corrective Controls

Corrective controls come into play after a failure has been identified: root cause analysis, remediation plans, process improvements, and verification that changes have been effective. A corrective control that addresses the immediate failure without identifying and fixing the underlying cause will typically produce a repeat of the same failure.

Effective corrective controls close the loop: identify what went wrong, understand why it happened, fix the underlying condition, and verify that the fix has worked. Incident management processes that track findings to genuine resolution rather than to a remediation action that is logged but never followed up are essential for corrective controls to deliver their intended purpose.

Manual versus Automated Controls

The distinction between manual and automated controls cuts across all four types and significantly affects how they are assessed and what evidence of their operation looks like.

Manual controls depend on human action: a manager performing a review, an operator completing a reconciliation, a staff member obtaining an approval. They are inherently susceptible to inconsistency, particularly under time pressure, high workload, or when the perceived consequence of bypassing the control seems minor. Testing manual controls requires evidence that the human action was performed by the right person, using the right information, at the right frequency.

Automated controls are embedded in technology systems and operate without human discretion on each transaction. They are generally more reliable because they do not depend on an individual remembering to perform a step correctly every time. But their reliability depends on the IT general control environment governing the systems they run on. If system access is inadequately controlled, or if changes to system configurations are not properly governed, automated controls may have been modified or may operate incorrectly without detection. Testing automated controls therefore includes examining the IT general control environment as well as the specific automated control itself.

The Control Environment

The control environment is the foundation on which all other elements of internal control rest. It encompasses the tone set by leadership, the organisation's ethical values and culture, the governance structures through which accountability flows, and the commitment to competence and integrity that shapes how people behave when nobody is watching.

The COSO Internal Control Framework lists the control environment as its first component for a reason. A technically well-designed control framework operating in a culture where circumventing controls is tolerated, where tone at the top does not genuinely reinforce ethical behaviour, or where accountability is nominal rather than real, will perform poorly regardless of its technical quality. Conversely, a strong control environment creates conditions in which controls are respected, exceptions are surfaced rather than concealed, and failures are treated as learning opportunities rather than threats.

Assessing the control environment requires looking beyond documentation to behaviour: does leadership model the values the organisation's policies espouse, are people held accountable when they bypass controls, and is the organisation's culture one in which concerns can be raised without personal risk?

Design Effectiveness and Operating Effectiveness

These two concepts are among the most important in the assessment of internal controls, and the distinction between them is frequently underappreciated.

Design Effectiveness

Design effectiveness asks whether a control, if operated exactly as described, would actually prevent or detect the risk it is intended to address. A control can be consistently applied and well documented and still fail the design test if the logic of the control does not genuinely address the underlying risk.

A monthly management review of summarised financial data is not an adequate preventive control for daily transaction fraud in a high-volume environment. A password complexity policy does not address the risk of authorised users sharing credentials. An annual policy attestation does not control the risk that staff misapply the policy in their daily work. In each case, the control exists and is performed, but it is not designed to address the specific risk it claims to manage.

Design effectiveness assessment requires mapping each control explicitly to the risk it addresses, the assertion or objective it supports, and asking whether the control logic would catch or prevent the specific failure mode the risk describes.

Operating Effectiveness

Operating effectiveness asks whether the control has actually been applied consistently as intended over the period under review, and whether there is evidence of this. A control that is adequately designed but not consistently operated provides no more protection than one that was never implemented.

Operating effectiveness evidence must be actual evidence, not assertions. The IIA's Global Internal Audit Standards are explicit that independent verification, based on actual documentation that the control operated as described, is required. A risk owner's statement that a control is working is not evidence of operating effectiveness.

How Internal Controls Connect to the Wider Risk Framework

Controls sit within the broader risk management framework as the practical mechanism through which identified risks are managed. Each significant risk in the risk register should have explicitly mapped controls, with an assessment of their effectiveness. The gap between inherent risk and residual risk in the risk register is a claim about what those controls are achieving.

When controls are not tested or their effectiveness is assumed rather than evidenced, residual risk ratings become unverifiable assertions rather than evidence-based assessments. The connection between risk management and controls management, ensuring that residual risk ratings reflect what is actually known about control effectiveness rather than what is hoped, is one of the most important governance connections in any well-run organisation.

References and Further Reading

Keywords: what are internal controls, internal controls definition, types of internal controls, preventive detective controls, control environment, COSO internal control, design effectiveness operating effectiveness

Next Steps

Can you prove your controls actually work?

See how calQrisk helps you test and evidence controls across the business.
Book a Demo