Internal controls for small businesses: the eight that matter most
Segregation of duties is hard with a small finance team. These are the eight controls that matter most, and how to run each one with the people you actually have.
Internal controls have a reputation as something for big companies with compliance departments. In reality, a growing business needs them more: fewer people means more reliance on each one, and a single mistake or fraud is a bigger share of the profit.
The good news is that a small business does not need hundreds of controls. It needs the right eight, run consistently, with evidence that they happened.
Why small teams struggle with controls
The textbook answer to most finance risk is segregation of duties: the person who approves a payment should not be the person who makes it. With two or three people in finance, that is often impossible.
The practical answer is compensating controls: where one person must do several steps, someone else reviews the result. An owner who looks through the payment run before it is released is doing exactly that.
The eight controls that matter most
1. Payment approval
Every payment over a set threshold is approved by someone other than the person who prepared it. Below the threshold, a periodic review of payments made is enough. Set the threshold so the approver sees most of the money, not most of the transactions.
2. Supplier master changes
New suppliers and changes to bank details are one of the most common routes for payment fraud. Every change should be verified by calling the supplier on a number you already hold, never one in the email requesting the change, and approved by a second person.
3. Bank reconciliation, reviewed
Reconciling the bank is not enough; someone should review and sign off the reconciliation, and old unreconciled items should be investigated, not carried forward month after month.
4. Manual journal review
Manual journals are where errors, and occasionally fraud, hide. Any manual journal above a threshold, or any journal to sensitive accounts such as revenue, cash or payroll, should be reviewed by someone who did not post it.
5. Payroll changes
New starters, pay rises and bank detail changes in payroll should be approved outside the payroll function. A monthly comparison of payroll to headcount catches ghost employees and leavers who were never removed.
6. Credit notes and write-offs
Revenue can leave quietly through credit notes and bad debt write-offs. Both should need approval, and a monthly report of them should go to someone senior.
7. System access
Who has admin rights in the accounting system and the bank? Who can both create a supplier and pay one? Review access quarterly, and remove leavers the day they go.
8. Stock counts, where you hold stock
Regular counts, with differences investigated and approved before they are written off, protect one of the largest assets on most distributors’ balance sheets.
Evidence: if it is not written down, it did not happen
A control that leaves no trail is invisible to an auditor, a lender or a buyer. The evidence does not need to be elaborate: an approval in the system, an initial and date on a reconciliation, a saved email. What matters is that it exists and can be found.
Start with the risks, not a template
Every business has different weak points. A distributor’s biggest risk may be stock; a services firm’s may be billing; a business with many suppliers may be most exposed to bank detail fraud. Start by asking where the money could leave without anyone noticing, and put controls there first.
When to get help
If you are preparing for a first audit, raising finance or selling the business, controls are about to be looked at closely by someone else. Our internal controls review tests how your key processes actually operate and gives you a practical plan sized for the team you have. For the full year-end picture, see our audit readiness checklist.
Share this