Control Environment and Risk Assessment
The foundation everything else rests on.
12 min
What internal control is for
Internal control is the set of processes designed to provide reasonable assurance that the organisation achieves reliable financial reporting, effective and efficient operations, compliance with laws and regulations, and safeguarding of assets. Note “reasonable”: no system provides absolute assurance, because controls cost money, can be overridden by management, and can be defeated by collusion.
The components
The widely used framework identifies five interdependent components:
- Control environment — integrity, ethical values, competence, governance structure, authority and accountability. This is the foundation, and a weak environment defeats every control built on it.
- Risk assessment — identifying what could go wrong and how significant it would be.
- Control activities — the actual procedures: authorisation, reconciliation, segregation, physical safeguards, review.
- Information and communication — people knowing what is expected and having the information to do it.
- Monitoring — checking that controls are still operating, not merely that they were designed.
Tone at the top
The most important control is not a procedure. It is whether senior people follow the rules themselves, whether concerns can be raised safely, and whether results are pursued in a way that makes people feel they must achieve them by any means. An executive who is exempted from the approval process, or who reacts badly to a challenge, disables the entire framework regardless of how well documented it is.
Assessing risk
- Identify what could go wrong in each significant process — error, loss, misstatement, theft, non-compliance.
- Assess likelihood and impact, considering both financial and reputational consequences.
- Identify the existing controls and whether they actually address that risk.
- Evaluate the residual risk after controls.
- Decide whether to accept it, add control, transfer it through insurance, or avoid the activity.
Consider fraud risk explicitly and separately. Ordinary error controls assume nobody is deliberately trying to defeat them; fraud controls must assume someone is.
Types of control
- Preventive — stop it happening: authorisation limits, system access restrictions, segregation of duties, locked stores. Generally more valuable than detective controls because the loss never occurs.
- Detective — find it afterwards: reconciliations, exception reports, physical counts, audits.
- Corrective — put it right and prevent recurrence.
- Directive — policies, training and procedures that set the expectation.
Proportionality
Controls cost money and time, and excessive control has real costs: delay, frustration, and people routing around the process. The test is whether the cost of the control is proportionate to the risk it addresses. A three-signature approval for a small purchase costs more than it saves, and it devalues the approval process for transactions where it matters. Concentrate control effort where the exposure is genuinely significant.