African audit team reviewing internal control processes
AnalysisRisk and compliance24 July 20267 min read

Internal control: why a procedures manual is not enough

A procedures manual is a useful foundation. It describes what should happen. Internal control becomes real when responsibilities are understood, controls operate, exceptions are resolved and the framework is regularly adjusted to the organisation's risks.

01

The danger of treating the document as the outcome

Many organisations invest in a detailed manual, approve it and then assume that risk is under control. A few months later, teams have bypassed certain steps, tools have changed, new activities have appeared and delegations no longer match reality. The document exists, but the operating system has moved away from it.

This gap is more than a compliance issue. It creates duplication, delays, decisions made with incomplete information and areas where nobody knows who should control what. Internal control should therefore be designed as a living cycle that supports operations, reporting and compliance.

02

Five components that must work together

The COSO framework explains that effective internal control depends on several interconnected components. Translating them into day-to-day practice requires more than documenting procedures.

  • A clear control environment: leadership example, delegations, capabilities and accountability.
  • Risk assessment connected to objectives and updated as the context changes.
  • Proportionate control activities embedded in processes and systems.
  • Useful information that reaches the right level at the right time.
  • Ongoing monitoring that identifies failures, follows action plans and measures progress.
03

Start with risk, not habit

The most effective approach connects every process to the objectives it supports and then identifies the events that could prevent those objectives from being achieved. This makes it possible to distinguish essential controls from historical checks that consume time without materially reducing exposure.

Every key control should answer simple questions: which risk does it cover? Who performs it? How often? What evidence is retained? Who reviews exceptions? What happens when it fails? Without clear answers, the framework remains difficult to test and manage.

04

Give ownership to controls and exceptions

Internal control cannot be delegated solely to internal audit, compliance or finance. Operating teams own processes and therefore need to own the controls that protect them. Control functions provide methodology, independent challenge and escalation capacity.

A simple accountability matrix should make that allocation visible. It identifies the risk owner, control performer, reviewer and recipient of alerts. It also helps resolve weaknesses at source instead of accumulating findings without an owner or deadline.

05

A ninety-day plan to restart the system

The entire framework does not need to be rewritten immediately. A focused programme can begin with the most critical processes and deliver visible improvements.

  • Select priority risks using objectives, incidents, audit findings and recent changes.
  • Field-test a sample of key controls and review the evidence that is actually available.
  • Remove duplication, clarify accountability and automate repetitive checks where appropriate.
  • Introduce a short dashboard covering missed controls, exceptions, remediation deadlines and residual risk.
  • Update the manual to reflect the improved operating model and establish a periodic review cycle.

Sources and reference material

This publication provides general information and does not constitute accounting, legal, tax or investment advice tailored to a specific situation.

A question about this topic?

Turn analysis into practical decisions.

Speak with our team