
Internal control: why a procedures manual is not enough
A procedures manual is a useful foundation. It describes what should happen. Internal control becomes real when responsibilities are understood, controls operate, exceptions are resolved and the framework is regularly adjusted to the organisation's risks.
The danger of treating the document as the outcome
Many organisations invest in a detailed manual, approve it and then assume that risk is under control. A few months later, teams have bypassed certain steps, tools have changed, new activities have appeared and delegations no longer match reality. The document exists, but the operating system has moved away from it.
This gap is more than a compliance issue. It creates duplication, delays, decisions made with incomplete information and areas where nobody knows who should control what. Internal control should therefore be designed as a living cycle that supports operations, reporting and compliance.
Five components that must work together
The COSO framework explains that effective internal control depends on several interconnected components. Translating them into day-to-day practice requires more than documenting procedures.
- A clear control environment: leadership example, delegations, capabilities and accountability.
- Risk assessment connected to objectives and updated as the context changes.
- Proportionate control activities embedded in processes and systems.
- Useful information that reaches the right level at the right time.
- Ongoing monitoring that identifies failures, follows action plans and measures progress.
Start with risk, not habit
The most effective approach connects every process to the objectives it supports and then identifies the events that could prevent those objectives from being achieved. This makes it possible to distinguish essential controls from historical checks that consume time without materially reducing exposure.
Every key control should answer simple questions: which risk does it cover? Who performs it? How often? What evidence is retained? Who reviews exceptions? What happens when it fails? Without clear answers, the framework remains difficult to test and manage.
Give ownership to controls and exceptions
Internal control cannot be delegated solely to internal audit, compliance or finance. Operating teams own processes and therefore need to own the controls that protect them. Control functions provide methodology, independent challenge and escalation capacity.
A simple accountability matrix should make that allocation visible. It identifies the risk owner, control performer, reviewer and recipient of alerts. It also helps resolve weaknesses at source instead of accumulating findings without an owner or deadline.
A ninety-day plan to restart the system
The entire framework does not need to be rewritten immediately. A focused programme can begin with the most critical processes and deliver visible improvements.
- Select priority risks using objectives, incidents, audit findings and recent changes.
- Field-test a sample of key controls and review the evidence that is actually available.
- Remove duplication, clarify accountability and automate repetitive checks where appropriate.
- Introduce a short dashboard covering missed controls, exceptions, remediation deadlines and residual risk.
- Update the manual to reflect the improved operating model and establish a periodic review cycle.
Sources and reference material
This publication provides general information and does not constitute accounting, legal, tax or investment advice tailored to a specific situation.


