INTERNAL CONTROLS
NB: I am going to integrate this with the “Payment and Acquisition Cycle” if you can understand the integration all Cycle will
be a walk in a park, so make sure this makes sense from this Cycle.
The Five Components of Internal Control:
Component Description / Objective
This refers to mainly the attitude of the management towards
1. Control the internal controls (behaviour and leadership; the management is
Environment expected to lead by example if not they are influencing others to not take these
controls serious as well).
Management’s identification and analysis of relevant risks
2. Risk Assessment that may prevent the achievement of business objectives and
determining how those risks should be managed.
These are the actual policies and procedures designed to
mitigate identified risks. Examples include segregation of
3. Control Activities
duties, authorization procedures, reconciliations, access
controls, and documentation controls.
Ensures that relevant, accurate, and timely information flows
4. Information and throughout the entity both internally (between departments)
Communication and externally (to stakeholders). (If there was not sharing of
data/Masterfile’s from one department to another this could be regarded as lack
of information and communication)
Ongoing or periodic assessments (e.g., internal audits,
5. Monitoring management reviews) that ensure internal controls are
Activities operating as intended and are updated when conditions
change.
Types of Control Activities:
These are the day-to-day mechanisms that safeguard the organization’s assets and
ensure the integrity of operations:
1. Authorization controls – only designated personnel can approve transactions.
(e.g. approval of the requisition by a senior before requisition is sent to the
placing order)
Examples: (You need to know how to apply the following)
1. Pre-approval Requirement Every purchase requisition, order, or payment must be authorized
before being processed. (in Acquisition and payment method)
2. System based controls: In automated systems, digital workflows restrict access, employees
cannot override approval hierarchies.
3. Documentation: The authorization should be traceable (signatures, approval logs, or system
timestamps).