Risk Advisory
Internal financial controls: making the reporting requirement useful
IFC reporting is a statutory obligation. Treated properly, it is also the cheapest diagnostic your finance function will get.
Reporting on internal financial controls over financial reporting is a statutory requirement for most companies. It is also, for many finance teams, an annual box-ticking ritual that produces a folder nobody opens. That is a waste of the one exercise that systematically maps how your numbers are actually produced.
Start with the risk, not the control
The common failure is to begin by listing controls that exist and then reverse-engineer risks to justify them. Done properly, the sequence runs the other way: identify what could go materially wrong in each significant account, then ask what stops it.
For revenue, the risks are recognition timing, completeness of billing, and unauthorised credit notes. For procurement, they are unauthorised vendors, duplicate payments and price overrides. Name the risk in a sentence a business person would recognise.
Design before you test
A control that is well operated but poorly designed provides no assurance. Before testing whether the monthly reconciliation was performed, ask whether the reconciliation would actually catch the error you are worried about — and whether the person performing it has the information and the authority to act on a difference.
Design questions worth asking of every key control:
- Who performs it, and are they independent of the transaction?
- What evidence does performance leave behind?
- What is the threshold, and who set it?
- What happens when the control fails — is there a documented escalation?
Entity-level controls do heavy lifting
Delegation of authority, the code of conduct, the whistleblower channel, the budget process and the board's review of results are entity-level controls. When they work, they reduce how much transaction-level testing is needed. When they are nominal, no amount of transaction testing compensates.
Automate the evidence
The most common testing failure is not that the control did not happen, but that nobody can prove it did. Where the control lives in a system, configure it to leave a log. Where it is manual, standardise the evidence — a signed checklist, a dated review note, a workflow approval — so that testing becomes a retrieval exercise rather than an archaeology project.
Use the output
The gap list produced at the end of an IFC exercise is a prioritised map of where your financial reporting is fragile. Read it as a management document, assign owners and dates, and revisit it at the half year. Companies that do this find the second year's exercise takes a fraction of the effort — and the auditors have far less to write about.
General information only. This note reflects the position as we understood it on 14 March 2026. It is not advice on your circumstances — please take advice before acting. See our disclaimer.
Let’s talk about what is actually in front of you.
A notice to answer, an audit to plan, a deal to price, or a compliance calendar that has got away from you — a short conversation usually tells us both whether we fit.