Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
5.1 Governance, risk and compliance
5.1.1 Internal control objectives and the COSO Framework
5.1.2 Responsibility for internal control and segregation of duties
5.1.3 Internal control limitations, risks, and deficiencies
5.1.4 Corporate governance structure and responsibilities
5.1.5 Corporate governance roles and responsibilities
5.1.6 External audit
5.1.7 The Sarbanes-oxley Act
5.1.8 Other regulatory bodies
5.2 System controls and security measures
6. Technology and analytics
Achievable logoAchievable logo
5.1.2 Responsibility for internal control and segregation of duties
Achievable CMA Part 1
5. Internal control
5.1. Governance, risk and compliance
Our CMA Part 1 course is currently in development and is a work-in-progress.

Responsibility for internal control and segregation of duties

6 min read
Font
Discuss
Share
Feedback

Who is responsible for internal control?

Responsibility for internal control is distributed across various levels of an organization, with specific roles assigned to individuals and groups within the entity, as well as external parties such as regulators and auditors. A sound internal control system relies on the collaboration of all these players to be effective.

1. Board of directors and audit committee

The Board of Directors and its Audit Committee are primarily responsible for providing high-level oversight and governance of the internal control system. They play a crucial role in setting the overall tone at the top by ensuring that the organization maintains a strong control environment and cultivates an effective risk management culture. Their responsibilities include reviewing and evaluating reports from internal and external auditors to monitor the adequacy, integrity, and performance of the control framework.

2. Senior management (e.g., CEO, CFO)

Senior management, including positions such as the CEO and CFO, is responsible for the design, implementation, and maintenance of internal controls. They play a central role in establishing the control framework by formulating control policies and allocating appropriate resources to ensure effective execution. In addition to technical responsibilities, senior management also sets the ethical tone within the organization, promoting a culture that values integrity and reinforces the importance of adhering to internal control procedures.

3. Operational and functional managers

Operational and functional managers are responsible for applying and monitoring internal controls within their specific areas of responsibility. They ensure that established procedures are properly followed and that risks are identified and addressed in a timely manner. These managers act as the first line of defense by maintaining control activities in day-to-day operations and are expected to report any control issues or deficiencies they observe to senior management for further action.

4. Internal audit function

The internal audit function operates independently from management to assess the adequacy and effectiveness of internal controls across the organization. Internal auditors examine whether controls are properly designed and functioning as intended, and they provide objective recommendations for improvement. To maintain independence and impartiality, they report directly to the audit committee or the board of directors, thereby avoiding conflicts of interest that could compromise their evaluations.

5. Employees

All employees are responsible for complying with the organization’s control policies and procedures in the course of their daily duties. They play a critical role in maintaining the integrity of internal controls by adhering to established protocols and reporting any observed irregularities, control weaknesses, or unethical behavior. Their active participation helps in the early detection and mitigation of potential risks.

6. External auditors

External auditors are responsible for evaluating and reporting on the effectiveness of internal control over financial reporting as part of their audit engagements. While they may offer recommendations to improve identified weaknesses or inefficiencies, they do not take part in the design or implementation of controls in order to preserve their independence and objectivity.

7. Regulators and standard-setting bodies

Regulators and standard-setting bodies are responsible for establishing laws and frameworks that shape internal control practices. For example, the Sarbanes-Oxley Act (SOX) in the United States mandates requirements for internal controls over financial reporting. These external entities may also conduct examinations, request attestations, or require disclosures related to the effectiveness of an organization’s internal control system to ensure transparency, accountability, and compliance with applicable standards.

Segregation of duties

An efficient control environment begins with strong personnel policies and procedures. These policies guide the recruitment, training, supervision, and evaluation of employees, ensuring that competent and trustworthy individuals are placed in positions of responsibility. Clearly defined job descriptions, ethical codes of conduct, and ongoing professional development support a culture of accountability and transparency, which are critical for internal control effectiveness.

Definitions
Segregation of duties
An internal control principle that requires dividing key responsibilities for authorizing transactions, recording transactions, and maintaining custody of related assets among different individuals. By separating these functions, organizations reduce the risk of error, misuse, or fraud and strengthen the system of checks and balances.

The goal of segregation of duties is to ensure that no single individual has control over all aspects of a financial transaction, thereby creating a system of checks and balances.

Key functional responsibilities to segregate

Internal control best practices recommend that the following four types of responsibilities be segregated to different people or departments:

Segregation of accounting duties
Segregation of accounting duties
  1. Authority to execute transactions - This refers to the approval or initiation of transactions. For example, a purchasing manager may have the authority to place orders for goods and services.
  2. Recording transactions - This involves maintaining the accounting records, such as entering transactions into the general ledger or subledgers. A separate accounting staff member would typically perform this function.
  3. Custody of assets - This responsibility includes physical possession or control over assets such as cash, inventory, or fixed assets. For instance, a warehouse supervisor may manage inventory storage and access.
  4. Reconciliation of assets to records - Periodic reconciliation ensures that physical assets match the recorded balances in the accounting system. Ideally, someone who does not have access to assets or records them should perform this task to maintain objectivity.

Failure to segregate these duties increases the risk that errors or fraud could occur and go undetected. For example, if one person is responsible for authorizing payments, recording them, and reconciling bank statements, they could easily conceal unauthorized transactions.

Examples of segregation of duties by department

To illustrate how segregation of duties can be applied in practice, consider the following departmental examples:

Examples of segregation of accounting duties
Examples of segregation of accounting duties

These examples demonstrate how dividing responsibilities helps to reduce the risk of unauthorized transactions and ensure accuracy and accountability in financial operations.

Board of directors and audit committee

  • Provide high-level oversight and governance of internal controls
  • Set organizational tone and risk management culture
  • Review auditor reports to monitor control framework

Senior management (e.g., CEO, CFO)

  • Design, implement, and maintain internal controls
  • Establish control policies and allocate resources
  • Set ethical tone and promote integrity

Operational and functional managers

  • Apply and monitor controls in specific areas
  • Ensure procedures are followed and risks addressed
  • Report control issues to senior management

Internal audit function

  • Independently assess adequacy and effectiveness of controls
  • Provide objective recommendations for improvement
  • Report directly to audit committee or board

Employees

  • Comply with control policies and procedures
  • Maintain integrity by following protocols
  • Report irregularities or control weaknesses

External auditors

  • Evaluate and report on internal control over financial reporting
  • Provide improvement recommendations
  • Maintain independence; do not design or implement controls

Regulators and standard-setting bodies

  • Establish laws and frameworks for internal controls (e.g., SOX)
  • Require disclosures and attestations on control effectiveness
  • Ensure transparency, accountability, and compliance

Segregation of duties

  • Divide responsibilities for authorizing, recording, custody, and reconciliation
  • Reduces risk of error, misuse, or fraud
  • Supports checks and balances in financial transactions

Key functional responsibilities to segregate

  • Authority to execute transactions (approval/initiation)
  • Recording transactions (accounting entries)
  • Custody of assets (physical control)
  • Reconciliation of assets to records (independent verification)

Examples of segregation of duties by department

  • Assign different people to approval, recordkeeping, asset custody, and reconciliation
  • Prevents unauthorized transactions and concealment of errors
  • Enhances accuracy and accountability in operations

Sign up for free to take 8 quiz questions on this topic

Previous
Next  | 5.1.3 Internal control limitations, risks, and deficiencies
All rights reserved ©2016 - 2026 Achievable, Inc.

Responsibility for internal control and segregation of duties

Who is responsible for internal control?

Responsibility for internal control is distributed across various levels of an organization, with specific roles assigned to individuals and groups within the entity, as well as external parties such as regulators and auditors. A sound internal control system relies on the collaboration of all these players to be effective.

1. Board of directors and audit committee

The Board of Directors and its Audit Committee are primarily responsible for providing high-level oversight and governance of the internal control system. They play a crucial role in setting the overall tone at the top by ensuring that the organization maintains a strong control environment and cultivates an effective risk management culture. Their responsibilities include reviewing and evaluating reports from internal and external auditors to monitor the adequacy, integrity, and performance of the control framework.

2. Senior management (e.g., CEO, CFO)

Senior management, including positions such as the CEO and CFO, is responsible for the design, implementation, and maintenance of internal controls. They play a central role in establishing the control framework by formulating control policies and allocating appropriate resources to ensure effective execution. In addition to technical responsibilities, senior management also sets the ethical tone within the organization, promoting a culture that values integrity and reinforces the importance of adhering to internal control procedures.

3. Operational and functional managers

Operational and functional managers are responsible for applying and monitoring internal controls within their specific areas of responsibility. They ensure that established procedures are properly followed and that risks are identified and addressed in a timely manner. These managers act as the first line of defense by maintaining control activities in day-to-day operations and are expected to report any control issues or deficiencies they observe to senior management for further action.

4. Internal audit function

The internal audit function operates independently from management to assess the adequacy and effectiveness of internal controls across the organization. Internal auditors examine whether controls are properly designed and functioning as intended, and they provide objective recommendations for improvement. To maintain independence and impartiality, they report directly to the audit committee or the board of directors, thereby avoiding conflicts of interest that could compromise their evaluations.

5. Employees

All employees are responsible for complying with the organization’s control policies and procedures in the course of their daily duties. They play a critical role in maintaining the integrity of internal controls by adhering to established protocols and reporting any observed irregularities, control weaknesses, or unethical behavior. Their active participation helps in the early detection and mitigation of potential risks.

6. External auditors

External auditors are responsible for evaluating and reporting on the effectiveness of internal control over financial reporting as part of their audit engagements. While they may offer recommendations to improve identified weaknesses or inefficiencies, they do not take part in the design or implementation of controls in order to preserve their independence and objectivity.

7. Regulators and standard-setting bodies

Regulators and standard-setting bodies are responsible for establishing laws and frameworks that shape internal control practices. For example, the Sarbanes-Oxley Act (SOX) in the United States mandates requirements for internal controls over financial reporting. These external entities may also conduct examinations, request attestations, or require disclosures related to the effectiveness of an organization’s internal control system to ensure transparency, accountability, and compliance with applicable standards.

Segregation of duties

An efficient control environment begins with strong personnel policies and procedures. These policies guide the recruitment, training, supervision, and evaluation of employees, ensuring that competent and trustworthy individuals are placed in positions of responsibility. Clearly defined job descriptions, ethical codes of conduct, and ongoing professional development support a culture of accountability and transparency, which are critical for internal control effectiveness.

Definitions
Segregation of duties
An internal control principle that requires dividing key responsibilities for authorizing transactions, recording transactions, and maintaining custody of related assets among different individuals. By separating these functions, organizations reduce the risk of error, misuse, or fraud and strengthen the system of checks and balances.

The goal of segregation of duties is to ensure that no single individual has control over all aspects of a financial transaction, thereby creating a system of checks and balances.

Key functional responsibilities to segregate

Internal control best practices recommend that the following four types of responsibilities be segregated to different people or departments:

  1. Authority to execute transactions - This refers to the approval or initiation of transactions. For example, a purchasing manager may have the authority to place orders for goods and services.
  2. Recording transactions - This involves maintaining the accounting records, such as entering transactions into the general ledger or subledgers. A separate accounting staff member would typically perform this function.
  3. Custody of assets - This responsibility includes physical possession or control over assets such as cash, inventory, or fixed assets. For instance, a warehouse supervisor may manage inventory storage and access.
  4. Reconciliation of assets to records - Periodic reconciliation ensures that physical assets match the recorded balances in the accounting system. Ideally, someone who does not have access to assets or records them should perform this task to maintain objectivity.

Failure to segregate these duties increases the risk that errors or fraud could occur and go undetected. For example, if one person is responsible for authorizing payments, recording them, and reconciling bank statements, they could easily conceal unauthorized transactions.

Examples of segregation of duties by department

To illustrate how segregation of duties can be applied in practice, consider the following departmental examples:

These examples demonstrate how dividing responsibilities helps to reduce the risk of unauthorized transactions and ensure accuracy and accountability in financial operations.

Key points

Board of directors and audit committee

  • Provide high-level oversight and governance of internal controls
  • Set organizational tone and risk management culture
  • Review auditor reports to monitor control framework

Senior management (e.g., CEO, CFO)

  • Design, implement, and maintain internal controls
  • Establish control policies and allocate resources
  • Set ethical tone and promote integrity

Operational and functional managers

  • Apply and monitor controls in specific areas
  • Ensure procedures are followed and risks addressed
  • Report control issues to senior management

Internal audit function

  • Independently assess adequacy and effectiveness of controls
  • Provide objective recommendations for improvement
  • Report directly to audit committee or board

Employees

  • Comply with control policies and procedures
  • Maintain integrity by following protocols
  • Report irregularities or control weaknesses

External auditors

  • Evaluate and report on internal control over financial reporting
  • Provide improvement recommendations
  • Maintain independence; do not design or implement controls

Regulators and standard-setting bodies

  • Establish laws and frameworks for internal controls (e.g., SOX)
  • Require disclosures and attestations on control effectiveness
  • Ensure transparency, accountability, and compliance

Segregation of duties

  • Divide responsibilities for authorizing, recording, custody, and reconciliation
  • Reduces risk of error, misuse, or fraud
  • Supports checks and balances in financial transactions

Key functional responsibilities to segregate

  • Authority to execute transactions (approval/initiation)
  • Recording transactions (accounting entries)
  • Custody of assets (physical control)
  • Reconciliation of assets to records (independent verification)

Examples of segregation of duties by department

  • Assign different people to approval, recordkeeping, asset custody, and reconciliation
  • Prevents unauthorized transactions and concealment of errors
  • Enhances accuracy and accountability in operations

More from Governance, risk and compliance

  • Internal control objectives and the COSO Framework
  • Internal control limitations, risks, and deficiencies
  • Corporate governance structure and responsibilities
  • Corporate governance roles and responsibilities
  • External audit