Achievable logoAchievable logo
CMA Part 1
Sign in
Sign up
Purchase
Textbook
Practice exams
Support
How it works
Exam catalog
Mountain with a flag at the peak
Textbook
1. External financial reporting decisions
2. Planning, budgeting, and forecasting
3. Performance management
4. Cost management
5. Internal control
5.1 Governance, risk and compliance
5.1.1 Internal control objectives and the COSO Framework
5.1.2 Responsibility for internal control and segregation of duties
5.1.3 Internal control limitations, risks, and deficiencies
5.1.4 Corporate governance structure and responsibilities
5.1.5 Corporate governance roles and responsibilities
5.1.6 External audit
5.1.7 The Sarbanes-oxley Act
5.1.8 Other regulatory bodies
5.2 System controls and security measures
6. Technology and analytics
Achievable logoAchievable logo
5.1.3 Internal control limitations, risks, and deficiencies
Achievable CMA Part 1
5. Internal control
5.1. Governance, risk and compliance
Our CMA Part 1 course is currently in development and is a work-in-progress.

Internal control limitations, risks, and deficiencies

7 min read
Font
Discuss
Share
Feedback

Limitations of internal control

While internal controls are essential for promoting accountability, reliability, and integrity within organizations, they are not foolproof. Even the most well-designed systems have inherent limitations due to practical constraints, human involvement, and environmental variables. Recognizing these limitations helps set realistic expectations and supports continuous improvement in internal control practices. External and internal audits can help alleviate some of these limitations by providing independent assessments, detecting weaknesses, and recommending improvements that enhance the overall effectiveness of the internal control environment.

Key limitations:

  1. Human error or judgment – Internal control processes often rely on individuals who may make unintentional mistakes or exercise poor judgment. Fatigue, lack of training, distractions, or complexity of tasks can all lead to errors despite established procedures.
  2. Collusion – Internal controls are generally designed under the assumption of individual accountability. When two or more individuals collude, they can bypass controls, making it difficult to detect or prevent fraudulent activities.
  3. Management override – Senior management may have the ability to override established controls for personal gain or strategic reasons, undermining the integrity of the control environment.
  4. Cost-benefit trade-offs – Not all risks can be addressed cost-effectively. Organizations must balance the cost of implementing controls against the potential benefits or risk reductions, which can leave certain vulnerabilities unaddressed.
  5. Changing conditions – Internal control systems may become outdated as the business environment evolves. Technological advancements, regulatory changes, or shifts in organizational structure can render controls less effective unless they are regularly reviewed and updated.

Internal control risk

Definitions
Internal control risk
The possibility that a material misstatement or operational failure could occur and not be prevented or detected in a timely manner due to inadequacies in the internal control system.

Internal control risk exists in every organization, regardless of the strength of its internal control framework. Managing internal control risk involves identifying vulnerable areas, evaluating the severity of potential consequences, and implementing strategies to mitigate these risks effectively.

Management must take a proactive role in identifying and addressing internal control risks through consistent evaluation and enhancement of the control environment. This includes conducting internal audits, updating policies and procedures, reinforcing training and supervision, and ensuring segregation of duties is appropriately maintained. Controls should be tested regularly, and deficiencies must be addressed promptly.

To assess internal control risk, organizations should:

  • Perform risk assessments aligned with business objectives and operations
  • Evaluate the likelihood and impact of control failures
  • Examine historical issues, audit findings, and regulatory feedback

Based on these assessments, organizations can implement mitigation strategies such as:

  • Strengthening existing controls or introducing new ones
  • Increasing oversight in high-risk areas
  • Improving documentation and communication of processes
  • Automating control functions where feasible to reduce manual error

Internal control deficiencies

Internal controls can generally be classified into two main categories: preventive controls and detective controls.

Definitions
Preventive controls
Controls that are designed to prevent errors or irregularities from occurring in the first place. Examples include segregation of duties, access controls (such as passwords and role-based permissions), approval and authorization procedures, and physical security measures like locked storage.
Detective controls
Controls that are designed to identify and alert management to errors or irregularities that have already occurred. These include reconciliations, audits, inventory counts, and review of exception reports.

Both types of controls are necessary to create a robust internal control environment, as they complement each other in reducing the risk of fraud, error, and misstatement.

Safeguarding controls

Safeguarding controls are a specific type of preventive control focused on protecting assets from loss, theft, or misuse. This has been identified specifically by the CMA Part 1 learning outcome statements.

Examples include:

  • Security cameras and alarm systems in physical storage areas
  • Locked cash drawers or safes for holding currency
  • Controlled access to inventory or sensitive equipment
  • System-based restrictions for financial transactions

These controls help ensure that assets are used only for authorized purposes and are physically and digitally secure.

Control through documentation and authorization

Documentation and authorization are essential components of a strong internal control framework. One effective technique is the use of prenumbered forms (such as invoices, checks, and purchase orders). These forms help prevent missing or duplicate documents and make it easier to trace transactions.

In addition, detailed policies and procedures specifying who is authorized to receive, review, or approve documents enhance accountability. For example:

  • Only designated personnel may authorize purchases or receive shipments
  • Incoming mail or payments are logged and verified by different individuals
  • Access to accounting records is limited to authorized finance staff

Together, these practices create a control environment that emphasizes accuracy, traceability, and prevention of unauthorized actions.

Testing the adequacy of internal controls

To evaluate whether internal controls are functioning effectively, organizations can use various testing methods:

  • Inquiry: Involves asking employees about how processes work and whether they understand and follow control procedures. This helps assess awareness and consistency in applying controls.
  • Observation: Watching employees perform tasks provides direct evidence of whether controls are being applied correctly and consistently.
  • Inspection: Reviewing documents, records, and system logs verifies the presence and completeness of control elements such as approvals, reconciliations, and audit trails.
  • Re-performance: Independently executing a control or process (e.g., recalculating a total or verifying a reconciliation) to confirm its accuracy and effectiveness.

Using a combination of these methods provides a more reliable basis for evaluating the adequacy of the control system.

Remediating internal control deficiencies

When deficiencies are identified, timely remediation is critical to preserving the integrity of the internal control system. The process typically includes:

  • Assessing the severity and potential impact of the deficiency
  • Identifying the root cause (e.g., lack of training, poor segregation of duties, or outdated policies)
  • Designing and implementing corrective actions, such as revising procedures, enhancing oversight, or upgrading systems
  • Communicating the changes to relevant staff and ensuring proper training
  • Retesting the control to confirm that the remediation was effective

Failure to address deficiencies may expose the organization to operational, compliance, and financial risks.

Importance of Independent Checks and Verification

Independent checks and verification are essential components of a well-functioning internal control system. They help validate the accuracy and completeness of information, detect anomalies, and promote accountability. These checks can include supervisory reviews, reconciliations performed by a separate individual, or independent audits.

One of the most structured forms of independent review is the internal audit function. Internal auditors assess the effectiveness of controls, evaluate risk management processes, and recommend improvements to strengthen governance and compliance. Because they are independent from day-to-day operations, internal auditors can provide objective assessments that add credibility to internal control evaluations. To reinforce this independence, the internal audit function typically reports functionally to the audit committee of the board of directors and administratively to the chief executive officer (CEO), creating a dual reporting line that balances oversight with operational effectiveness.

Although the Sarbanes-Oxley Act (SOX) and SEC regulations do not explicitly require companies to maintain an internal audit function, internal auditors often play a vital role in supporting management’s compliance with SOX (particularly under Sections 302 and 404), which require certification and evaluation of internal controls over financial reporting. In contrast, the New York Stock Exchange (NYSE) requires all listed companies to maintain an internal audit function, highlighting its importance in corporate governance.

The internal audit function also serves as a bridge to the next level of oversight, external audit, which provides an independent opinion on the fairness of the organization’s financial statements. We will explore this further in the following section.

Limitations of internal control

  • Subject to human error, poor judgment, and management override
  • Vulnerable to collusion among employees
  • Cost-benefit constraints and outdated controls due to changing conditions

Internal control risk

  • Risk of undetected material misstatement or operational failure
  • Requires proactive management: risk assessments, audits, updated procedures
  • Mitigation strategies: strengthen controls, increase oversight, automate processes

Internal control deficiencies

  • Two main control types:
    • Preventive controls: stop errors/fraud before occurrence (e.g., segregation of duties, access controls)
    • Detective controls: identify errors/fraud after occurrence (e.g., reconciliations, audits)
  • Safeguarding controls: preventive controls to protect assets (e.g., security systems, restricted access)

Control through documentation and authorization

  • Prenumbered forms prevent missing/duplicate documents
  • Clear policies specify authorization and accountability
  • Restricted access to records and segregation of duties

Testing the adequacy of internal controls

  • Inquiry: ask employees about procedures
  • Observation: watch processes in action
  • Inspection: review documents and records
  • Re-performance: independently execute control tasks

Remediating internal control deficiencies

  • Assess severity and root cause of deficiencies
  • Implement corrective actions and communicate changes
  • Retest controls to confirm remediation effectiveness

Importance of Independent Checks and Verification

  • Independent reviews (e.g., supervisory checks, reconciliations, internal audits) ensure accuracy and accountability
  • Internal audit function:
    • Reports to audit committee (functionally) and CEO (administratively)
    • Supports SOX compliance and strengthens governance
    • Required for NYSE-listed companies
  • External audit provides independent opinion on financial statements

Sign up for free to take 12 quiz questions on this topic

Previous
Next  | 5.1.4 Corporate governance structure and responsibilities
All rights reserved ©2016 - 2026 Achievable, Inc.

Internal control limitations, risks, and deficiencies

Limitations of internal control

While internal controls are essential for promoting accountability, reliability, and integrity within organizations, they are not foolproof. Even the most well-designed systems have inherent limitations due to practical constraints, human involvement, and environmental variables. Recognizing these limitations helps set realistic expectations and supports continuous improvement in internal control practices. External and internal audits can help alleviate some of these limitations by providing independent assessments, detecting weaknesses, and recommending improvements that enhance the overall effectiveness of the internal control environment.

Key limitations:

  1. Human error or judgment – Internal control processes often rely on individuals who may make unintentional mistakes or exercise poor judgment. Fatigue, lack of training, distractions, or complexity of tasks can all lead to errors despite established procedures.
  2. Collusion – Internal controls are generally designed under the assumption of individual accountability. When two or more individuals collude, they can bypass controls, making it difficult to detect or prevent fraudulent activities.
  3. Management override – Senior management may have the ability to override established controls for personal gain or strategic reasons, undermining the integrity of the control environment.
  4. Cost-benefit trade-offs – Not all risks can be addressed cost-effectively. Organizations must balance the cost of implementing controls against the potential benefits or risk reductions, which can leave certain vulnerabilities unaddressed.
  5. Changing conditions – Internal control systems may become outdated as the business environment evolves. Technological advancements, regulatory changes, or shifts in organizational structure can render controls less effective unless they are regularly reviewed and updated.

Internal control risk

Definitions
Internal control risk
The possibility that a material misstatement or operational failure could occur and not be prevented or detected in a timely manner due to inadequacies in the internal control system.

Internal control risk exists in every organization, regardless of the strength of its internal control framework. Managing internal control risk involves identifying vulnerable areas, evaluating the severity of potential consequences, and implementing strategies to mitigate these risks effectively.

Management must take a proactive role in identifying and addressing internal control risks through consistent evaluation and enhancement of the control environment. This includes conducting internal audits, updating policies and procedures, reinforcing training and supervision, and ensuring segregation of duties is appropriately maintained. Controls should be tested regularly, and deficiencies must be addressed promptly.

To assess internal control risk, organizations should:

  • Perform risk assessments aligned with business objectives and operations
  • Evaluate the likelihood and impact of control failures
  • Examine historical issues, audit findings, and regulatory feedback

Based on these assessments, organizations can implement mitigation strategies such as:

  • Strengthening existing controls or introducing new ones
  • Increasing oversight in high-risk areas
  • Improving documentation and communication of processes
  • Automating control functions where feasible to reduce manual error

Internal control deficiencies

Internal controls can generally be classified into two main categories: preventive controls and detective controls.

Definitions
Preventive controls
Controls that are designed to prevent errors or irregularities from occurring in the first place. Examples include segregation of duties, access controls (such as passwords and role-based permissions), approval and authorization procedures, and physical security measures like locked storage.
Detective controls
Controls that are designed to identify and alert management to errors or irregularities that have already occurred. These include reconciliations, audits, inventory counts, and review of exception reports.

Both types of controls are necessary to create a robust internal control environment, as they complement each other in reducing the risk of fraud, error, and misstatement.

Safeguarding controls

Safeguarding controls are a specific type of preventive control focused on protecting assets from loss, theft, or misuse. This has been identified specifically by the CMA Part 1 learning outcome statements.

Examples include:

  • Security cameras and alarm systems in physical storage areas
  • Locked cash drawers or safes for holding currency
  • Controlled access to inventory or sensitive equipment
  • System-based restrictions for financial transactions

These controls help ensure that assets are used only for authorized purposes and are physically and digitally secure.

Control through documentation and authorization

Documentation and authorization are essential components of a strong internal control framework. One effective technique is the use of prenumbered forms (such as invoices, checks, and purchase orders). These forms help prevent missing or duplicate documents and make it easier to trace transactions.

In addition, detailed policies and procedures specifying who is authorized to receive, review, or approve documents enhance accountability. For example:

  • Only designated personnel may authorize purchases or receive shipments
  • Incoming mail or payments are logged and verified by different individuals
  • Access to accounting records is limited to authorized finance staff

Together, these practices create a control environment that emphasizes accuracy, traceability, and prevention of unauthorized actions.

Testing the adequacy of internal controls

To evaluate whether internal controls are functioning effectively, organizations can use various testing methods:

  • Inquiry: Involves asking employees about how processes work and whether they understand and follow control procedures. This helps assess awareness and consistency in applying controls.
  • Observation: Watching employees perform tasks provides direct evidence of whether controls are being applied correctly and consistently.
  • Inspection: Reviewing documents, records, and system logs verifies the presence and completeness of control elements such as approvals, reconciliations, and audit trails.
  • Re-performance: Independently executing a control or process (e.g., recalculating a total or verifying a reconciliation) to confirm its accuracy and effectiveness.

Using a combination of these methods provides a more reliable basis for evaluating the adequacy of the control system.

Remediating internal control deficiencies

When deficiencies are identified, timely remediation is critical to preserving the integrity of the internal control system. The process typically includes:

  • Assessing the severity and potential impact of the deficiency
  • Identifying the root cause (e.g., lack of training, poor segregation of duties, or outdated policies)
  • Designing and implementing corrective actions, such as revising procedures, enhancing oversight, or upgrading systems
  • Communicating the changes to relevant staff and ensuring proper training
  • Retesting the control to confirm that the remediation was effective

Failure to address deficiencies may expose the organization to operational, compliance, and financial risks.

Importance of Independent Checks and Verification

Independent checks and verification are essential components of a well-functioning internal control system. They help validate the accuracy and completeness of information, detect anomalies, and promote accountability. These checks can include supervisory reviews, reconciliations performed by a separate individual, or independent audits.

One of the most structured forms of independent review is the internal audit function. Internal auditors assess the effectiveness of controls, evaluate risk management processes, and recommend improvements to strengthen governance and compliance. Because they are independent from day-to-day operations, internal auditors can provide objective assessments that add credibility to internal control evaluations. To reinforce this independence, the internal audit function typically reports functionally to the audit committee of the board of directors and administratively to the chief executive officer (CEO), creating a dual reporting line that balances oversight with operational effectiveness.

Although the Sarbanes-Oxley Act (SOX) and SEC regulations do not explicitly require companies to maintain an internal audit function, internal auditors often play a vital role in supporting management’s compliance with SOX (particularly under Sections 302 and 404), which require certification and evaluation of internal controls over financial reporting. In contrast, the New York Stock Exchange (NYSE) requires all listed companies to maintain an internal audit function, highlighting its importance in corporate governance.

The internal audit function also serves as a bridge to the next level of oversight, external audit, which provides an independent opinion on the fairness of the organization’s financial statements. We will explore this further in the following section.

Key points

Limitations of internal control

  • Subject to human error, poor judgment, and management override
  • Vulnerable to collusion among employees
  • Cost-benefit constraints and outdated controls due to changing conditions

Internal control risk

  • Risk of undetected material misstatement or operational failure
  • Requires proactive management: risk assessments, audits, updated procedures
  • Mitigation strategies: strengthen controls, increase oversight, automate processes

Internal control deficiencies

  • Two main control types:
    • Preventive controls: stop errors/fraud before occurrence (e.g., segregation of duties, access controls)
    • Detective controls: identify errors/fraud after occurrence (e.g., reconciliations, audits)
  • Safeguarding controls: preventive controls to protect assets (e.g., security systems, restricted access)

Control through documentation and authorization

  • Prenumbered forms prevent missing/duplicate documents
  • Clear policies specify authorization and accountability
  • Restricted access to records and segregation of duties

Testing the adequacy of internal controls

  • Inquiry: ask employees about procedures
  • Observation: watch processes in action
  • Inspection: review documents and records
  • Re-performance: independently execute control tasks

Remediating internal control deficiencies

  • Assess severity and root cause of deficiencies
  • Implement corrective actions and communicate changes
  • Retest controls to confirm remediation effectiveness

Importance of Independent Checks and Verification

  • Independent reviews (e.g., supervisory checks, reconciliations, internal audits) ensure accuracy and accountability
  • Internal audit function:
    • Reports to audit committee (functionally) and CEO (administratively)
    • Supports SOX compliance and strengthens governance
    • Required for NYSE-listed companies
  • External audit provides independent opinion on financial statements

More from Governance, risk and compliance

  • Internal control objectives and the COSO Framework
  • Responsibility for internal control and segregation of duties
  • Corporate governance structure and responsibilities
  • Corporate governance roles and responsibilities
  • External audit