What Is Internal Control?

Internal Control refers to the integrated framework of institutional policies and procedures which are designed to provide reasonable assurance that the University will achieve its strategic objectives, manage risk effectively, safeguard resources, and operate efficiently and in compliance with applicable requirements.

An effective system of internal control helps ensure:

  • Reliable Information 鈥 Financial, operational, and other information is accurate, complete, and timely. 
  • Compliance 鈥 Activities are conducted in accordance with applicable laws, regulations, policies, and procedures. 
  • Protection of Assets 鈥 Physical, financial, information, and other University assets are safeguarded from loss, misuse, or unauthorized access. 
  • Operational Effectiveness and Efficiency 鈥 Resources are used responsibly and processes operate as intended. 
  • Achievement of Objectives 鈥 Activities support the University's mission, strategic goals, and operational priorities.

Internal controls may be preventive (to deter errors before they occur), detective (to identify errors after they occur), or corrective (to remediate errors). Controls may be implemented through automated, manual, or hybrid processes.

Internal controls may be:

  • Manual 鈥 Performed by individuals (e.g., supervisory reviews and approvals).
  • Automated 鈥 Embedded within information systems (e.g., system-enforced approvals or access restrictions).
  • Hybrid 鈥 A combination of manual and automated activities working together to achieve a control objective.

Internal Control Concepts

Internal controls consist of five interrelated components, each of which is an integral part of the management process and plays a specific role in departmental internal control procedures. 

  • Control Environment 鈥 鈥淭one at the top鈥 which establishes the organizational culture regarding ethics and integrity.
  • Risk Assessment 鈥 The continuous process of identifying and analyzing potential threats which may prevent the achievement of organizational objectives.
  • Control Activities 鈥 Institutional policies and procedures (such as approvals, reconciliations, and segregation of duties) that help mitigate organizational risks.
  • Information and Communication 鈥 Systems that ensure knowledge and data sharing across the institution. 
  • Monitoring 鈥 Ongoing evaluations to ensure internal controls are functioning and effective.

Internal Control Components

The control environment establishes the organization鈥檚 overarching tone and influences the internal control awareness of its personnel. As the foundational element of the internal control framework, it provides the necessary discipline and structure for all other components. Key factors include integrity, ethical values, and professional competence of staff; management鈥檚 leadership philosophy and operating style; the formal delegation of authority and responsibility; human resource development practices; and the strategic oversight provided by the Board of Visitors.

The risk assessment involves the systematic identification and analysis of risks that could impact the achievement of organizational objectives. This process entails a comprehensive evaluation of departmental processes, activities, and personnel to proactively identify potential vulnerabilities. These findings serve as the essential framework for developing effective risk mitigation and management strategies.

These constitute the policies and procedures established to ensure that management directives are executed effectively. Integrated at every organizational level, control activities include performance evaluations, functional reviews, reconciliations, and physical safeguards. Key control objectives include:

  • Transaction Authorizations: Ensures that all activities are approved by authorized personnel prior to execution. Examples include verifying authorized signatures on purchase orders, travel vouchers, and access requests.
  • Documentation: Maintains comprehensive and organized supporting records for all business activities.
  • Completeness and Accuracy: Guarantees that all valid transactions are captured in the accounting records without omission, remain consistent with originating data, and are recorded promptly. This includes bank reconciliations and the monthly audit of budget expenditures against physical documentation.
  • Validity: Confirms that recorded transactions represent actual economic events, are lawful, and comply with institutional and state guidelines.
  • Physical Safeguards: Restricts access to physical assets and information systems to authorized personnel only. This includes securing offices, conducting periodic inventory audits, and maintaining password confidentiality.
  • Error Handling: Ensures that discrepancies identified during processing are promptly corrected and reported to the appropriate management level.
  • Segregation of Duties: Distributes responsibilities among multiple individuals to prevent any single person from controlling both the recording and processing of a transaction. For instance, the individual who maintains petty cash funds should not be the same person who approves reimbursements or performs the final reconciliation.

A robust internal control framework is designed to satisfy these fundamental objectives across all operational processes.

An effective information system must ensure the delivery of accurate, relevant, and timely data to the appropriate personnel. This facilitates the informed execution of duties and ensures that all stakeholders can effectively fulfill their professional responsibilities.

This process facilitates the continuous assessment of internal control performance to ensure sustained operational quality and effectiveness. It encompasses ongoing monitoring through the routine review of reports, active supervision, and internal self-assessments. Furthermore, periodic independent evaluations are conducted by external units to provide objective oversight and validation. 

Types of Internal Controls

Preventive controls are designed to reduce the likelihood of errors, irregularities, or unauthorized activities occurring in the first place. These controls help the University proactively manage risk and protect its people, resources, and information.

Examples:

  • Segregation of duties
  • Authorization and approval requirements
  • System access controls and user permissions
  • Firewalls and cybersecurity controls
  • Records retention and management procedures
  • System approval workflows
  • Accurate and timely entry of payroll and other transaction information

Corrective controls are designed to address the errors or irregularities that have been detected and reduce the likelihood of recurrence. These controls support compliance, strengthen processes and remediate weaknesses. 

Examples: 

  • Fire detection sprinkler systems
  • Additional employee training
  • New or revised policies and procedures
  • Software patches to fix a vulnerability
  • Budget adjustments or enhanced monitoring activities
  • Disaster recovery and business continuity plans
  • Performance improvement measures

Detective controls are designed to identify errors or irregularities that may have occurred. While they may not prevent an issue, they help ensure that problems are detected in a timely manner and addressed appropriately.

Examples: 

  • Physical asset inventories of equipment and other assets
  • Data analytics and exception reporting 
  • Monitoring and review activities
  • Reconciliations and reasonableness checks
  • Benchmarking and trend analysis
  • Timely review and approval of your employee time records and transactions
  • Reporting suspected fraud, waste or abuse

Benefits and Limitations of Internal Control Systems

Internal control systems provide a structured framework that facilitates the consistent achievement of organizational goals and objectives. These systems offer management a high degree of assurance that internal policies are being strictly observed and enforced and that organizational assets are being utilized appropriately. Conversely, a deficient, weak, or nonexistent control environment can significantly increase the risk of operational failures, including:

  • Degradation of Service or Product Quality: Erosion of operational standards and output consistency.
  • Unauthorized Transactions: Execution of activities without proper approval or oversight. 
  • Data Integrity Deficiencies: Provision of inaccurate, incomplete, or unreliable information.
  • Reporting Delays: Failure to provide critical management information within required timeframes.
  • Asset Vulnerability: Inadequate protection of physical and intellectual property.
  • Financial Misappropriation: Increased risk of fraud, embezzlement, or the misuse of funds.

All internal control systems, regardless of design, possess inherent limitations. Operational errors may arise from misunderstood instructions, judgmental lapses, or other human factors such as oversight and fatigue. Furthermore, internal controls predicated on the segregation of duties remain vulnerable to circumvention through collusion, and management may possess the ability to intentionally override established protocols. 

As organizational conditions evolve over time, existing control procedures may undergo deterioration or eventually become insufficient to address emerging risks.

Who Is Responsible For Internal Controls?

Every member of the University community has a role in maintaining effective internal controls. Employees support the control environment by carrying out their responsibilities, following policies and procedures, and helping safeguard University resources. University leadership is responsible for the design, implementation, and ongoing oversight of internal controls within their areas.

In accordance with University Policy No. 3010, specific roles and responsibilities for internal accounting controls are formally defined. Additionally, internal and external auditors conduct periodic assessments to evaluate the effectiveness of internal controls and ensure the controls are functioning as intended.