Accounting
Internal Controls
The policies and procedures a business puts in place so that no single person can both cause an error or theft and hide it in the records — trust built into the process itself, not into any one person.
Definition
Internal controlsare the policies, procedures, and checks a business puts in place to prevent and catch errors, fraud, and misuse of its assets and financial records — things like requiring a second signature on large payments, reconciling a bank statement against the accounting records every month, or making sure the person who approves a purchase isn't the same person who pays the resulting bill.
Why this exists
Whenever one person has both the ability to handle an asset — cash, inventory, a company credit card — and the ability to record what happened to it in the books, that same person can misuse the asset and then adjust the records so nothing looks wrong, with no one else immediately positioned to notice. Owners, lenders, and investors can't personally watch every transaction a business makes, so they need the accounting process itself to provide credible assurance that the numbers can be trusted, even without anyone watching over every employee's shoulder.
The core idea internal controls rely on is called segregation of duties: splitting the responsibility for authorizing a transaction, recording it, and physically safeguarding the related asset across different people. If those three roles are held by different people, no single person can both cause a problem and cover it up alone — catching it would require two or more people to deliberately work together, which is far less likely than one person acting alone. This is the same underlying logic as Double-Entry Bookkeeping's built-in check (every transaction has to balance) applied to people and processes instead of numbers: redundancy that makes a single point of failure much harder to hide.
Auditors often think about this risk in terms of three ingredients that tend to appear together whenever fraud happens: an opportunity to do it without getting caught (weak controls), an incentive or pressure to do it (financial trouble, a bonus tied to hitting a number), and a rationalizationthat makes it feel justified ("I'll pay it back," "everyone does it"). Internal controls can't reach into someone's motives or their conscience, but they can directly remove the opportunity — which is why they're the piece a business can actually design and control.
Worked example
At Maria's bakery, one employee runs the cash register all day. If that same employee also tallied up the register at closing and recorded the day's sales in the books, they could pocket some cash and simply record a lower sales figure to match — nothing would ever look wrong on paper.
Instead, a different employee — say, Maria herself — counts the cash in the register at closing and compares it against the register's own recorded total, independent of whoever handled the cash all day. Now a shortfall shows up immediately as a mismatch between cash on hand and what the register says should be there, because the person recording the comparison isn't the same person who had access to the cash.
Common misconceptions
“Internal controls exist only to prevent employees from stealing.”
They also catch honest mistakes — data entry errors, duplicate payments, miscounts — and support reliable financial reporting generally, not just fraud prevention.
“Strong internal controls make fraud or errors impossible.”
Controls can be overridden by management or defeated when two or more people collude — no control system offers a 100% guarantee. They meaningfully reduce risk and improve the odds of catching a problem quickly, not eliminate it entirely.
“Designing and maintaining internal controls is the auditor's job.”
It's management's responsibility to design, implement, and maintain internal controls. Auditors independently test and evaluate them — see Audits — but they don't run the business's day-to-day control process themselves.
Also in the Glossary: Internal Controls, Segregation of Duties