internal control
Think of all the quiet safeguards built into a busy kitchen: a checklist taped to the fridge, two people signing off before a big order goes out, a locked supply cabinet, a daily count of the cash drawer. None of them is exciting, but together they keep mistakes and theft from piling up. Internal control is the business version: the whole set of policies, procedures, and habits a company uses to make sure it reaches its goals, keeps its records reliable, protects its assets, and follows the rules.
Internal control is usually described as having five components (the COSO framework): the control environment (the overall tone and ethics set at the top), risk assessment (identifying what could go wrong), control activities (the concrete checks — approvals, reconciliations, locks, separating incompatible duties), information and communication (getting the right data to the right people), and monitoring (regularly checking that the controls still work). Controls also come in flavors: preventive controls stop errors before they happen (requiring a second signature on payments), while detective controls catch errors after the fact (a monthly bank reconciliation that surfaces a missing deposit). A simple everyday example: requiring two signatures on any cheque over 10,000 is a preventive control that makes it much harder for one person to steal.
Internal control matters because it is the foundation everything else rests on — auditors assess it to decide how much to test, and reliable financial statements are nearly impossible without it. But be honest about the ceiling: internal control gives reasonable assurance, never a guarantee. It can be defeated by collusion (two people agreeing to cheat together), by management override (a boss who simply ignores the rules), and by human error. Controls also cost money, so companies must balance the protection against the price.
A company requires that every payment be requested by one employee, approved by a manager, and recorded by a third person, and that the bank account be reconciled monthly. The approval rule is a preventive control; the monthly reconciliation is a detective control that would surface a fraudulent payment that somehow slipped through.
Preventive controls stop errors up front; detective controls catch what slips through.
Even strong internal control gives only reasonable assurance: it can be beaten by collusion, by management override, and by simple human error — and it always costs money to run.