Blog

Best Practices for Effective Internal Controls

Written by Eliassen Group | Jul 27, 2026 4:12:29 PM
 

Effective internal controls are a foundational component of a well-governed organization, supporting the reliability of financial reporting, operational efficiency, and compliance with regulatory requirements. As organizations expand across systems, geographies, and regulatory environments, the complexity of the control environment continues to increase.

In today’s environment, this complexity is further amplified by rapid advancements in technology, including the adoption of automation, artificial intelligence (AI), and increasingly interconnected digital platforms. At the same time, organizations are facing heightened risks related to cybersecurity, data integrity, system dependencies, system logic, and user access—requiring more dynamic and responsive control frameworks.

Within this broader technology risk landscape, IT General Controls (ITGCs) play a critical role in supporting the reliability of technology-enabled control environments. As more business processes and financial reporting activities depend on enterprise systems, automated workflows, and system-generated data, organizations must ensure that foundational IT controls are appropriately designed and operating effectively. Key ITGC areas typically include user access management, change management, system operations, and data backup and recovery. These controls help ensure that systems process transactions accurately, changes to applications are authorized and tested, and access to sensitive data and functionality is restricted to appropriate personnel.

When ITGCs are ineffective, reliance on automated controls, system-generated reports, and key system configurations may be reduced, potentially increasing the need for additional manual procedures or compensating controls. Accordingly, ITGCs should be considered as part of the broader risk assessment and control design process, particularly when organizations are implementing new systems, expanding automation, or increasing reliance on data analytics and AI-enabled processes.

Despite these developments, many organizations continue to operate control environments that are overly complex, inconsistently executed, or misaligned with actual risk exposure. Controls are frequently implemented reactively, driven by audit findings or compliance requirements, rather than as part of a cohesive, risk-based strategy. This often results in duplicative activities, gaps in coverage, and unnecessary operational burden.

As organizations continue to evolve, there is a clear shift toward more integrated and technology-enabled control environments, where automation, data analytics, and continuous monitoring play a central role in both execution and oversight. This evolution requires not only enhancements to tools and systems, but also a fundamental reassessment of how controls are designed, embedded, and governed.

This paper outlines five core pillars that underpin an effective control environment and provide practical guidance for building a framework that is both sustainable and aligned with the modern risk landscape.

The practices described in this paper are consistent with the principles of the COSO Internal Control Integrated Framework while expanding on practical considerations for modern, technology-enabled organizations.

The Five Pillars of Effective Internal Controls

An effective and sustainable control environment is built upon five interdependent pillars:

  1. Risk Alignment

  2. Control Design & Precision

  3. Process Integration

  4. Governance & Accountability

  5. Monitoring & Continuous Improvement

Together, these pillars provide a practical framework for evaluating and enhancing internal controls in a structured and scalable manner.

1. Risk Alignment

A strong control environment begins with a clear and continuously updated understanding of risk. Controls should be directly aligned to specific risks related to financial reporting, operations, and compliance, rather than inherited from legacy practices or prior audit cycles.

Organizations should perform structured risk assessments that evaluate exposures across key dimensions, including process-level risks (e.g., revenue, inventory), system-level risks (e.g., data integrity, access controls), and entity-level considerations (e.g., governance and oversight). These assessments should be updated regularly to reflect changes in systems, business models, and regulatory expectations.

A common failure point is the persistence of controls in areas that are no longer high risk, while newly emerging risks remain insufficiently addressed. For example, the implementation of a new ERP system (Enterprise Resource Planning) may shift key risks upstream into system configuration and data governance, yet legacy manual controls may still be performed downstream.

In the current environment, risk assessments must also explicitly incorporate technology-driven risks, including cybersecurity threats, system access vulnerabilities, and risks introduced through automation and AI-enabled processes. As organizations rely more heavily on data and interconnected systems, risks related to data integrity, system logic, and user access have become increasingly critical.

Practical Example:

Following the implementation of a new ERP system, an organization reassesses its revenue recognition risks and determines that key risks have shifted from manual invoice review to system configuration, automated pricing logic, and user access provisioning. As a result, management redesigns the control approach to focus on configuration approvals, access reviews, and exception reporting, rather than continuing to rely primarily on downstream manual reconciliations.

Aligning controls to current risk ensures that efforts are focused on what matters most, reducing inefficiency while strengthening overall coverage. This alignment should be reinforced through periodic control rationalization to confirm that the control environment remains relevant, efficient, and responsive to changes in risk.

Control Rationalization as an Extension of Risk Alignment

As organizations evolve, control environments often expand in response to new regulatory requirements, audit findings, system implementations, and organizational changes. Over time, this can result in control frameworks that contain redundant, overlapping, or outdated controls that no longer align with the organization's current risk profile. Excessive controls not only increase operational burden but can also divert attention and resources away from the areas of greatest risk.

Control rationalization is the process of systematically evaluating the control inventory to ensure that each control addresses a defined risk, operates efficiently, and provides meaningful value. Organizations should periodically assess whether controls remain necessary, whether multiple controls mitigate the same risk, and whether manual activities can be replaced or supplemented by automated or preventative controls.

A structured rationalization effort should evaluate whether controls:

    • Continue to address a current and relevant risk
    • Duplicate or overlap with other existing controls
    • Can be consolidated without reducing risk coverage
    • Can be automated or embedded within business processes
    • Are operating at an appropriate frequency based on current risk levels

Practical Example:

During a control assessment, an organization identified three separate monthly management review controls designed to detect revenue reporting errors. Following a risk assessment, management determined that a newly implemented automated system validation prevented the underlying errors from occurring. The organization consolidated the three manual detective controls into a single monitoring control supported by automated reporting. This reduced manual effort while maintaining appropriate assurance over financial reporting.

Control rationalization should not be viewed solely as a cost-reduction initiative. Rather, it is a continuous improvement practice that strengthens the overall control environment by eliminating low-value activities, improving consistency, and enabling greater focus on controls that address the organization's most significant risks. As organizations continue to modernize their operations through automation and digital transformation, periodic rationalization helps ensure that the control environment remains both effective and sustainable.

2. Control Design & Precision

The effectiveness of a control is heavily dependent on its design. Controls should be clearly defined and consistently documented, including:

  • A specific control objective tied to a risk
  • A designated control owner
  • A defined frequency of execution
  • Explicit documentation and evidence requirements

Precision is particularly critical for management review controls (MRCs), which are a common source of deficiencies. High-level controls that lack defined procedures or thresholds often fail to provide sufficient assurance.

A well-designed review control should clearly specify:

  • The data or reports being reviewed

  • The criteria applied (e.g., variance thresholds, trend analysis)

  • The process for investigating and resolving exceptions

  • The evidence retained to support execution

Practical Example:

A high-level monthly review of financial results provides limited assurance. In contrast, a control that defines variance thresholds (e.g., greater than 10%), requires documented investigation of fluctuations, and retains supporting evidence of follow-up actions demonstrates significantly greater precision and effectiveness.
Designing controls with clarity and precision improves consistency, enhances auditability, and increases the likelihood of identifying meaningful issues in a timely manner.

3. Process Integration

Controls are most effective when they are embedded within the natural flow of business operations rather than treated as standalone compliance activities. Integration ensures that controls are executed consistently and reduces reliance on manual intervention.

Organizations should evaluate opportunities to further integrate controls within increasingly digital and automated environments, including:

  • Embedding controls directly into system workflows

  • Implementing automated and system-enforced controls within ERP platforms

  • Shifting controls upstream to prevent issues at the source

For example, system-enforced validations in order entry processes can prevent invalid transactions before they occur, reducing the need for downstream detective controls. Similarly, automated three-way match processes within procure-to-pay systems provide more consistent and scalable assurance than manual reviews.

As organizations continue to deploy automation and AI-enabled processes, control environments must evolve to ensure that system logic, automated decision-making, and data flows are appropriately governed and controlled.

Practical Example:

In a procure-to-pay process, an organization embeds approval thresholds and automated three-way match functionality directly within the ERP workflow. Purchase orders that exceed defined limits are automatically routed for approval, while invoices that do not match purchase order and receiving data are blocked from payment until exceptions are resolved. This reduces manual review effort and helps prevent errors before transactions are processed.

Prioritizing preventative and automated controls can improve effectiveness but also reduces the operational burden on control owners.

4. Governance & Accountability

Clear ownership and strong governance are essential for sustaining an effective control environment. Each control should have a defined owner responsible for execution and, where applicable, a reviewer responsible for oversight.

Control owners should understand:

  • The purpose of the control and the associated risk

  • Execution requirements and expectations

  • Documentation and evidence requirements

Organizations should reinforce accountability through governance mechanisms such as:

  • Periodic control owner certifications

  • Management reporting on control performance and deficiencies 

  • Defined escalation protocols for control failures

Practical Example:

An organization establishes a quarterly control owner certification process requiring each owner to confirm that assigned controls were performed, evidence was retained, and any exceptions were escalated. Results are summarized for management and the audit committee, enabling leadership to identify recurring issues, overdue remediation items, and areas where additional training or clarification is needed.

Strong governance helps ensure that controls are treated as a core operational responsibility rather than a compliance formality. It also promotes transparency and accountability across the organization, enabling management to identify and address issues proactively.

5. Monitoring & Continuous Improvement

An effective control environment requires ongoing monitoring and a commitment to continuous improvement. This includes both management-level oversight and independent testing through SOX or Internal Audit functions.

Testing activities should assess both design effectiveness and operating effectiveness. Design effectiveness should be assessed first, as a poorly designed control cannot be considered effective regardless of how consistently it is performed.

  • Design effectiveness (whether controls address the intended risk)

  • Operating effectiveness (whether controls are executed consistently)

In 2026, organizations are increasingly leveraging data analytics and emerging AI capabilities to enhance monitoring practices. These tools enable analysis of full populations of data, supporting more proactive identification of anomalies and emerging risks.

Organizations should leverage:

  • Continuous monitoring tools

  • Data analytics for transaction-level insights

  • Dashboards and KPIs to track control performance

Practical Example:

Rather than relying solely on sample-based testing of journal entries, automated analytics can be used to identify high-risk entries based on defined criteria, such as unusual timing, manual postings, or unexpected account combinations.

Importantly, findings from monitoring and testing should be fed back into the control environment. Recurring issues often signal broader weaknesses in process design, system configuration, or training that require more comprehensive remediation.

Deficiency Management and Remediation

Even well-designed control environments will experience deficiencies. The key to long-term effectiveness lies in how these issues are identified, evaluated, and remediated.

Organizations should implement structured processes to:

  • Identify and document deficiencies

  • Assess severity based on risk and potential impact

  • Perform root cause analysis

In the current landscape, root causes are increasingly linked to system configurations, data dependencies, and automated processes, requiring a broader perspective beyond traditional control failures.

Remediation efforts should focus on addressing underlying drivers rather than implementing temporary fixes. Sustainable solutions may include process redesign, enhanced automation, or improved data governance. Strong governance, including tracking mechanisms and escalation protocols, is critical to ensuring timely and effective resolution.

Impact on the Control Environment

Organizations that adopt this framework can transition from reactive, compliance-driven control environments to more proactive and risk-focused models. Controls become more efficient as low-value activities are eliminated, while high-risk areas receive greater focus and precision.

Integration with business processes and technology reduces manual effort and improves consistency, while strong governance enhances accountability and transparency. Additionally, the use of data-driven monitoring enables earlier identification of issues, reducing the likelihood of significant deficiencies or material weaknesses.

This evolution can position internal controls not only as a compliance requirement but as a strategic enabler of operational effectiveness and informed decision-making.

Summary

Effective internal controls require a structured and deliberate approach that aligns control activities with risk, integrates them into business operations, and supports them through strong governance, accountability, and continuous monitoring. The five pillars outlined in this paper—Risk Alignment, Control Design & Precision, Process Integration, Governance & Accountability, and Monitoring & Continuous Improvement—provide a practical framework for building a sustainable, scalable, and effective control environment.

As organizations operate in increasingly complex and technology-enabled environments, control frameworks must also address risks related to system access, data integrity, automated processing, system-generated reports, and IT General Controls. Organizations that adopt a risk-focused, integrated, and continuously improving approach to internal controls will be better positioned to manage emerging risks, meet regulatory expectations, and support long-term organizational performance.

Looking Ahead: Evolving the Control Environment Through Technology

As organizations strengthen their control environments, emerging technologies such as automation, data analytics, and artificial intelligence are playing an increasingly important role in how controls are designed, executed, and monitored. These capabilities enable more efficient processing, broader data coverage, and more timely identification of risks.

At the same time, they introduce new considerations around governance, model oversight, data integrity, and cybersecurity. Controls must evolve to address not only traditional financial and operational risks, but also those introduced through automated processes, system dependencies, and digital transformation initiatives.

Organizations that successfully integrate these technologies while maintaining strong control discipline will be better positioned to enhance efficiency, improve insight generation, and respond effectively to an increasingly dynamic risk landscape.

Author

 

Tom Gibbons

Manager, SOX & Internal Audit Solutions

tgibbons@eliassen.com

Tom Gibbons | LinkedIn