Implementing Effective Internal Control
In a Small, Private Company
Billy J. Taylor
Texas A&M University- Commerce
Abstract
Internal controls are often thought of in the context of large, publicly traded companies. However, even though they are not required by law to do so, small, private companies can benefit a great deal from implementing strong internal controls. COSO, the body who provided the internal control guidelines later adopted by the Sarbanes-Oxley Act of 2002, was used as a model to formulate internal control suggestions for a small, private company. While many of those suggestions do not apply to a small, private company, many of them can still be used to create solid internal controls that help to promote effective and efficient operations, reliable and accurate financial reporting, and the conformity of the firm to the various applicable laws and regulations. The five components that COSO outlined for effective internal control cover the internal control environment, risk assessment, control activities, information and communication, and monitoring the internal control system. The foundation for solid internal control is the internal control environment which covers topics like management promoting an environment where ethics and integrity are at the forefront. Small, private companies can then assess risk, devise control activities like separation of duties and control of physical assets, provide for solid information systems, and monitor and improve their internal control system only if they have a solid foundation upon which to build on. An internal control environment promoting the ideas that encourage solid internal controls is a prerequisite for all of the other components that COSO suggested for effective internal control back in 1992.
One aspect of accounting that is consistently emphasized is internal controls. Usually, the concept of internal controls is discussed in relation to the auditing process and with respect to publically traded companies. However, strong internal controls are just as important for small, private companies to have in place as they are for regulated, publicly traded companies.
The organization that issues the framework and guidance on internal controls is the Committee of Sponsoring Organizations of the Treadway Commission, or COSO (Louwers et al., 2015). They define internal control as a “process to provide reasonable assurance” that the controls are promoting effective and efficient operations, reliable and accurate reporting of financial information, and the conformity of the firm to laws and regulations (Louwers et al., 2015). While the Securities and Exchange Commission accepted the components of internal controls devised by COSO in 1992 under the Sarbanes-Oxley Act of 2002 and require publicly traded companies to abide by those internal control guidelines, private companies have no such obligation (Louwers et al., 2015). Still, it is in the best interest of small, privately held companies to at minimum become familiar with the basic guidelines set forth by COSO and to put them into practice wherever it is cost effective to do so. The COSO guidelines put forth that can be implemented in a small, private company touch on the following components of internal control: internal control environment, risk assessment, control activities, information and communication, and monitoring the internal control system (COSO, 2013).
The first component, internal control environment, is comprised of many parts including a commitment to integrity and ethical values, management’s philosophy and operating style, organizational structure, financial reporting competencies, authority and responsibility, and human resources management (COSO, 2013). The control environment and all of its corresponding parts, can be said to be the very foundation of an internal control system (Louwers et al., 2015). In any firm, public or private, regardless of size, this is a very important topic. However, in a small, private company, the internal control environment is absolutely critical. The internal control environment must be one that promotes unquestionable integrity and a strong commitment to ethical values (Louwers et al., 2015). At a small company, that means the owner and management personnel have an obligation to set an example of how to behave and conduct business. It is imperative that the owner and management cultivate an environment where employees understand the conduct that is expected out of them for all activities, especially in the area of financial reporting.
The management of a small, private company can take several steps to create and maintain an internal control environment that promotes these aforementioned, favorable themes. First, management must set a positive example for all personnel within the firm to follow (James, n.d.). The owner as well as the management must “set the tone at the top” (Louwers et al., 2015). That means they themselves must conduct themselves with integrity and a high ethical standard at all times. Another way to create a solid internal control environment is to write an official code of conduct emphasizing an ethical company culture (Louwers et al., 2015). While there may be some costs associated with this, it is a worthwhile endeavor that will bolster the internal control environment of the firm. Also, periodic meetings that highlighting the importance of integrity and high ethical standards in the daily work environment should be conducted. Special consideration should be given to accurate, complete, and honest financial reporting and the importance of ethical standards relating to all personnel dealing with inputs and financial information that will eventually go into the firm’s accounting system. Furthermore, an open door policy should be implemented and communicated to all employees so that they know that any problems or issues of any kind, especially related to ethical behavior, can be reported and addressed without fear of disciplinary action or a breach of their confidentiality.
The next pillar of a strong control environment relates to management’s philosophy and operating style. This component of internal control pertains to how management measures and drives performance. It pertains to how they set goals and how they achieve those goals (Louwers et al., 2015). Further, management’s philosophy and operating style deals with how management runs things, how they reward achievement, and how they admonish poor performance.
Management’s philosophy and operating style can have a significant influence on the behavior of individuals within an organization. For example, if management is too geared towards performance and employees fear for their job security or worry about compensation derived from achievement, it can be a bad thing (Louwers et al., 2015). It can inadvertently encourage employees to behave dishonestly in order to meet unreasonable goals. To prevent this, management should make realistic goals that are attainable but allow for such things as down time, maintenance, and employee fatigue. In addition, the management of a small, private company could even reward personnel periodically based on the accuracy of their work, rather than the speed at which they complete it. This would stress to personnel, especially those charged with producing information that will eventually make its way into the accounting system, that accuracy and integrity is of paramount concern.
Organizational structure is the third pillar of control environment. This concept relates to how a firm manages and situates its personnel in order to meet the objectives laid out by management (Louwers et al., 2015). Although organizational structure is not as involved with a small, private company as it is with a larger one, it is still a component of the control environment worth exploring and refining.
In a small, private firm, the organizational structure will be far simpler than that of a large, publicly held corporation. There are far less people and there is far less bureaucracy. The concept of organizational structure and the hierarchy within an organization is closely intertwined with another pillar of the internal control environment, authority and responsibility. A small company needs to address what different personnel will answer to, where and when they need to get approvals, and who they go to with problems (James, n.d.). The organizational structure should be developed in a way to provide for control over financial activity and review for all activity. The section on authority and responsibility goes into more depth on this issue.
Ensuring that there is financial reporting competency within the firm is the fourth pillar of a strong control environment. Simply, firms need to hire individuals for staff positions and management roles who are competent with respect to financial reporting (COSO, 2013). They should have the relevant experience and education that the position they are filling requires. Competent personnel is absolutely necessary in order to have strong internal control and accuracy in financial reporting.
The responsibility for financial reporting competency falls into the hands of the firms various management personnel, specifically the human resources management team. The firm can reasonably assure financial reporting competency by bolstering strict human resources hiring practices with continuing education requirements for all personnel in the accounting and finance department. Of course, there are costs associated with continuing education but these costs can be minimized by utilizing the controller to come up with continuing education curriculum based on new regulations and reporting standards. The items identified by the controller as important and the areas he sees as needing improvement can then be used by human resources management to facilitate continuing financial reporting competency through educational meetings or literature. The primary responsibility of management with respect to financial reporting competency is in hiring competent, educated personnel and then ensuring that personnel stays up to date with changing financial reporting standards and regulations.
Authority and responsibility is the fifth pillar of an effective control environment. This pillar addresses who has authority over each business function, who is in charge of various approvals, and what each employee is responsible for. The goal of communicating the process around who has authority and who has responsibility is to ensure accuracy in reporting and to eliminate questionable or illegal practices.
Communicating where authority and responsibility lies should be fairly straightforward for a small, private company. The personnel should be familiarized with the organizational structure and how it works in the aforementioned written code of conduct policy handbook. It should also be communicated verbally toward each staff member by the owner and management regularly so that each employee knows what their responsibilities are, to whom they report to, and what approvals are needed and from whom should they be obtained. First, each employee should know what they are responsible for, what is expected of them, and which manager or staff member they are to report to (James, n.d.). This gives staff direction and holds them accountable for their actions. Next, there should be a separation of duties to prevent fraud and control financial reporting (Louwers et al., 2015). In a small firm, that means that the junior accountant will be tasked with reconciling the various accounts, such as the cash account. The senior accountant will be in charge of making journal entries into the accounting system. A separate individual should receive the cash payments or credit card information on behalf of customers and enter the payments into the accounting system. Finally, the controller will review all of the information for accuracy and completeness. This allows four pairs of eyes to be involved in each transaction and serves to check and balance personnel dealing with financial information.
Additionally, purchasing and inventory management is an area where separation of duties are critically important in preventing fraud and ensuring accurate financial reporting (Bradford, n.d.). All purchases should be made by the purchasing manager and approved by their superior (Bradford, n.d.). Upon receipt of the units, two different staff members should count and inspect the inventory and match it to the purchase order. The same system requiring checks and balances should be used with respect to shipping orders that were filled. All shipping information should be matched against customer orders so that the integrity of the sales process as well as the information that will factor into the financial reporting will remain intact. Routine inventory counts should be done involving two staff members and a member of the management team to reduce fraud or theft and ensure accuracy valuation for financial reporting.
Another aspect of the authority and responsibility component of the control environment has to do with accounts payable. All checks need to be signed by the controller and a designated individual in upper management. There needs to be two signatures on every single check that leaves the firm. In the case of checks over $10,000, the owner and the controller need to be sign the check. If the owner is unavailable, verbal approval should be given to both the controller and the manager who is signing the check before the check is signed.
The final pillar of a strong internal control environment is human resources management. Human resources management must play a critical role in the implementation and the maintenance of a strong internal control environment. This is done through effective hiring practices and through a commitment to ensuring compliance (Louwers et al., 2015).
Human resources management can enhance the internal control environment by simply hiring competent personnel. At a small, private company, this is very important and can be achieved in a cost-effective way. For example, each prospective employee should go through a rigorous interview where they are asked various situational questions about the position they are applying for that demand critical thinking ability. This should be done by management personnel only if the prospective employee makes it through an initial vetting interview performed by the hiring manager. In addition, benchmarks should be set as far as education and experience requirements for each position. A junior accountant should have at least a bachelor’s degree in accounting or a related subject or the equivalent work experience. A senior accountant should have at least a bachelor’s degree in accounting or a related subject and at least five years of relevant work experience. Management should have the same strict education and experience requirement along with a track record of success. Background checks should be performed and the prospective employee’s references should be called and questioned in order to verify with a reasonable degree of assurance that he or she has the experience and education he or she claims to have. The background check also serves to make sure that the employee has no criminal history and that they can be reasonably trusted.
Moreover, human resources has the obligation to help foster a strong internal control environment (Louwers et al., 2015). Employees should be given worksheets to complete on a monthly basis that cover topics regarding ethics and integrity. Regular meetings should be conducted emphasizing core principles and operating procedures. Also, human resources management needs to write up personnel for misconduct and terminate them for serious offenses that involve fraud, theft, or failure to perform up to the standards that their position requires.
While the internal control environment is the foundation for strong internal controls, risk assessment is a critical component of effective internal control. The management of any firm, large or small, needs to articulate their goals very clearly in order to find the risks that may be associated with them (Louwers et al., 2015). For example, management must address what events and conditions could possibly get in the way and prevent the organization from achieving its clearly established goals. In addition, management must address the risk of fraud and the conditions that could increase this risk (Louwers et al., 2015).
Small, private companies are not required to perform a risk assessment but the activity will have the added value of strengthening the firm’s internal controls. A small, private firm should still conduct an economic risk analysis where they analyze trends in the growth or contraction of local, national, and even foreign markets if they sell goods abroad or purchase supplies from foreign vendors. Inflation, currency, and legal and political developments should all be reviewed and assessed based on the risk they present. For example, if a small firm has a small distribution agreement in Mexico and the country has a weakening peso, how will sales be affected? What if the firm is based in California and a higher tax on businesses was approved by voters and will set in later this year? If geopolitical events or an economic downturn slow sales, will it encourage dishonest behavior by personnel in order to meet the goals and objectives set forth during previous planning? What if a machine breaks down and production slows causing customer orders to remain unfilled and key performance metrics for the manufacturing department to decline? These are the kinds of risks to consider during the risk assessment process because they all require close attention and might even cause the firm to modify the existing controls that are in place in order to mitigate or manage each unique risk.
After the risk assessment has been completed, the firm will need to address how to improve internal controls to counter the risks if and when they are presented. This component of an internal control system is called internal control activities. Internal control activities are formulated by management but they are carried out by both management and employees (Louwers et al., 2015). These activities constitute the answer as to how the firm plans on mitigating and managing the risks that were identified during the risk assessment. Some activities will be preventative controls and some activities will be detective controls. Preventative controls control a risk before it happens (Bradford, n.d.). Detective controls detect a problem after the event has occurred (Bradford, n.d.). Internal control activities cover a wide scope and include controls over personnel, the accounting system, and the information technology system.
At a small, private company with limited personnel, putting into practice effective control activities much easier task than the one facing large corporations. In order to protect sensitive information and preserve the integrity of the information technology system, management should only allow a limited number of users, especially in the accounting system. The junior accountant should only be able to view most accounting information and can only enter information as it relates to reconciliation. All other work done by the junior accountant such as reviewing invoices to be paid and receiving checks to be deposited should be entered on an Excel spreadsheet and sent upstream for review. The senior accountant, who is responsible for making journal entries but not reconciling accounts, should be able to view everything in the accounting system and have access to everything except the reconciliations. Finally, the controller will have access to the whole accounting system. Everyone using the accounting computer system should have a unique password and should be restricted from performing tasks outside of their job description in order to mitigate risk. Only select, authorized personnel should have access to sensitive accounting information and banking information. If fraud risk is present, perhaps the small firm will need to add more separation of duties and possibly set up a lockbox where no payments whatsoever come to the office for payment. Furthermore, while it is costly and not required, a small, private firm may even hire an external auditor to audit the firm’s financial records and check for evidence of fraud or material misstatement.
Additionally, physical controls should be put into place. Physical controls benefit the firm by allowing only authorized personnel to have physical access to assets, documents, and important material that might be susceptible to fraud. The accounting system and the information technology system are obvious places where physical controls are needed. Inventory and equipment are slightly harder to restrict access to but equally important to safeguard (James, n.d.). Inventory counts should take place at minimum every quarter. Two staff members along with a manager should be tasked with this job. When inventory arrives, it should be inspected by a separate employee than the one who handled the purchasing under the supervision of a manager. Receiving documents should be matched to purchase orders and any discrepancies should be addressed (Bradford, n.d.). Also, video surveillance is never a bad idea in an area that houses valuable assets and inventory. While it does come at a cost, it effectively detours employees who may be considering theft. It also comes in handy in identifying the culprit in the event that items do go missing.
Also, business risk needs to be controlled (Louwers et al., 2015). Performance reviews are an excellent way of making sure that employees are being held accountable for their job performance and that management is being held accountable for their results. In a small, private company, the owner is the individual who should perform the performance reviews of management since there is no board of directors to answer to. Frequent performance reviews are have also proven to result in fewer accounting errors. Accuracy is crucial in financial reporting so while performance reviews may use some time and resources, they are a net benefit to the company’s financial health in the long run. However, employees and management need to be reviewed fairly. If economic conditions change, equipment breaks down, or the staff is shorthanded, the performance review should be conducted in a way as to reflect those changes.
The next component of an effective internal control system as identified by COSO covers information and communication. This topic deals with how records are kept including external and internal documents (Louwers et al., 2015). Information and records should be reliable, complete, and include source documents like invoices from a vendor. Internally, accounting procedures and rules should be made know to all relevant employees that handle or produce any of the inputs that go into the accounting information system. While this is not as time or space consuming at a small, private company as it is at a large, publicly traded corporation, it is still an important piece of the internal control system. Communication in this context largely deals with management’s responsibility to effectively convey responsibilities and objectives to every employee at the firm.
In order for a small, private firm to save and preserve all relevant information, it takes a strong commitment from the accounting department and related departments to thoroughness and completeness. The junior accountant or office assistant receiving the invoices for the accounts payable needs to make appropriate copies of the document and produce the work to accompany it on an Excel spreadsheet. They also need to make copies of all the checks that they receive and create a check register in Excel to accompany it. All bank statements used by the junior accountant for reconciling the cash account need to be copied, with the original copy being filed away in a secure location and the copy being used to accompany the reconciliation work. All notes and loan agreements should be copied and stored away in a secure location. There should be secure storage for accounts payable, accounts receivable, bank information, blanks checks, and personnel records along with all of the accompanying documentation (James, n.d.).
In addition, purchase orders receiving documentation should be copied by the purchasing manager and the employee charged with receiving inventory and supplies (Louwers et al., 2015). They should be matched to ensure accuracy and prevent fraud and then field away as support documentation in the accounts payable folder. Shipping documents and customer orders should be matched for accuracy, copied, and stored away with the accounts receivable records. Records, especially those that can be used as support documentation for tax purposes, should be kept for anywhere from three to seven years depending on the type of record (IRS, 2015). However, records from the last year or two should be kept in a place where they are readily available for the accounting staff and the management staff.
Communication is another aspect of the information and communication component of effective internal controls. The management of a small, private company must communicate standard accounting procedures, standard approval procedures, and general operating procedures to every employee. Even though a company of this size and structure is not required to do so, they would be well advised to put the procedures into writing so that employees can review the procedures and use it for reference if they need to in the future. Effective communication is just another way to strengthen internal controls and mitigate risk.
Lastly, monitoring internal controls is the final component of the effective internal control guidelines formulated by COSO. Internal controls need be consistently monitored in order to incrementally improve the internal control system and make changes to it where they are needed (Louwers et al., 2015). Personnel changes from time to time and risks vary in size and scope. It makes sense that the internal control system in place should be monitored to identify any breakdowns in the system or any changes that should be made to improve the overall effectiveness of the system. The monitoring of internal controls should be done at all firms, regardless of size.
There are a variety of monitoring activities that a small, private company should engage in to enhance the internal control system that they have in place. The first thing that management needs to commit to doing is monitoring the effectiveness of the internal control system (Louwers et al., 2015). They should do so periodically to look form improvements and honestly evaluate breakdowns in the internal control system. They should analyze operating metrics that could signal a breakdown within the internal control system (Louwers et al., 2015). If a deficiency is identified, it should be corrected and followed up on to make sure the changes have been implemented by personnel and have effectively nullified the previous breakdown. Also, management should periodically reconcile important accounts, like the cash account, to make sure that the checks and balances that have been put into place are actually working (Louwers et al., 2015). Management, along with some staff members should do a physical inventory count at least once every quarter to make sure the separation of duties with respect to purchasing, receiving, and shipping are having the desired effect on the internal control system. An internal audit can be conducted and steps should be taken by management if the internal control problems continue. The most important part monitoring the internal control system of a small, private company is to be consistent, cost-effective, and honest. If something is not working, then it needs to change to prevent fraud, material misstatement, and to ensure accurate financial reporting.
In conclusion, strong internal controls are absolutely critical to the success of a firm. Strong internal controls are not something that only large, regulated, publicly traded firms should have in place. Small, private companies can benefit from strong internal controls and should have them in place as well. Control environment, risk assessment, control activities, information and communication, and the monitoring of internal control activities are the components of a strong internal control system (COSO, 2013). Many of the guidelines COSO has laid out as part of a strong internal control system can apply to small firms as well as large ones at a very minimal cost. The implementation of even a few of the recommendations by COSO will help foster efficient and effective operations, reliable and accurate financial reporting, and ensure that the firm is in compliance with laws and regulations. As important as internal controls are for large, public companies, they are even more important for small, private companies where even relatively small mistakes are sometimes magnified and noncompliance can lead to nonexistence.
References
Committee of Sponsoring Organizations of the Treadway Commission (COSO). (2013, July 25).
A closer look 2013 internal control- integrated framework. Retrieved from the Accounting Research Manager database.
Louwers, T. J., Ramsay, R. J., Sinason, D. H., Strawser, J. R., & Thibodeau, J. C. (2015).
Auditing & assurance services (6th ed.). New York, NY: Mcgraw-Hill Eduaction.
Internal Revenue Service (IRS). (2015, June 30). How long should I keep records. Retrieved
from https://www.irs.gov/Businesses/Small-Businesses-&-Self-Employed/How-long-should-I-keep-records.
James, K. (n.d.) Five common features of an internal control system of business. Houston
Chronicle. Retrieved from http://smallbusiness.chron.com/five-common-features-internal-control-system-business-430.html.
Bradford, C. (n.d.) Examples of internal controls. Houston Chronicle. Retrieved from
http://smallbusiness.chron.com/examples-internal-controls-57039.html.