Internal Control Gaps in SMEs: Practical Risks and Improvements

Internal Control Gaps in SMEs: Practical Risks and Improvements 

Small and medium-sized businesses often rely heavily on trust, speed and the direct involvement of an owner. Those qualities can support growth, but they are not substitutes for internal control. 

A control is any policy, approval, restriction, reconciliation or review designed to help the business achieve an objective or reduce a risk. Effective controls protect cash and other assets, improve the reliability of reporting, support compliance and make responsibilities clear. 

The goal is not to create unnecessary paperwork. It is to place sensible checks where an error or unauthorised action could cause material damage. 

Why control gaps develop 

Control gaps often appear gradually rather than through a deliberate decision. A process that was acceptable when a company had five transactions a week may become unsafe when it has fifty transactions a day. 

Common causes include: 

  • Rapid growth without corresponding changes to finance processes. 
  • Too much system access given to one employee. 
  • Informal approvals through calls or messages with no retained evidence. 
  • Lack of written responsibilities and delegated authority limits. 
  • High staff turnover or insufficient handover. 
  • Accounting software configured without access or change controls. 
  • Owners assuming that personal oversight covers every transaction. 
  • Reconciliations performed by the same person who processes transactions. 

Segregation of duties—and what smaller businesses can do 

Segregation of duties means dividing incompatible responsibilities so that one person cannot initiate, approve, record and conceal the same transaction. 

The strongest payment process, for example, separates supplier creation, invoice recording, payment preparation, payment approval and bank reconciliation. A small business may not have enough employees to separate every step. That does not mean the risk should be ignored. 

Compensating controls may include: 

  • Owner approval of new suppliers and changes to bank details. 
  • Dual authorisation for online payments. 
  • Read-only bank access for accounting staff. 
  • Independent review of bank reconciliations. 
  • Monthly review of exception reports and changes to master data. 
  • Transaction limits based on role and seniority. 
  • Direct review of supporting documents for high-value or unusual payments. 

The correct control structure should reflect the size, transaction volume and risk profile of the business. 

Key control areas and common gaps 

Revenue and collections 

Common gaps: Invoices are raised outside the accounting system; discounts or credit notes are not approved; services are delivered without billing; one person collects cash and records receipts; overdue balances are not followed up. 

Practical controls: Use sequential system-generated invoices, approve price changes and credit notes, reconcile sales records to contracts or delivery evidence, issue official receipts, deposit cash promptly and review customer ageing regularly. 

Purchasing and supplier payments 

Common gaps: Purchases are made without authorisation; supplier bank details can be changed without review; invoices are paid twice; payment evidence is incomplete; personal and business purchases are mixed. 

Practical controls: Establish approval limits, maintain an approved supplier list, verify bank-detail changes independently, match purchase orders or approvals to receipt evidence and invoices, mark paid documents, and use dual bank authorisation. 

Cash and banking 

Common gaps: Shared online-banking credentials, excessive petty cash, delayed bank reconciliations, unidentified transfers and no review of unusual payments. 

Practical controls: Assign individual user access, enable multi-factor authentication, restrict permissions, set transaction limits, reconcile every account monthly and require independent review of unusual or high-value activity. 

Payroll 

Common gaps: The same person adds employees and processes payroll; salary changes lack approval; former employees remain on the payroll; overtime and deductions are not supported. 

Practical controls: Approve joiners, leavers and salary changes independently; reconcile the payroll register to employment records and bank transfers; restrict employee-master access; and review exception reports before payment. 

Inventory 

Common gaps: Inventory movements are not recorded promptly; damaged or obsolete stock remains at full value; system quantities are never compared with physical stock; warehouse access is unrestricted. 

Practical controls: Use authorised goods-received and dispatch records, restrict physical access, perform periodic counts, investigate differences, monitor slow-moving items and approve write-offs. 

Accounting and financial reporting 

Common gaps: Journal entries have no supporting documents; balance-sheet accounts are not reconciled; periods remain open indefinitely; users can edit prior-year transactions; management reports are issued without review. 

Practical controls: Require journal descriptions and support, approve unusual entries, use a monthly close checklist, lock completed periods, reconcile key accounts and document management’s review of financial reports. 

Systems and data 

Common gaps: Shared passwords, excessive administrator access, former employees retaining access, no reliable backup, and changes to supplier or customer data with no history. 

Practical controls: Give each user a unique account, apply least-privilege access, review user rights periodically, remove access immediately when staff leave, enable audit logs and test backups and recovery procedures. 

How to assess control gaps properly 

A useful control assessment should follow the transaction from beginning to end. Policies alone are insufficient; the assessor should understand what staff actually do and inspect the evidence retained. 

A practical approach includes: 

  1. Identify the objectives and material risks of each process. 
  2. Document how transactions are initiated, approved, processed, recorded and reviewed. 
  3. Identify the existing controls and who performs them. 
  4. Determine whether the design of each control addresses the risk. 
  5. Where included in the agreed scope, inspect whether selected controls have been performed as described. 
  6. Rate gaps based on likelihood and potential impact. 
  7. Recommend realistic actions, responsible owners and target dates. 
  8. Follow up whether agreed improvements were implemented. 

Recommendations should be specific. “Improve controls over payments” is not an action plan. “Require independent callback verification for every supplier bank-detail change before the first payment” is clear, assignable and testable. 

Not every weakness has the same priority 

Control findings should be prioritised. A practical rating may consider: 

  • The potential financial and operational impact. 
  • The likelihood of the issue occurring. 
  • Whether the gap could enable fraud or regulatory non-compliance. 
  • The number and value of transactions exposed. 
  • Whether another control reduces the risk. 
  • The cost and feasibility of remediation. 

High-risk issues—such as a single person controlling supplier setup and payment approval—normally require urgent attention. Lower-risk documentation improvements can be addressed through a planned timetable. 

Final thought 

Trust is important, but control protects both the business and its employees. Clear approvals, restricted access, regular reconciliations and visible management review reduce ambiguity and make errors easier to detect. 

The best control environment is not the one with the most procedures. It is the one in which the most important risks are understood, responsibilities are clear and key controls are performed consistently. 

How Steadence can help 

Steadence assists management in documenting financial processes, identifying control-design gaps and developing practical recommendations suited to the scale and complexity of the business. The work is advisory in nature and does not constitute an audit or assurance opinion. 

This article provides general information and does not constitute audit, assurance, tax or legal advice for a specific business.