Internal Controls for Growing Private Companies
A growing private company needs a set of internal controls that covers financial authorization, accurate recordkeeping, asset protection, and IT access governance. The baseline is segregation of duties across the authorize-record-custody cycle, owner or management review of key financial outputs, and IT general controls over access and change management. These controls do not require a large team, but they do require deliberate design as the business scales.
Why Internal Controls Matter Before You Think You Need Them
Most private companies add controls reactively, after a fraud, a bad audit finding, or a failed lender covenant test. That is usually too late. The ACFE’s 2024 Report to the Nations found that more than half of occupational frauds happen because of a lack of internal controls or an active override of controls that exist on paper. The median loss per case was $145,000, and private companies suffered among the highest median losses across organization types.
The cost of building controls proactively is a fraction of that. More importantly, solid internal controls support accurate financial reporting, smoother audits, better access to capital, and scalable operations. Finance leaders at growth-stage companies often discover this when preparing for their first external audit or a debt transaction: auditors and lenders expect to see a control environment, not just clean numbers.
The Internal Controls Framework Every CFO Should Know
The standard reference for internal controls design is the COSO Internal Control Integrated Framework, first issued in 1992 and substantially updated in 2013. COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission, and its framework organizes internal controls into five components and 17 underlying principles.
For a private company, the five components translate directly to practical questions:
- Control Environment. Does leadership visibly set the tone for integrity and accountability? Are roles and responsibilities clear? This is the foundation. Weak tone at the top undermines every other control.
- Risk Assessment. Has the company identified what could go wrong in financial reporting and operations? Risk assessment is not a one-time exercise; it updates when the business changes (new markets, acquisitions, new ERP systems).
- Control Activities. These are the actual procedures, approvals, reconciliations, and system configurations that prevent or detect errors and fraud. This is where most companies focus their energy.
- Information and Communication. Are financial data and control responsibilities communicated clearly to the people who need them? Poor information flow is a common failure point in rapidly growing companies where processes outpace documentation.
- Monitoring. Are controls actually operating as designed? Monitoring can be as simple as a CFO reviewing exception reports monthly or as formal as an internal audit function.
Private companies are not required by law to adopt COSO, but the framework is widely used by auditors, lenders, and PE sponsors as the benchmark for evaluating a control environment. Designing your controls with COSO in mind makes every external conversation easier.
Segregation of Duties: The Most Critical Control
Segregation of duties is the single most powerful fraud-prevention control available to a private company. The concept is straightforward: no one person should be able to initiate a transaction, approve it, record it in the accounting system, and have custody of the related asset. Concentrating all four functions in one person eliminates independent checks and creates an opportunity for undetected fraud or error.
The Four Functions to Separate
- Authorization. Approving transactions before they are executed (purchase orders, vendor payments, payroll changes).
- Custody. Physical or system access to assets (cash, inventory, check stock, bank accounts).
- Recording. Entering transactions into the accounting system or general ledger.
- Reconciliation. Comparing recorded amounts to independent sources (bank statements, sub-ledgers, third-party confirmations).
Compensating Controls When Full Segregation Is Not Feasible
Many private companies have small accounting teams, and full segregation across all four functions is not always possible. When it is not, compensating controls can fill the gap:
- Owner or CFO review of bank statements. The person who receives and reviews the unopened bank statement each month should not be the same person who processes cash transactions.
- Dual approval thresholds. Require a second approver for payments or journal entries above a defined dollar amount (commonly $5,000 or $10,000, depending on company size).
- Vendor master change controls. Require a separate approver for any new vendor or bank account change, with an automated notification to a non-AP email address.
- Payroll register review. Have someone outside the payroll process review the payroll register before each pay run for unexpected changes to headcount, rates, or bank routing numbers.
- Surprise cash counts. Periodic unannounced counts of petty cash, inventory, or check stock reduce the opportunity window for misappropriation.
Compensating controls do not eliminate risk, but they dramatically increase the likelihood that irregularities will be caught quickly. The key is documenting what controls exist and who is responsible for performing them.
IT General Controls: The Layer Most Private Companies Overlook
As accounting moves to cloud-based platforms, IT general controls (ITGCs) have become as important as traditional financial controls. ITGCs govern the technology environment in which all other controls operate. Weak ITGCs can render financial controls ineffective, because if anyone can change system data or access privileges without oversight, the integrity of every downstream output is suspect.
Core ITGC Categories
Logical access controls. Only authorized users should have access to financial systems, and access should be role-based: accounts payable staff should not have the ability to approve payments or override approved purchase orders. Periodic access reviews (at least annually, ideally quarterly) should remove terminated employees and users who no longer need a given privilege.
Change management. Changes to financial systems, including configuration changes, should follow a documented process with testing and approval before being deployed to the production environment. Undocumented changes are a common audit finding and a genuine fraud risk, because unauthorized configuration changes can alter posting rules, payment routing, or approval workflows.
Computer operations and availability. Are backups running and tested? Is there a documented recovery plan if the accounting system goes down? Many companies discover these gaps only during an incident.
User authentication. Multi-factor authentication (MFA) for all financial system access is now a baseline expectation, not an advanced practice. Password sharing and generic system accounts undermine every other access control.
For companies with a SOC-covered vendor in their financial reporting chain (a cloud ERP, a payroll processor, a payment platform), your auditors will likely request the vendor’s SOC 1 report as part of their procedures. Understanding SOC reporting and the controls covered in a complementary user entity controls (CUEC) section can help you understand what obligations remain on your side of the shared-responsibility model.
Building an Internal Controls Framework by Growth Stage
Controls that work for a 10-person company need to be revisited at 50 employees, and again at 150. Growth creates new risk vectors: more employees with system access, new transaction types, geographic complexity, and eventually external stakeholders like lenders or investors who will scrutinize the control environment.
Startup to $10M Revenue
At this stage, the owner is often close enough to operations to serve as a key compensating control. Priority controls include:
- Owner reviews bank statements and signs all checks above a threshold.
- Accounting software uses role-based access so that no single employee can create, approve, and post a payment.
- Monthly bank reconciliations reviewed by the owner or an outside accountant.
- Vendor master changes require written owner approval.
$10M to $50M Revenue
As the company adds staff and transaction volume grows, manual oversight becomes harder to sustain. Priority shifts include:
- Formal approval workflows in the ERP system that enforce authorization before payment processing.
- A documented month-end close checklist with sign-off requirements.
- Internal audit or outsourced risk advisory reviews of key control areas at least annually.
- IT access reviews conducted quarterly, not just at onboarding/offboarding.
- A code of conduct and a confidential reporting mechanism (ethics hotline or anonymous form).
$50M and Beyond
At this stage, companies typically face scrutiny from lenders, private equity, or pre-IPO readiness work. The control environment needs to demonstrate not just that controls exist but that they operate consistently. Key additions include:
- A formal risk assessment process documented and updated at least annually.
- Separation of the internal audit function from the accounting close team.
- Control testing documentation that supports management assertions about the effectiveness of controls.
- Formal change management and SDLC processes for financial system modifications.
Working with a firm that can assess your control environment against the COSO framework and identify gaps before an audit or transaction is one of the most efficient investments a CFO can make at this stage. Audit and assurance services from a firm experienced in mid-market private companies can surface control weaknesses while there is still time to remediate them.
Common Internal Control Failures and How to Avoid Them
Documented controls that no one follows. A control that exists in a policy manual but is not actually performed is sometimes called a “paper control.” Auditors test whether controls operate as designed. Paper controls can create a false sense of security and a difficult audit conversation.
Excessive reliance on a single employee. Finance teams with one trusted accountant who handles everything from AP to reconciliations create concentration risk. Cross-training and documented procedures reduce dependence on any single individual.
Access not provisioned on a least-privilege basis. Giving everyone system administrator access because it is easier to manage is one of the most common ITGC findings. Least privilege means each user has only the access needed to do their job, nothing more.
No independent review of journal entries. Manual journal entries are a common vehicle for fraud and error. Someone outside the team that posts entries should review unusual or large journal entries, particularly at period end.
Ignoring controls during system implementations. ERP migrations and system upgrades are periods of heightened control risk. Data migration accuracy, new user access assignments, and changes to system configurations should all have formal controls and sign-off before go-live.
Frequently Asked Questions
What internal controls does a growing company need?
A growing private company needs controls covering financial authorization (who can approve transactions), recordkeeping accuracy (reconciliations and journal entry review), asset custody (who has physical or system access to assets), and IT access governance. The COSO Internal Control Integrated Framework organizes these into five components: control environment, risk assessment, control activities, information and communication, and monitoring. Most small and mid-size companies should start with segregation of duties across the authorize-record-custody cycle and management review of key financial outputs.
What is segregation of duties and why does it matter?
Segregation of duties means dividing the authorization, recording, custody, and reconciliation functions across different people so that no single employee can execute a fraud or error without another person detecting it. It is consistently identified as the most effective fraud-prevention control. When full segregation is not possible with available staff, compensating controls (such as management review of bank statements or dual-approval thresholds) partially substitute.
What is an internal controls framework?
An internal controls framework is a structured model that organizations use to design, implement, and evaluate their internal controls. The most widely used framework in the United States is the COSO Internal Control Integrated Framework (2013), which organizes controls into five components and 17 principles. Auditors, lenders, and regulators reference COSO when assessing whether a company’s control environment is adequate.
What are IT general controls (ITGCs) and why do they matter?
IT general controls govern the technology environment that all financial controls rely on. They cover logical access (who can use financial systems and with what permissions), change management (how system configurations are modified and approved), computer operations (backup and recovery), and user authentication. Weak ITGCs can undermine the reliability of financial controls that operate within those systems. As more accounting functions move to cloud platforms, ITGCs have become a standard part of any audit or control assessment.
How do internal controls change as a company grows?
Early-stage companies often rely on owner oversight as a primary compensating control. As headcount and transaction volume grow, formal workflows, system-enforced approvals, access reviews, and documented control procedures become necessary. By the time a company is preparing for a debt transaction, private equity investment, or external audit, the control environment needs to demonstrate not just that controls exist but that they are consistently operating as designed.
Do private companies have to follow COSO?
Private companies in the United States are not legally required to adopt the COSO framework. However, it is the benchmark that most auditors, lenders, and PE sponsors use when evaluating a control environment. Companies preparing for an external audit, seeking bank financing, or anticipating a transaction will benefit from designing their controls with COSO in mind, because it provides a common language for discussing control gaps and remediation.
Filed under: Audit Fundamentals