Controls that worked when an owner approved every transaction may become unreliable as a business grows. More employees, suppliers, customers and locations create more hand-offs and more opportunities for mistakes, delays or unauthorised activity.
This does not mean misconduct is occurring. It means the control environment should be reviewed as responsibilities and transaction volumes change.
What internal controls are designed to do
- safeguard cash, inventory, information and other assets;
- produce more reliable records and management reports;
- apply delegated authority consistently;
- identify errors or unusual transactions earlier;
- support compliance and record-keeping obligations; and
- maintain continuity when key people are absent.
Controls reduce risk; they cannot eliminate it. Their cost and complexity should be proportionate to the organisation.
Common pressure points
One person controls an entire transaction
Where possible, different people should initiate, approve and reconcile significant transactions. Small teams may not achieve complete separation, so management can add compensating reviews—for example, independent review of bank reconciliations or exception reports.
Approvals are verbal or unclear
A financial authority matrix should state who may approve purchases, payments, credit, discounts, contracts and capital expenditure, and at what limits. Splitting transactions to avoid limits should be prohibited.
Reconciliations are delayed
Bank accounts, receivables, payables, inventory and key control accounts should be reconciled on a defined timetable. Old or unexplained items should be assigned for investigation.
Access is not updated
Banking, accounting and business-system access should reflect current roles. Departing staff should be removed promptly. Privileged access and changes to supplier bank details deserve additional verification.
Management information arrives too late
Reports should focus on decisions. A concise monthly pack may include cash outlook, aged receivables, budget variances, major commitments and control exceptions.
A practical control review
- Map significant transaction flows from initiation to reporting.
- Identify where an error, unauthorised action or failure could materially affect the business.
- Record the controls intended to prevent or detect that event.
- Confirm who performs each control and what evidence is retained.
- Test a sample to see whether the control actually operates.
- Prioritise gaps by impact and likelihood.
- Assign actions, owners and dates, then follow them through.
Reviews may be triggered by rapid growth, a new system, a significant contract, staff changes or an incident. A fixed review cycle can also help, but there is no universal 12- or 24-month rule for every business.
Directors and management remain accountable
PNG’s Companies Act sets out duties for directors, including acting in good faith and in what the director believes to be the company’s best interests. Appropriate governance and monitoring arrangements depend on the company’s circumstances and should be considered with qualified advisers.
External advisers can provide an objective diagnostic and implementation support. They do not assume management responsibility or provide assurance unless that service is specifically agreed and appropriately qualified.
GoBisnix can help identify priority control gaps and develop an achievable improvement roadmap. Request a confidential conversation.
Sources and further reading
- IPA — Companies Act 1997 (consolidated to 2014)
- Bank of Papua New Guinea — Our legislation
- Internal Revenue Commission — official information
General information only. It is not accounting, tax, legal, audit or assurance advice. Obtain advice appropriate to your circumstances.
