Internal Financial Controls
Internal controls aren't just for listed companies — smaller businesses are often more exposed, because one person frequently raises invoices, approves payments and reconciles the bank account at once. The five pillars are separation of duties, authorisation, documentation, supervision and reconciliation. Fraud against UK businesses with employees cost an estimated £5.2 billion in the year to March 2024, and directors remain personally responsible for their company's records even after hiring an accountant — with a £3,000 fine or disqualification for failing to keep them. Cross the audit exemption thresholds (turnover over £15m, balance sheet over £7.5m, more than 50 employees — any two of three) and a statutory audit becomes mandatory, testing exactly these controls.
Internal controls have a reputation problem: most business owners assume they're something for listed companies with audit committees, not something a growing business needs to think about yet. That assumption is exactly how errors go uncaught, cash goes missing, and a business finds out its numbers were wrong months after the decisions built on them were already made.
Internal controls aren't bureaucracy for its own sake — they're the systems that make sure one person's mistake, or one person's dishonesty, gets caught before it becomes a much bigger problem. The Finance Equation Ltd is an award-winning, ACCA-regulated firm of chartered certified accountants with over 30 years' experience, helping businesses across London design and run financial controls that fit a growing business, not a listed one.
It's Not Just a Big Company Problem
If anything, smaller and mid-sized businesses are more exposed, not less. A large company has departments, layers of approval and dedicated compliance staff built in almost by accident, simply because of its size. A smaller business often has one person raising invoices, approving payments and reconciling the bank account — sometimes the owner themselves, stretched across every function at once. That concentration of control isn't a moral failing, it's just what happens when a business grows faster than its admin does. But it's precisely the condition internal controls exist to fix.
The risk compounds with growth, not against it. A business that runs fine on trust and familiarity at five people is a very different proposition at twenty-five, with more transactions, more staff holding system access, and an owner who can no longer personally review every payment before it goes out. Controls that felt unnecessary at the start are exactly what stand between a fast-growing business and a loss that goes unnoticed until the bank balance simply doesn't add up.
The Five Pillars of Financial Control
Financial internal controls aren't one thing — they're a set of interlocking procedures, and a business is only as protected as its weakest one:
- Separation of duties
No single person should be able to both authorise a payment and record it in the books unchecked — splitting these roles, even across a small team, is what makes an error or a dishonest transaction visible rather than invisible.
- Authorisation
Every transaction above an agreed threshold should require sign-off from someone with the authority to approve it, so spending decisions are deliberate, not just whoever has access to the bank account that day.
- Documentation
Every financial transaction needs a paper trail — an invoice, an approval, a record of who did what and when — so the business can reconstruct what happened without relying on memory.
- Supervision
Controls only work if someone is actually checking that they're being followed, not just written down in a policy document nobody reads.
- Reconciliation
Bank balances, supplier statements and internal records need to be checked against each other regularly, so a discrepancy is caught within weeks, not discovered a year later at the annual audit.
None of these five pillars works well in isolation. Separation of duties means little without documentation to prove it actually happened; authorisation limits are only as good as the supervision that checks they're being respected. The businesses that get into real trouble are rarely the ones with no controls at all — they're the ones with one or two pillars in place and a gap running straight through the rest.
What Weak Controls Actually Cost
This isn't a theoretical risk. The Home Office's Economic and Social Cost of Fraud 2023 to 2024 report estimated that fraud against businesses was £5.2 billion in the year to March 2024, with businesses in England and Wales with employees spending approximately £3.6 billion in the last 12 months defending against it, and still losing around £507 million directly to fraudsters.
Because fraud is only counted when it's actually detected, the real figure for undiscovered losses — the kind weak internal controls are most likely to miss entirely — is almost certainly higher. The damage isn't limited to fraud, either. Without reconciliation and supervision built in, ordinary errors — a duplicated payment, a missed invoice, a miscoded transaction — can sit undetected for months, distorting the numbers a business is actually making decisions on. By the time it's found, the cost isn't just the error itself, but every decision made while the numbers were wrong.
Invoice Fraud: The Threat Good Controls Actually Stop
One of the most common ways weak controls translate directly into a financial loss is invoice fraud, where criminals impersonate a genuine supplier, or intercept an email thread, to divert a real payment into their own account. The National Crime Agency's guidance on invoice fraud describes exactly how it happens: a fraudster impersonates a trusted supplier, often by compromising or spoofing an email, and asks for a payment to be sent to "updated" bank details — sometimes adding pressure by claiming the payment is already overdue. The NCA's own recommended defences map directly onto good internal controls:
- Verify by phone, on a known number
Confirm any change of bank details by calling the supplier on a number you already had on file — never one supplied in the request itself.
- Get a second person to authorise
Have a colleague authorise high-value payments, so a single compromised inbox can't move money on its own.
- Cross-check against previous invoices
Compare any new invoice against a previous, genuine example before it's paid — small formatting or account-detail changes are often the only tell.
Every one of those steps maps directly onto separation of duties and authorisation — which is exactly why a business with weak controls is so much more exposed to this specific, and increasingly common, type of fraud.
The Legal Reality: You're Responsible, Even If You Don't Keep the Books
Directors sometimes assume that hiring an accountant transfers the responsibility for the company's records along with the task. It doesn't. Gov.uk guidance for company directors is clear that you remain legally responsible for your company's records, accounts and performance, even where a professional has been engaged to help manage them.
That responsibility carries real weight. Companies must keep accounting records covering all money received and spent, company assets and debts, and stock and transaction details, retained for at least six years from the end of the financial year they relate to. Fail to keep adequate records, and a director can be fined £3,000 by HMRC or disqualified from acting as a director altogether — a personal consequence that internal controls, properly designed, are built to prevent.
When Controls Become a Legal Requirement
There's also a point at which internal controls stop being optional best practice and start being tested for real. Private limited companies qualify for audit exemption only where they meet at least two of three conditions:
Turnover
No more than £15 million a year.
Balance sheet
Assets worth no more than £7.5 million.
Employees
50 or fewer, on average.
Cross two of those thresholds and a full statutory audit becomes mandatory, with an external auditor testing exactly the separation of duties, authorisation and reconciliation processes this page describes. Businesses that have never had to think seriously about internal controls often find this is the point they're tested for the first time, under real scrutiny, with no time left to build them properly. Getting the fundamentals in place well before that threshold is reached means a statutory audit, when it arrives, confirms what's already working rather than exposing what isn't.
Protecting the Company Itself, Not Just the Numbers
Internal controls aren't only about what happens inside the business — they extend to protecting the company's own records from external interference. Companies House guidance on protecting your company from fraud and scams recommends registering for its free PROOF scheme, which prevents unauthorised paper-filed changes to a company's registered office and officer details, along with treating your Companies House authentication code with the same care as a bank card PIN. It's a reminder that financial control isn't only about the numbers in the accounts — it's about who can act on behalf of the company at all.
How We Help
The obstacle most growing businesses face isn't understanding why internal controls matter — it's resourcing them without the overhead of a full-time finance hire. A part-time, fractional Finance Director closes exactly that gap: designing separation of duties that actually fits a small team, setting authorisation thresholds that match how the business really operates, and building the supervision and reconciliation habits in from the start, rather than retrofitting them after something has already gone wrong. That's precisely where our fractional CFO service picks up — bringing board-level financial oversight to a business that isn't ready for, or doesn't need, a full-time finance director, but can no longer afford to run without proper controls in place.
Quick Questions
What are the five pillars of financial control?
Separation of duties, authorisation, documentation, supervision and reconciliation — each reinforces the others, so a business is only as protected as its weakest pillar.
Is a director still responsible for the company's records if an accountant handles them?
Yes. Directors remain legally responsible for their company's records, accounts and performance even where a professional has been engaged to help manage them — failure to keep adequate records can lead to a £3,000 HMRC fine or disqualification.
When does a UK private company need a statutory audit?
Once it exceeds at least two of three thresholds: turnover over £15 million, balance sheet assets over £7.5 million, or more than 50 employees on average.
Why Businesses Choose Finance Equation
We're an award-winning, ACCA-regulated practice with more than 30 years advising businesses across London on financial structure, controls and governance — not a service bolted onto bookkeeping, but a core part of how we help a business grow safely. Every control we recommend is built around how your business actually operates, not a generic policy template that looks good in a folder and nowhere else.
Because we're chartered certified accountants first, the systems we put in place sit behind advice from people who understand your numbers and your risk — so a control isn't just documented, it's actually followed.
Sources
- Economic and social cost of fraud 2023 to 2024 — Home Office
- Invoice fraud infosheet — National Crime Agency
- Being a company director — GOV.UK
- Company and accounting records — GOV.UK
- Companies Act 2006, s.382 (small companies) — legislation.gov.uk
- Protecting your company from fraud and scams — Companies House
