What ICFR/IFC reporting actually assesses
Internal Financial Controls reporting examines whether a company's internal controls over financial reporting are adequately designed and operating effectively — not whether the financial statements themselves are accurate (that's the core audit opinion), but whether the control environment that produces those statements is sound.
Common findings, and why they happen
- Lack of segregation of duties — the same person initiating, approving, and recording a transaction, common in smaller finance teams where headcount is limited
- Missing or informal approval trails — expenses or journal entries processed without a documented approval, even if the underlying transaction was legitimate
- Weak IT access controls — too many users with broad system access, or inadequate controls over who can modify financial data
- Undocumented processes — key financial processes that exist only as institutional knowledge, not written procedures, making consistency and review difficult
- Inadequate review of estimates and judgments — provisions, valuations, or accruals prepared without a clear secondary review
Why smaller companies find this genuinely challenging
Full segregation of duties assumes a certain team size — a lean finance function often can't fully separate every incompatible function the way a larger company can. This is a real, common constraint, not a sign of poor governance by itself — what matters is whether compensating controls (like closer management review) are in place to offset it.
A practical remediation approach
- Document your actual current processes, even informally, as a starting point
- Identify where a single point of control creates risk, and add a review or approval step even if full segregation isn't feasible
- Formalise IT access reviews on a periodic basis
- Build a simple, consistent review process for judgment-heavy areas like provisions and estimates
ICFR findings are meant to drive improvement, not just compliance box-ticking — addressing them properly tends to reduce the operational risk of errors and fraud regardless of the reporting requirement itself.
Related Reading
Have a question about your specific situation?
Talk to Our Team →