CPA · CISA · CISM · CDPSE · CCSE · MBA
Risk register and internal control matrix under review during an enterprise risk assessment

Enterprise Risk Management and Internal Controls Assessment

Where the business can fail, whether the control that should catch it works, and what to fix first.

What does an internal controls assessment in California tell you?

Whether anything would catch a failure before it mattered. The answer is usually yes for the risks a company has already experienced and no for the ones it has not, because control environments grow reactively: each control traces back to an incident, so the set covers history rather than exposure. The assessment establishes where the business can fail, whether the control that should catch it works, and what to fix first.

An internal controls assessment in California answers a question most companies assume they already know the answer to: if something went wrong in this process, would anything catch it before it mattered?

The reason is that controls get added after incidents and almost never get retired afterwards. What accumulates is a record of what has already gone wrong here, not a map of where this business can fail next. The process redesigned last year and the system that replaced the one a control was written for are both sitting outside it.

Why an internal controls assessment in California starts with risk

Assessing controls without first assessing risk produces a list of what exists rather than a view of what is missing. The sequence has to run the other way.

A workable risk assessment is not a hundred-line register scored one to five. It is a short conversation with each function about what would actually damage the business, converted into a small number of scenarios with a plausible magnitude attached. Ten to fifteen risks that a management team genuinely recognises is more useful than eighty that were generated to be comprehensive.

The output then drives everything: control testing goes where the exposure is, remediation is sequenced by consequence, and the board receives something it can act on rather than a heat map.

Segregation of duties in a small finance team

The textbook answer (separate the initiation, approval, recording and custody of every transaction) assumes enough people to separate them. A five-person finance team cannot fully segregate, and pretending otherwise produces documentation nobody follows.

The realistic approach is to identify the small number of combinations that genuinely enable material loss and address those specifically. In practice that is a short list:

  • The same person can add a vendor and approve payment to it
  • The same person can change employee bank details and run payroll
  • The person who prepares the bank reconciliation is the person who reviews it
  • One person holds both the ability to post journal entries and to approve them
  • Administrative access to the accounting system is held by someone who also processes transactions in it

Where separation is impossible, compensating detective controls do real work: a monthly review of new and changed vendor master data by someone outside AP, an out-of-band confirmation for bank detail changes, and an owner review of the payment run against supporting documents. These are cheap, and each of them defeats a specific fraud that occurs regularly to companies of this size.

Outsourced and co-sourced internal audit

Companies rarely required to have internal audit still benefit from the function once complexity passes a threshold, multiple entities, regulated activity, a lender requiring assurance, or a board wanting independent verification of what management reports.

Building it internally is expensive and produces a function reporting to the people it examines. Outsourcing gives independence and a broader skill base; co-sourcing pairs an internal resource with external specialists for areas requiring depth the in-house team does not have. IT controls, privacy, treasury.

The deliverable that matters is an annual plan tied to the risk assessment, a small number of substantive reviews executed properly, and findings reported to the board with management's response alongside. What does not work is an internal audit function producing volume to justify its existence.

Fraud risk, specifically

Occupational fraud in owner-managed companies follows a small number of patterns, and they are not sophisticated. Fictitious vendors created by someone with vendor master access. Payroll additions or unauthorised rate changes. Expense reimbursement abuse that grows because nobody checks. Cheque and ACH tampering. Diversion of customer receipts where the same person banks and posts them. Business email compromise, in which a convincing email redirects a legitimate payment to a new account.

Each has a specific, inexpensive control. The reason they succeed is not that the controls are hard; it is that nobody assigned ownership of the review, so it happened for two months and then stopped.

What a report looks like

Findings ranked by consequence, not by discovery order, with an owner and a date against each. A distinction drawn between what must be fixed, what should be, and what is worth knowing but not acting on. And a remediation sequence that respects dependencies, several fixes only work once a prior one is in place, and attempting them in the wrong order wastes a quarter.

Where the assessment feeds a SOX 404 programme or a SOC 2 engagement, the control documentation is written in a form those frameworks can consume directly, rather than being rewritten later.

Javed Peeran CPA

Javed Peeran

CPA · CISA · CISM · CDPSE · CCSE · MBA

Licensed by the California Board of Accountancy and the author of every article published here. Thirty years of practice covering external audit of banks, insurers and mortgage companies, fifteen years as CFO and Corporate Controller inside technology companies, and IT governance and security compliance work spanning SOX 404, SOC 1 and SOC 2, ISO 27001, FISMA, FedRAMP, PCI DSS, HIPAA/HITECH, CCPA and GDPR, plus Oracle ERP migrations and, more recently, generative-AI audit automation.

What the engagement delivers

  • Enterprise risk assessment with scenario-based exposure analysis
  • Process narratives and control matrices for in-scope cycles
  • Segregation of duties analysis with a practical compensating-control design
  • Control effectiveness testing with documented evidence
  • Fraud risk assessment covering the patterns specific to company size and sector
  • Prioritised findings register with owners and target dates
  • Dependency-sequenced remediation roadmap
  • Outsourced or co-sourced internal audit plan and execution
  • Board or audit committee reporting and briefing

How a typical engagement runs

  1. Risk first

    Interviews across functions to establish what would genuinely damage the business, converted into a small number of scenarios with magnitude attached.

  2. Walk the processes

    Follow real transactions end to end through the systems and the people. Documented process and actual process diverge more often than not, and the divergence is where the exposure lives.

  3. Test

    Sample-based testing of the controls that address the significant risks. Design effectiveness and operating effectiveness are assessed separately, a well-designed control that nobody performs is still a gap.

  4. Report and sequence

    Findings ranked by consequence, remediation sequenced by dependency, and a briefing to the board or owner that says plainly what is not working.

Enterprise Risk & Internal Controls across Ventura County and Los Angeles

This service is delivered on site and remotely across the firm's service area. See how it applies locally:

Enterprise Risk & Internal Controls: questions we are asked

Not answered here? Ask Javed directly

We have five people in finance. How can we segregate duties?

You cannot fully, and a framework that pretends otherwise will be ignored. Target the specific combinations that enable material loss rather than attempting textbook separation everywhere.

The highest-value single change in most small finance functions is removing the ability for one person to both create a vendor and approve payment to it. After that, an out-of-band verification step for any change to a vendor or employee bank account, and a review of the bank reconciliation by someone who did not prepare it, typically the owner, which is perfectly acceptable.

How is this different from what our external auditor already does?

Different purpose, and much narrower scope on the auditor's side. An external auditor evaluates internal control only to the extent needed to plan the financial statement audit. They are not looking for operational risk, fraud exposure outside financial reporting, or process inefficiency, and they are not obliged to tell you about weaknesses that do not affect their opinion.

The management letter you receive is a by-product of the audit, not an assessment. It is genuinely useful and it is not the same thing.

Is an enterprise risk assessment worth it for a company our size?

Below roughly $10M in revenue with a single location and one product line, a formal programme is usually disproportionate; the risks are visible to the owner without a framework. A focused fraud risk and segregation of duties review is the better use of the budget.

The threshold is complexity rather than revenue. Multiple entities or locations, regulated activity, significant third-party dependency, or an owner no longer close enough to daily operations to see problems directly, any one of those makes formal assessment worth the cost.

Can the same firm assess our controls and also perform our audit?

No, where the assessment amounts to designing or operating the controls. Independence rules restrict a firm performing an attestation engagement from also performing management functions or designing the controls it will subsequently test.

Assessment and testing performed on behalf of management, for a company audited elsewhere, is entirely appropriate; and is how most of this work is structured.

What if the assessment finds something involving a senior person?

This is agreed before the engagement begins, not after a finding arises. The reporting line for the engagement is defined at the outset (typically to the board, the audit committee, or the owner) and it is defined so that a finding involving a member of management does not have to pass through that person to reach the people who need it.

Where a finding suggests possible fraud, the work stops and the matter is escalated immediately rather than continuing under an assessment scope, because an assessment is not an investigation and conflating the two damages both.

Related services

SOX 404 Compliance

Scoping, control design, testing and remediation for Section 404, including the first-year programmes that decide whether year two is manageable.

SOX 404 support

Organisations we have worked with

Three decades of audit, controls and finance leadership across banking, card, mortgage, insurance, staffing and semiconductor.

  • Diodes Incorporated
  • City National Bank
  • Robert Half
  • SMBC
  • PennyMac
  • American Express
  • Zenith Insurance
  • Capco Consulting Services
  • WebVision

Get in touch

Enquire about enterprise risk & internal controls

A sentence or two about your situation (the standard involved, the deadline, and what has already been attempted) is enough to get a useful reply.

Have a deadline, or just a question?

Send the shape of it. The first call is diagnostic, not billed, and it regularly ends with a smaller engagement than the one you asked about.

Javed Peeran CPA Request a consultation

Answered personally, within one business day. Your details are used only to reply to you, see our privacy policy.

Talk through a enterprise risk & internal controls engagement

Thirty years of audit, financial leadership and IT governance in one engagement, and a direct answer about scope, sequence and cost before anything is signed.

WhatsApp Us
Call Now