Strategic Business Leader · Internal control and management reporting
Internal Control Systems and Frameworks for ACCA SBL
Updated 11 October 2026 · Fact-checked
An internal control system is the set of policies, procedures and behaviours that helps a board achieve objectives, protect assets, keep reliable records and comply with rules. Frameworks such as COSO and the UK Corporate Governance Code guidance structure how you design, assess and report on it.
Understand Internal Control Systems and Frameworks
Start with the purpose. A board cannot watch every transaction. So it builds a system that gives reasonable assurance that objectives will be met. The objectives are usually effective and efficient operations, reliable reporting, and compliance with laws and regulations. Protecting assets and preventing and detecting fraud sit under these.
A framework gives you a ready structure so that nothing is missed. The COSO internal control framework has five components: the control environment, risk assessment, control activities, information and communication, and monitoring. The control environment is the base. It covers integrity, ethical values, board oversight, structure, authority, and the commitment to competence. Weakness here undermines every other component.
The UK Corporate Governance Code and its related guidance take a board-level view. The board is responsible for determining the nature and extent of the risks it will take, and for maintaining sound risk management and internal control systems. The board should monitor these systems and review their effectiveness at least annually, and report on the review. The guidance stresses that the system should be embedded in operations, respond to changing risks, and be reviewed by the board, often supported by the audit committee.
Now the limits. No system gives absolute assurance. Controls can fail through human error, poor judgement or misunderstanding. They can be bypassed by collusion between staff, or overridden by management. Cost matters too: a control should not cost more than the risk it addresses. Controls aimed at routine transactions may not catch unusual ones. The system can also become out of date as the business changes.
Finally, do not confuse internal control with internal audit. Internal control is the system itself, owned by management and the board. Internal audit is a function that independently reviews and tests that system and reports on it. Internal audit is part of monitoring, not the whole system.
Key rules to remember
- COSO internal control components
- Control environment + Risk assessment + Control activities + Information and communication + Monitoring
- Five components. Learn the order, with the control environment as the foundation.
- COSO objectives categories
- Operations + Reporting + Compliance
- The three categories of objectives that the controls support.
- Cost-benefit rule for controls
- Benefit of control ≥ Cost of control
- A rule of thumb for design. Benefits include losses avoided and better assurance.
- Board responsibility under UK Code guidance
- Board = determine risk appetite + maintain sound systems + review effectiveness + report
- Review should cover all material controls, including financial, operational and compliance controls.
- Control type grouping
- Preventive, detective, corrective, directive
- Use these labels when you classify controls in a scenario.
How to solve Internal Control Systems and Frameworks questions
Use this method for any SBL requirement on control systems, frameworks or weaknesses. Always tie your answer to the scenario.
- 1Read the requirement and note the verb: explain, evaluate, assess, recommend, or advise. Note who you are writing for and in what role.
- 2Pick the framework that fits. Use the five COSO components as a checklist for design or weakness questions. Use board responsibilities for governance questions.
- 3Scan the scenario and tag each fact to a component, such as tone at the top (control environment) or no review of exceptions (monitoring).
- 4For each weakness, state the issue, explain the risk it creates for this business, and give a specific recommendation.
- 5For limitations, link each general limit to a scenario fact, for example one person doing two tasks makes collusion or override easier.
- 6Weigh cost against benefit and say which controls you would prioritise and why.
- 7Close with a clear conclusion or recommendation in the format asked, such as a report or briefing note, to earn professional skills marks.
Quickest way: COSO scan with Issue, Risk, Fix
When to use it: Use when time is short and the scenario lists many control problems.
- Write the five COSO headings down the page in two minutes.
- Place each scenario fact beside the matching heading.
- Write one line per fact: Issue, Risk, Fix.
- Add one line on cost versus benefit and one on inherent limitations.
- Finish with a short prioritised recommendation.
Common mistakes in Internal Control Systems and Frameworks
Treating internal control and internal audit as the same thing.
Both words appear together in the syllabus and in practice.
Fix: Say that internal control is the system owned by management. Internal audit is an independent function that reviews it as part of monitoring.
Listing the five COSO components without applying them.
Students memorise the list and treat it as the answer.
Fix: Use the list only as a checklist. Each point must name a scenario fact, the risk and a fix.
Claiming a good system eliminates fraud and error.
Students forget that the assurance is only reasonable.
Fix: State the limits: human error, collusion, management override, cost and changing conditions.
Giving generic recommendations such as 'improve controls'.
Time pressure and lack of a method.
Fix: Name the specific control, who performs it, how often and what it prevents or detects.
Ignoring the control environment and tone at the top.
Students focus on visible procedures like authorisation and reconciliations.
Fix: Check for culture, ethics, board oversight and pressure to hit targets. These often drive the real problem.
Recommending expensive controls without weighing cost.
Students aim to cover every risk.
Fix: Prioritise by likelihood and impact, and say when a control is not worth its cost.
Worked examples
Example 1
A listed group has had several errors in its management accounts. The CEO also approves large payments and the finance director has not reviewed the system for three years. Explain, using COSO, the weaknesses and advise the board what to do.
Show the solution
- Control environment: the CEO approving large payments with no independent check suggests weak tone and oversight. Risk: management override and fraud. Fix: require a second approver outside the CEO's line for payments above a set limit.
- Risk assessment: no review for three years means changes in the business and its risks may be missed. Risk: new exposures go uncontrolled. Fix: carry out a formal annual risk assessment.
- Control activities: errors in management accounts point to weak checks such as reconciliations and review. Fix: add reconciliations and supervisory review before reports are issued.
- Information and communication: errors reaching reports mean poor data quality and unclear responsibility. Fix: define data owners and reporting timetables.
- Monitoring: no review means nobody tests whether controls work. Fix: the board, with the audit committee, should review effectiveness at least annually, using internal audit to test controls and report findings.
Answer: The main weaknesses are a weak control environment (CEO payment authority), no risk assessment, poor control activities and no monitoring. The board should add independent approval, an annual risk assessment, reconciliations and review, and a regular effectiveness review supported by the audit committee and internal audit.
Example 2
The board of a retailer says its new control system 'will stop all fraud'. Evaluate this claim and explain the limitations of internal control systems.
Show the solution
- State that internal control gives reasonable, not absolute, assurance. The claim is wrong.
- Human error: staff may misunderstand procedures or make mistakes, especially if busy or poorly trained.
- Collusion: two or more staff working together can defeat controls built on segregation of duties.
- Management override: senior managers can bypass controls, and a retailer with a dominant leader is exposed to this.
- Cost: some controls cost more than the loss they prevent, so the board will accept some residual risk.
- Change: new products, systems or stores can make controls out of date, so the system needs regular review.
- Recommend that the board restate its objective as reducing fraud risk to an acceptable level, and add monitoring and whistleblowing channels.
Answer: The claim is not valid. A control system can reduce fraud risk but not eliminate it, because of human error, collusion, management override, cost constraints and changing conditions. The board should aim for reasonable assurance, keep reviewing controls and support them with monitoring and a whistleblowing route.
Exam tips
- Apply, do not recite. Marks come from linking each COSO component or limitation to a named fact in the scenario.
- Use clear sub-headings that match the requirement, such as one per component, so the marker can see your structure quickly.
- Always cover cost versus benefit and the idea of reasonable assurance when you evaluate a system.
- When asked about internal audit, separate it from internal control: internal audit reviews and reports, management owns the controls.
- Finish with a prioritised recommendation and a conclusion in the requested format to pick up professional skills marks.
Practice questions from Internal control and management reporting
- Zentra Foods, a listed manufacturer, has a board that wants to assess whether its controls over financial reporting are effective. The board…
- Pelham Pharma is deciding between an in-house internal audit team and outsourcing. The company operates in a highly specialised regulated ar…
- At Halden Bank, the head of internal audit reports functionally to the chief financial officer, who also approves the audit budget. The audi…
- Maribel Retail's external auditor also provides its outsourced internal audit service and designs the company's new inventory control system…
- Orion Logistics outsourced internal audit to Fenwick LLP under a three-year contract at a fixed annual fee for 120 audit days. The head of f…
Internal Control Systems and Frameworks in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Internal Control Systems and Frameworks: frequently asked questions
What are the five components of the COSO internal control framework?
They are the control environment, risk assessment, control activities, information and communication, and monitoring. The control environment is the foundation. In an exam, use them as a checklist against the scenario.
What is the difference between internal control and internal audit?
Internal control is the system of policies and procedures that management and the board put in place. Internal audit is an independent function that tests and evaluates that system and reports on it. Internal audit forms part of the monitoring of controls.
What are the main limitations of internal control systems?
The main limits are human error, collusion, management override, cost constraints and the system becoming out of date. Because of these, the system gives reasonable assurance, not absolute assurance. Link each limit to the scenario in your answer.
What does the UK Corporate Governance Code expect of the board on internal control?
The board should maintain sound risk management and internal control systems and decide the nature and extent of risk it will accept. It should monitor and review their effectiveness at least annually and report on the review. The audit committee often supports this work.