Skip to content

Strategic Business Leader · Management and internal control systems

Internal Control Systems and Their Components for ACCA SBL

Updated 11 October 2026 · Fact-checked

An internal control system is the set of policies and procedures that helps a business reach its objectives, protect assets, keep reliable records and comply with rules. Its components are the control environment, risk assessment, control activities, information and communication, and monitoring. In SBL, you identify weaknesses in the scenario and recommend fixes.

Understand Internal Control Systems and Their Components

An internal control system is everything management puts in place to make sure the organisation operates in an orderly way. It covers objectives, risk, assets, records and compliance. It is not only about stopping fraud. It also supports efficiency and good decisions.

A widely used framework (COSO) splits a system into five components. You should be able to name each one and apply it to a scenario.

  • Control environment: the tone and culture. It includes integrity and ethical values, board and audit committee oversight, management's attitude to control, organisational structure, authority and responsibility, and HR policies such as competence and training.
  • Risk assessment: how the organisation identifies the risks to its objectives, judges their likelihood and impact, and decides how to respond.
  • Control activities: the actual procedures. Examples are authorisation, segregation of duties, reconciliations, physical safeguards, access controls and performance reviews.
  • Information and communication: capturing relevant, reliable information and passing it to the right people, inside and outside the business, in time.
  • Monitoring: ongoing checks and separate evaluations, such as internal audit, to confirm controls still work and to report deficiencies.

Controls can also be classed by purpose. Preventive controls stop errors or fraud before they happen, for example passwords or authorisation limits. Detective controls find problems after they occur, for example bank reconciliations or exception reports. Corrective controls fix the problem once found, for example restoring data from backup. Other splits you may use are manual versus automated, and financial versus operational.

No system gives absolute assurance. Controls can fail through human error, collusion, management override, or because costs outweigh benefits. A good answer weighs the cost of a control against the risk it addresses.

Key rules to remember

Five components of internal control (COSO)
Control environment + Risk assessment + Control activities + Information and communication + Monitoring
Use these as headings to structure an answer on a control system. The control environment is the foundation for the rest.
Control types by timing
Preventive (before) | Detective (after) | Corrective (fix)
Preventive stops the event. Detective finds it. Corrective repairs the damage and stops recurrence.
Cost-benefit test for a control
Implement if expected risk reduction (benefit) > cost of the control
A rule of judgement, not a calculation. Always comment on cost and proportionality.
Weakness answer pattern
Weakness → Risk or consequence → Recommendation
Each point earns marks only if all three parts are present and linked to the scenario.

How to solve Internal Control Systems and Their Components questions

Use this method for any question asking you to describe, evaluate or improve an internal control system.

  1. 1Read the requirement and note the verb: describe, evaluate, identify weaknesses, or recommend. This sets the depth.
  2. 2Scan the scenario and highlight facts that signal a control issue, such as one person doing several jobs, no review, weak culture or rapid growth.
  3. 3Group the facts under the five components. This gives you a structure and stops you missing areas.
  4. 4For each weakness, state the problem using scenario facts, then explain the risk or consequence for this business.
  5. 5Give a specific, practical recommendation. Say whether it is preventive, detective or corrective where useful.
  6. 6Comment on cost, practicality and limits. A small firm may not afford full segregation of duties, so suggest compensating controls such as management review.
  7. 7Finish with a short conclusion that prioritises the most serious weakness. Write in the format asked, such as a report or memo, to earn professional skills marks.

Quickest way: Weakness, risk, fix in three lines

When to use it: When time is short and the scenario lists several control failures.

  1. Underline each control failure in the scenario as you read.
  2. Label each with a component: environment, risk assessment, activity, information or monitoring.
  3. Write three short lines per point: what is wrong, what could happen, what to do.
  4. Spend any spare time on prioritising and on cost or practicality comments.

Common mistakes in Internal Control Systems and Their Components

  • Listing the five components with textbook definitions and no link to the scenario.

    Students recall the framework and stop there, because it feels safe.

    Fix: Use the components only as a structure. Every point must quote or use a scenario fact.

  • Naming a weakness but giving no consequence or recommendation.

    Students rush and treat the requirement as a simple list.

    Fix: Always write weakness, risk, recommendation. Marks sit in the second and third parts.

  • Confusing preventive and detective controls.

    Both seem to reduce risk, and examples like reconciliations are mislabelled.

    Fix: Ask whether the control acts before or after the event. Authorisation prevents. Reconciliation detects.

  • Recommending expensive, ideal controls for a small business.

    Students copy large-company practice without checking size and cost.

    Fix: Suggest proportionate fixes and compensating controls, and mention cost versus benefit.

  • Treating internal control as only about fraud or only about finance.

    The topic is often taught through accounting examples.

    Fix: Remember it also covers operations, compliance and strategy. Include non-financial controls where the scenario allows.

  • Ignoring the control environment and culture.

    Procedures are easier to spot than attitudes.

    Fix: Look for tone at the top, ethics, pressure on staff, weak oversight and management override, and comment on them first.

Worked examples

Example 1

A fast-growing online retailer has one finance manager who raises purchase orders, approves supplier invoices, releases payments and reconciles the bank. Directors rarely review management accounts. Staff say targets are so tight that 'getting the numbers out matters more than getting them right'. Evaluate the weaknesses in the internal control system and recommend improvements.

Show the solution
  1. Control environment: the pressure on staff to hit targets over accuracy shows a weak tone at the top. This raises the risk of errors, misstatement and fraud. Recommend that directors set clear ethical expectations, balance targets with quality measures and encourage staff to report concerns.
  2. Control activities: one person controls the whole purchase-to-payment cycle. There is no segregation of duties. Risk: errors or fraudulent payments could be made and hidden, including through the bank reconciliation. Recommend splitting the duties between at least two people, with a second authoriser for payments above a set limit. This is preventive.
  3. Monitoring: directors rarely review management accounts, so problems may go unnoticed. Risk: late detection of losses or fraud. Recommend monthly review of accounts against budget with variances investigated. This is detective. Consider an internal audit review or an audit committee.
  4. Information: if numbers are produced under pressure, information reaching the board may be unreliable. Recommend defined reporting formats and independent checks on key figures.
  5. Cost and practicality: a growing business can afford extra staff or an outsourced reviewer, and the cost is small compared with the fraud and misstatement risk.
  6. Priority: the lack of segregation of duties combined with weak oversight is the most serious weakness, because it allows fraud to go undetected.

Answer: The most serious weaknesses are the absence of segregation of duties and weak director monitoring, made worse by a target-driven culture. Recommend splitting purchase-to-payment duties, introducing payment authorisation limits, regular director review of management accounts, and a change in tone that values accuracy and ethics.

Example 2

A manufacturer uses these controls: (a) password-protected access to the payroll system, (b) monthly reconciliation of inventory records to physical counts, (c) a backup restore after a server failure. Classify each as preventive, detective or corrective, and explain why.

Show the solution
  1. Control (a), password access: it stops unauthorised people from using or changing payroll before any misuse occurs. It is preventive.
  2. Control (b), monthly reconciliation of records to counts: it happens after transactions and discovers differences caused by error, loss or theft. It is detective.
  3. Control (c), backup restore: it repairs the damage after the failure has already happened and returns the data to use. It is corrective.
  4. Comment: a sound system uses all three together. Preventive controls reduce incidents, detective controls find those that get through, and corrective controls limit the harm.

Answer: (a) Preventive, because it blocks unauthorised access in advance. (b) Detective, because it identifies discrepancies after they occur. (c) Corrective, because it restores data after a failure.

Exam tips

  • Use the five components as your answer structure, but never leave a heading without scenario facts under it.
  • For every weakness, write the risk and a specific recommendation. Examiners reward the link between the three.
  • Always comment on cost and practicality, especially in small or fast-growing businesses, and mention compensating controls.
  • Put the control environment and tone at the top near the start. Scenarios often hide the root cause there.
  • Match your format to the requirement, such as a report to the board, and prioritise your points to earn professional skills marks.

Practice questions from Management and internal control systems

Internal Control Systems and Their Components in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Internal Control Systems and Their Components: frequently asked questions

What are the components of an internal control system for ACCA SBL?

Using the COSO framework, they are the control environment, risk assessment, control activities, information and communication, and monitoring. In the exam, use them to organise your answer and tie each one to scenario facts.

What is the difference between preventive and detective controls?

Preventive controls stop an error or fraud before it happens, such as authorisation limits or passwords. Detective controls find problems after they have occurred, such as reconciliations or exception reports. Corrective controls then fix the problem.

How do I evaluate internal control weaknesses in the exam?

Find the control failures in the scenario, group them by component, and explain the risk each creates. Then give a practical recommendation and comment on cost. Finish by prioritising the most serious weakness.

Why is the control environment so important?

It sets the attitude to control across the whole organisation. If management shows weak ethics or ignores controls, procedures are likely to be bypassed. That makes the control environment the foundation of the other components.