Skip to content

Strategic Business Leader · Management and internal control systems

Management Control Systems and Control Frameworks in SBL

Updated 11 October 2026 · Fact-checked

A management control system is the set of policies, procedures and information flows that help an organisation achieve its objectives. Controls work at strategic, tactical and operational levels. Frameworks such as COSO and the UK FRC guidance give a structure for designing and reviewing them. In SBL, apply them to the case.

Understand Management Control Systems and Control Frameworks

A management control system (MCS) is how an organisation steers itself towards its objectives. It sets targets, measures results, compares them with plan, and triggers action when they differ. Think of a thermostat: set a level, sense the temperature, correct the gap.

Control works at three levels. Strategic control looks at the long term and the whole organisation. It asks whether the strategy is still right, given the environment and performance against goals. Tactical (management) control looks at how resources are used to deliver the strategy, usually through budgets, departmental targets and variance reviews. Operational control looks at day-to-day tasks, such as checking that a process, transaction or job is done correctly and on time.

Controls can also be classed by timing and purpose. Preventive controls stop errors happening, for example authorisation limits. Detective controls find errors after the event, for example reconciliations. Corrective controls fix problems found. Controls may also be financial or non-financial, and formal (written rules, budgets) or informal (culture, trust, peer pressure).

A control framework gives boards a recognised structure for designing, operating and reviewing internal control. The COSO Internal Control – Integrated Framework defines internal control as a process, affected by the board, management and other staff, giving reasonable assurance about objectives in operations, reporting and compliance. It has five components: control environment, risk assessment, control activities, information and communication, and monitoring. It also sets out 17 principles supporting those components.

In the UK, the FRC Guidance on Risk Management, Internal Control and Related Financial and Business Reporting (which replaced the earlier Turnbull guidance) tells boards to set risk appetite, maintain sound risk management and internal control systems, and review their effectiveness at least annually. The board is responsible for the system. Management designs and runs it. Controls give reasonable, not absolute, assurance. In SBL, you must link a framework to the facts: what is weak in the case, which level of control is failing, and what the board should do.

Key rules to remember

COSO components
Control environment + Risk assessment + Control activities + Information and communication + Monitoring
Five components. Use them as a checklist to diagnose weaknesses in a case.
COSO objectives categories
Operations + Reporting + Compliance
Internal control supports all three, not just financial reporting.
Levels of control
Strategic (long term, whole organisation) → Tactical (resource use, budgets) → Operational (daily tasks)
Match each problem in the scenario to its level.
Control types by timing
Preventive, Detective, Corrective
Name the type when recommending a control.
Board duty under FRC guidance
Set risk appetite → Maintain systems → Review effectiveness at least annually
The board is responsible. Assurance is reasonable, not absolute.

How to solve Management Control Systems and Control Frameworks questions

Use this method for any question on control systems or frameworks. It keeps your answer tied to the scenario.

  1. 1Read the requirement and note the verb: assess, evaluate, recommend or explain. This sets the depth.
  2. 2Identify the objective the control should serve, and the level involved: strategic, tactical or operational.
  3. 3Pick the framework that fits. Use the five COSO components as a diagnostic list, or the board duties under the FRC guidance.
  4. 4Scan the scenario for facts that show a weakness or strength, and tie each one to a component or control type.
  5. 5Explain the consequence of each weakness for the organisation, such as fraud, misstatement or poor decisions.
  6. 6Recommend specific controls and name their type (preventive, detective, corrective). Say who should own them.
  7. 7Add the limits: cost versus benefit, reasonable assurance only, and management override.
  8. 8Finish with a clear conclusion or priority, written in the format asked for (report, memo or briefing note).

Quickest way: COSO checklist with scenario evidence

When to use it: Use when time is short and the question asks you to evaluate or improve controls in a case.

  1. Write the five COSO headings down the page as a plan.
  2. Under each, jot one fact from the scenario and one recommendation.
  3. Label each point with its control level and type.
  4. Write the answer with one short paragraph per heading, evidence first, then advice.
  5. Close with the biggest risk and the first action the board should take.

Common mistakes in Management Control Systems and Control Frameworks

  • Listing the COSO components from memory without applying them to the case.

    Students feel safe reciting what they learnt.

    Fix: Attach a fact from the scenario to every component you mention. Marks go to application.

  • Confusing strategic, tactical and operational control.

    All three involve monitoring and targets, so they blur together.

    Fix: Ask two questions: how long is the time horizon, and who acts? Board and long term means strategic. Budgets and managers means tactical. Daily tasks and staff means operational.

  • Saying internal controls guarantee that fraud and error will not happen.

    Students overstate what controls achieve.

    Fix: State that controls give reasonable assurance only. They can fail through collusion, override, human error or cost limits.

  • Treating internal control as only about financial reporting.

    Audit study encourages a narrow view.

    Fix: Cover operations and compliance as well. In SBL, controls also support strategy, safeguarding assets and efficiency.

  • Giving a generic list of controls with no priority.

    Students try to cover everything to collect marks.

    Fix: Rank the recommendations by risk. Explain why the first one matters most for this organisation.

  • Ignoring the board's responsibility for the system.

    Students focus on managers and internal audit.

    Fix: State that the board is responsible for the system and its review. Management implements it. Internal audit and the audit committee give assurance.

Worked examples

Example 1

A retail group has grown quickly through acquisitions. Each subsidiary uses its own reporting formats. Head office learns about losses only at year end. Staff in one subsidiary override stock counts to meet targets. Evaluate the weaknesses in the group's control system using the COSO components.

Show the solution
  1. Control environment: targets appear to push staff to override counts. This suggests weak tone from the top and poor integrity. Recommend a code of conduct and removal of pressure to manipulate results.
  2. Risk assessment: rapid acquisitions create new risks, yet no sign of a group-wide risk process. Recommend a regular group risk review that includes integration risks.
  3. Control activities: overriding stock counts shows weak preventive control. Recommend independent stock counts and authorisation for adjustments.
  4. Information and communication: different formats and year-end loss discovery mean information is late and inconsistent. Recommend standard monthly reporting to head office.
  5. Monitoring: nothing detects problems during the year. Recommend internal audit visits and monthly variance review at tactical level.
  6. Conclude that the control environment and monitoring are the priorities, because without integrity and timely review other controls will not work.

Answer: The group has weaknesses in all five COSO components. The priorities are the control environment (pressure and override) and monitoring (late detection). Standard monthly reporting, independent stock counts, a group risk review and internal audit visits would address them, with the board owning the system.

Example 2

A manufacturing company's board reviews only monthly profit. A production manager says machines are checked daily, but the board has not revisited whether the product range still fits the market. Explain which levels of control are working and which are missing, and recommend improvements.

Show the solution
  1. Operational control: daily machine checks show control of day-to-day tasks. This level appears to work.
  2. Tactical control: the board reviews monthly profit, which is a result measure. There is no mention of budgets by department or variance analysis, so tactical control is thin. Recommend departmental budgets and variance reviews.
  3. Strategic control: nobody has asked whether the product range fits the market. This level is missing. Recommend an annual strategic review using external analysis and performance against long-term goals.
  4. Explain the consequence: operations may run well while the company makes products that fewer customers want.
  5. Recommend that the board add non-financial strategic measures, such as market share and customer satisfaction, to its monthly pack.

Answer: Operational control works. Tactical control is weak because only a single profit figure is reviewed. Strategic control is missing. The board should add departmental variance reviews and a regular strategic review with long-term and non-financial measures.

Exam tips

  • Do not recite frameworks. Use COSO or the FRC guidance as a lens and quote scenario facts as evidence.
  • Name the level (strategic, tactical, operational) and the control type (preventive, detective, corrective) when you recommend something. It shows precision.
  • Remember the professional skills marks: structure the answer in the format requested, be concise and show scepticism about management's claims of good control.
  • Always mention limits of control, such as cost, override and collusion, in evaluation questions.
  • Link control weaknesses to wider topics where relevant, such as governance, ethics, risk appetite or fraud.

Practice questions from Management and internal control systems

Management Control Systems and Control Frameworks in other exams

The same ground in other exams, if you are preparing for more than one or want another angle on it.

Management Control Systems and Control Frameworks: frequently asked questions

What is a management control system in SBL?

It is the set of processes, measures and procedures that help management check that the organisation is moving towards its objectives and take action when it is not. In SBL you usually apply it to a case, so link controls to the strategy and risks of that business.

What are the five components of the COSO framework?

They are the control environment, risk assessment, control activities, information and communication, and monitoring. Use them as a checklist when you evaluate a scenario. COSO also has 17 principles that support these components.

What is the difference between strategic and operational control?

Strategic control looks at the long term and asks whether the organisation's direction and overall performance remain right. Operational control looks at everyday tasks and checks that they are done correctly. Tactical control sits between them and covers how resources are used, often through budgets.

Is the Turnbull guidance still examined?

The UK guidance that began as Turnbull is now the FRC Guidance on Risk Management, Internal Control and Related Financial and Business Reporting. Refer to the FRC guidance, and you can mention Turnbull as its origin. The key idea is that the board is responsible for maintaining and reviewing the system.