Strategic Business Leader · Management and internal control systems
Systems of Control: Fraud, Compliance and Whistleblowing for ACCA SBL
Updated 11 October 2026 · Fact-checked
Systems of control reduce fraud, error and unethical behaviour by preventing them, detecting them and responding to them. Fraud controls cover segregation of duties, authorisation and monitoring. Compliance controls enforce laws and policies. Whistleblowing gives staff a safe route to report concerns. In SBL, tailor each control to the scenario.
Understand Systems of Control: Fraud, Compliance and Whistleblowing
A system of control is the set of policies, procedures and behaviours that helps an organisation reach its objectives and stay within the rules. Fraud, compliance and ethics are three of its main targets. Error is a fourth: it is unintentional, while fraud is deliberate deception for gain.
Fraud usually needs three things. These are an incentive or pressure, an opportunity and a way to rationalise the act. This is the fraud triangle. Controls mostly work on opportunity, because you cannot easily change a person's pressure or attitude. Culture and tone from the top work on rationalisation.
Controls fall into three groups. Preventive controls stop the problem, such as segregation of duties, authorisation limits, access rights and vetting new staff. Detective controls find it, such as reconciliations, exception reports, surprise checks and internal audit. Corrective controls fix it and stop it recurring, such as disciplinary action, recovery of losses and redesign of weak processes.
Compliance controls make sure the organisation follows laws, regulations and its own policies. Typical examples are a compliance officer, written policies, staff training, compliance monitoring and reporting of breaches to the board or audit committee. Penalties for non-compliance can include fines, loss of licences and reputational damage.
Whistleblowing means a person raises a concern about wrongdoing, usually internally first. Good arrangements include a confidential hotline, a named senior contact, often the audit committee chair or a non-executive director, protection against retaliation, and a clear process for investigating and feeding back. Staff only use these routes if they trust them. That depends on culture and on seeing that concerns are acted on. External reporting to a regulator is usually a last resort, when internal routes fail or the wrongdoing involves senior management.
Key rules to remember
- Fraud triangle
- Fraud = Incentive/pressure + Opportunity + Rationalisation
- Controls mainly reduce opportunity. Culture and ethics work on rationalisation.
- Control types
- Preventive → Detective → Corrective
- Name the type for each control you suggest. A good answer has a mix of all three.
- Core fraud controls
- Segregation of duties + Authorisation + Reconciliation + Access restriction + Monitoring
- Adapt each one to the specific process in the scenario.
- Whistleblowing channel checklist
- Confidential route + Senior independent recipient + Protection from retaliation + Investigation + Feedback
- Use as a checklist when assessing or designing a policy.
How to solve Systems of Control: Fraud, Compliance and Whistleblowing questions
Use this method for any SBL question on fraud, compliance or whistleblowing. Keep your answer tied to the scenario.
- 1Read the requirement and note the verb (identify, evaluate, recommend, advise). It decides how much analysis you need.
- 2Find the facts in the scenario: who has access, who authorises, who reviews, what pressure exists and what the culture is like.
- 3Diagnose the weakness. Link it to the fraud triangle or to a missing control type (prevent, detect, correct).
- 4Recommend specific controls for that weakness. Say what the control is, who operates it and how it closes the gap.
- 5Cover culture and reporting: tone from the top, codes of conduct, training, a whistleblowing route and board or audit committee oversight.
- 6Note costs and limits. Controls can be bypassed by collusion or management override, and over-control can slow the business.
- 7Close with a clear recommendation or priority and link it to the business, using a professional tone suited to the reader.
Quickest way: Weakness, control, owner
When to use it: Use when time is short and you must produce several relevant points quickly.
- List each weakness you spot in the scenario in a few words.
- Beside each, write one control that fixes it and label it preventive, detective or corrective.
- Name who operates it (finance director, internal audit, audit committee).
- Add one culture point and one whistleblowing point if the scenario shows ethical concerns.
- Write each as a short paragraph that quotes a scenario fact.
Common mistakes in Systems of Control: Fraud, Compliance and Whistleblowing
Listing generic controls without using the scenario.
Students revise lists and reproduce them from memory.
Fix: For every control, quote a fact from the scenario that shows why it is needed.
Treating fraud as only a finance-department problem.
Fraud is linked in the mind with cash and accounting.
Fix: Also consider procurement, IT access, expenses, inventory and senior management override, plus culture and incentives.
Only suggesting preventive controls.
Prevention feels like the obvious answer.
Fix: Add detective and corrective controls, since no preventive system is perfect.
Describing whistleblowing as just a hotline.
Students stop at the channel and ignore trust and follow-up.
Fix: Cover confidentiality, protection from retaliation, a senior independent recipient, investigation and feedback, and link it to culture.
Ignoring who the fraudster might be, such as senior management.
Students assume controls are applied to junior staff.
Fix: Show that management override is a risk and suggest oversight by non-executives, the audit committee and internal audit.
Missing the professional skills marks by writing a list with no conclusion.
Students rush to cover technical points.
Fix: Use the requested format, prioritise your recommendations and give a short reasoned conclusion.
Worked examples
Example 1
A retail company's purchasing manager selects suppliers, approves invoices and releases payments. Staff say concerns about him are ignored. Identify the weaknesses and recommend controls.
Show the solution
- Weakness 1: one person controls selection, approval and payment. This gives opportunity for fraud, for example fictitious suppliers or kickbacks.
- Control: segregate duties. Procurement chooses suppliers, a separate team approves invoices and finance releases payments. This is preventive.
- Control: independent authorisation above set limits, and three-way matching of order, goods received and invoice. Matching is preventive and detective.
- Control: periodic review of the supplier list and payment exceptions by internal audit. This is detective.
- Weakness 2: concerns are ignored, which signals a weak culture and no safe reporting route.
- Control: introduce a confidential whistleblowing channel to the audit committee chair, with protection from retaliation and documented investigation and feedback.
- Corrective: if fraud is found, investigate, discipline, recover losses and redesign the process.
- Limit: collusion can defeat segregation, so monitoring and culture still matter.
Answer: The main weaknesses are concentrated duties in purchasing and a culture that ignores concerns. Recommend segregation of duties, authorisation limits, three-way matching, internal audit review, a protected whistleblowing route to the audit committee and a corrective process for confirmed fraud.
Example 2
A finance director discovers that the CEO is encouraging sales staff to record revenue early to meet targets. Advise how whistleblowing arrangements and the director's own actions should work.
Show the solution
- Identify the issue: possible fraudulent financial reporting driven by pressure from targets and a CEO who sets the tone.
- Internal route first: the director should raise the concern with the audit committee chair or a non-executive director, because the CEO is implicated and cannot be the contact.
- The company's policy should give a confidential route that bypasses management, with protection from retaliation.
- The director should document facts and seek evidence without confronting or tipping off the CEO.
- As a professional accountant, the director must comply with the fundamental principles, especially integrity and objectivity, and should not take part in misstatement. Advice from the professional body may help.
- If the board fails to act, the director should consider external disclosure to a regulator, taking legal advice on the protection and duties that apply.
- Recommend longer-term fixes: review targets and bonus design, strengthen revenue cut-off controls and provide ethics training.
Answer: Raise the concern with the audit committee chair or a non-executive, not the CEO. Keep records, protect confidentiality, refuse to take part in misstatement and consider external reporting if internal routes fail. The company should also fix target pressure and revenue controls.
Exam tips
- Tie every control to a scenario fact. Generic lists earn little in SBL.
- Label controls as preventive, detective or corrective to show structure and range.
- Always address culture and tone from the top, not just procedures.
- When senior people are implicated, route concerns to the audit committee or non-executives and mention management override.
- Write in the format requested, such as a briefing note or email, and end with a clear recommendation.
Practice questions from Management and internal control systems
- Halvorsen Retail plc has an internal audit function that reports to the finance director. The non-executive directors worry that internal au…
- Zenith Retail plc's board notices that store managers can raise purchase orders, approve supplier invoices and authorise payments for their …
- Karimov Logistics has detailed written procedures, strong authorisation limits and reconciliations. However, the CEO frequently tells staff …
- Mirabel Foods Inc.'s internal auditors have just completed a review that found weak authorisation controls over supplier master data. The ch…
- Dalmore Retail's board is reviewing its approach to controls. Management proposes a compliance-based approach to preventing fraud, with deta…
Systems of Control: Fraud, Compliance and Whistleblowing in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Systems of Control: Fraud, Compliance and Whistleblowing: frequently asked questions
What is the difference between fraud and error?
Fraud is deliberate deception to gain an advantage. Error is unintentional. Controls help with both, but fraud needs extra focus on opportunity, culture and management override.
What makes a whistleblowing procedure effective?
Staff must trust it. It needs a confidential route, a senior independent recipient, protection from retaliation, a fair investigation and feedback. Management must also show that concerns lead to action.
Who should staff report to if the CEO is involved?
They should report to the audit committee chair or a non-executive director. Those people are independent of executive management and can oversee an investigation.
Do controls remove fraud completely?
No. Collusion, management override and poor culture can defeat controls. They also cost money and time, so the aim is to reduce risk to an acceptable level.