Strategic Business Leader · Managing, monitoring and mitigating risk
Monitoring Risk and Internal Control Systems in ACCA SBL
Updated 11 October 2026 · Fact-checked
Monitoring risk and internal control means checking, on an ongoing basis, that risks are still understood and that controls are designed well and working. Management, internal audit and the audit committee do this, and the board receives the results. In SBL, you identify weaknesses in the scenario, explain their risk, and recommend practical fixes.
Understand Monitoring Risk and Internal Control Systems
A risk is an uncertain event that can affect an organisation's objectives. An internal control system is the set of policies, procedures and behaviours that keeps risks within the level the board accepts. Controls do not remove risk. They reduce it to a tolerable level.
Risks and controls do not stay still. New products, new technology, staff changes, new laws and acquisitions can make yesterday's controls weak or irrelevant. So the board needs monitoring: ongoing checks that the risk picture is current and that controls still work. Without monitoring, the board only finds out about failure when a loss, fraud or scandal occurs.
Monitoring happens at several levels. Management monitors day to day through supervision, exception reports, reconciliations and KPIs. Internal audit gives independent assurance by testing controls and reporting findings. The audit committee, made up of non-executive directors, oversees internal audit, reviews the control system and reports to the full board. The board keeps overall responsibility for risk management and internal control. It cannot delegate that responsibility.
Frameworks give structure. The COSO internal control framework describes five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Monitoring includes ongoing evaluations built into processes and separate evaluations, such as internal audit reviews. Deficiencies must be reported to those able to act. In SBL you do not need to recite COSO in detail. You use it as a checklist to spot what is missing in a scenario.
A good SBL answer links the weakness to the risk and the risk to the business. For example, no one reviewing journals is a weakness, the risk is undetected fraud or error, and the effect is misstated results and lost trust. Then you recommend a control that fits the organisation's size and cost.
Key rules to remember
- COSO components
- Control environment + Risk assessment + Control activities + Information and communication + Monitoring activities
- Use as a checklist. Name only those relevant to the scenario.
- Weakness answer chain
- Weakness → Risk → Consequence → Recommendation
- Use this chain for each control point to earn application and analysis marks.
- Monitoring levels
- Management (ongoing) → Internal audit (independent) → Audit committee (oversight) → Board (responsibility)
- Shows who monitors and who reports to whom.
- Control types
- Preventive, detective, corrective (also directive)
- Preventive stops the problem, detective finds it, corrective fixes it.
How to solve Monitoring Risk and Internal Control Systems questions
Use this method for any question asking you to evaluate, monitor or improve controls or to explain the role of internal audit.
- 1Read the requirement and note the verb: evaluate, advise, recommend or explain. Note who the audience is, such as the board or audit committee.
- 2Scan the scenario and mark every control gap, such as missing segregation of duties, weak authorisation, no review or poor information.
- 3For each gap, state the risk it creates, such as fraud, error, non-compliance or reputational damage.
- 4Explain the consequence for this business, using its figures, sector and size from the scenario.
- 5Recommend a specific, practical control or monitoring step, and say who owns it. Consider cost and size of the business.
- 6Say how the issue should be reported, for example by internal audit to the audit committee and then the board.
- 7Finish with a short judgement on overall control quality, and write in the format asked, such as a report or memo, to earn professional skills marks.
Quickest way: Weakness, risk, fix in three lines
When to use it: When time is short and the question lists several control problems in a scenario.
- Underline each control gap in the scenario as you read it.
- Write one short block per gap: the weakness, the risk, then the fix.
- Add one line on monitoring: who checks the fix and who they report to.
- Close with a one-sentence overall view for the board.
Common mistakes in Monitoring Risk and Internal Control Systems
Listing COSO or control types from memory without applying them.
Students want to show they have learned the theory.
Fix: Use the framework only to find issues in the scenario. Every point must refer to the facts given.
Stating a weakness without explaining the risk or consequence.
Spotting the issue feels like enough.
Fix: Always complete the chain: weakness, risk, consequence, recommendation.
Recommending generic or costly controls that do not suit the business.
Students copy textbook lists of controls.
Fix: Tailor each recommendation to the size, sector and resources in the scenario, and mention cost where relevant.
Confusing internal audit with external audit.
Both use the word audit and both test records.
Fix: Internal audit serves management and the board and reviews controls and risk. External audit gives an opinion on the financial statements to shareholders.
Saying internal audit is responsible for the control system.
Students link controls with the people who test them.
Fix: The board is responsible, and management operates controls. Internal audit gives independent assurance and advice.
Ignoring reporting lines and independence.
Students focus only on the controls themselves.
Fix: Say that internal audit should report to the audit committee, not only to the finance director, to protect its independence.
Worked examples
Example 1
Karan Foods sells packaged snacks through 40 regional distributors. The finance director approves all distributor credit terms and also reviews the receivables ledger. Last year, three distributors owed large balances for over a year before anyone noticed. There is no internal audit function. Advise the board on the control weaknesses and how monitoring should be improved. (10 marks)
Show the solution
- Weakness 1: one person sets credit terms and reviews receivables. This is poor segregation of duties. The risk is that poor or biased credit decisions go unchallenged, and fraud or favouritism is possible.
- Consequence: the long overdue balances suggest bad debts, cash flow pressure and overstated assets in the accounts.
- Recommendation 1: separate credit approval from ledger review. For example, sales or credit control proposes terms and the finance director approves them, while someone else reviews the ledger.
- Weakness 2: there is no regular monitoring of aged balances. The risk is that late payment is not detected in time. This is a failure of detective control.
- Recommendation 2: produce monthly aged receivables reports with exception highlighting, and set credit limits that stop further sales when exceeded.
- Weakness 3: there is no internal audit. No independent party tests whether controls work, so management has no independent assurance.
- Recommendation 3: set up an internal audit function, or outsource it given the company's size, reporting to an audit committee of non-executive directors.
- Reporting: significant findings should go to the audit committee, which updates the board and tracks that actions are completed.
Answer: The main weaknesses are concentration of duties in the finance director, no ageing review of receivables and no independent assurance. Separate credit approval from review, introduce monthly exception-based ageing reports with credit limits, and create or outsource an internal audit function reporting to an audit committee, which reports to the board.
Example 2
Explain the role of internal audit in monitoring risk and internal control, and explain how its independence can be protected. (8 marks)
Show the solution
- Role in risk: internal audit assesses whether the risk management process works. It helps identify and evaluate risks and checks that the board's responses are being applied.
- Role in controls: it tests whether controls are well designed and operate effectively, and it reports weaknesses with recommendations.
- Other roles: it may carry out value for money, compliance, operational and fraud reviews, and follow up whether management has acted on earlier findings.
- Value to the board: it gives independent assurance, so the board does not rely only on management's own reports.
- Threat to independence: if internal audit reports only to management, or audits areas it designed or operates, it may be unwilling to criticise.
- Safeguard 1: it should report to the audit committee, which approves its plan, budget and the appointment or removal of its head.
- Safeguard 2: it should have access to all records and staff, and should not carry out operational duties in the areas it reviews.
- Outsourcing note: if outsourced, the provider should be different from the external auditor to avoid self-review issues.
Answer: Internal audit gives independent assurance on risk management and internal control by testing controls, reporting weaknesses and following up actions. Independence is protected by reporting to the audit committee, full access to information, and no operational responsibility for the areas reviewed.
Exam tips
- Always use the weakness, risk, consequence, recommendation chain. It earns both technical and application marks.
- Match the answer format to the requirement. A report to the audit committee needs headings, a clear tone and a conclusion, which supports professional skills marks.
- Use scenario facts such as numbers, locations and staff roles in each point. Generic answers score poorly.
- When asked about internal audit, cover both its role and its independence and reporting line. Examiners often reward the link to the audit committee.
- Weigh cost against benefit in your recommendations, especially for smaller organisations, and show commercial judgement.
Practice questions from Managing, monitoring and mitigating risk
- Calder Retail has a board risk committee, a chief risk officer (CRO) and an internal audit function. The CEO suggests the CRO should also si…
- Tessling Pharma's audit committee reviews its annual assessment of internal controls. The review finds that controls were well designed, but…
- Toller Retail, a UK-based chain, plans to enter a new country by acquiring a local competitor. Directors worry that the new country's custom…
- Hadley Pharma sells a product in a country where a new law may ban it. Management estimates a 10% chance of a ban, with a loss of $50 millio…
- Brightwell Logistics is designing its risk process in line with ISO 31000. The risk manager proposes that the process of identifying, analys…
Monitoring Risk and Internal Control Systems in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Monitoring Risk and Internal Control Systems: frequently asked questions
What is the difference between risk management and internal control?
Risk management is the wider process of identifying, assessing and responding to risks. Internal control is the set of procedures used to carry out many of those responses. Internal control sits inside the risk management system.
How do I evaluate internal controls in the SBL exam?
Find each control gap in the scenario, state the risk it creates and its impact on the business. Then recommend a practical fix that suits the organisation. Add who should monitor it and how it is reported to the board.
Is the COSO framework examined directly in SBL?
You are more likely to use it as a way to analyse a scenario than to be asked to list it. Know its five components: control environment, risk assessment, control activities, information and communication, and monitoring activities. Then apply them to the facts.
Who is responsible for internal control in a company?
The board holds overall responsibility. Management designs and operates the controls day to day. Internal audit and the audit committee provide independent review and oversight but do not take over that responsibility.