Skip to main content
Remote Financial Services
HomeAboutPricingToolsContact
+1 (818) 321-4972 Book a free consultation
Article

Internal Controls for Small Businesses: A Practical Owner Checklist

Design internal controls for a small US business: risk-control-owner matrix, two-person compensating controls, approval thresholds, evidence log.

Published Remote Financial Services
Internal Controls for Small Businesses: A Practical Owner Checklist

Internal controls are the checks that keep one person from moving money, changing records, or approving their own work without a second set of eyes. For a US small business, a workable set of controls covers five risk areas — vendor payments, payroll, bank and cash, customer receipts, and system access — and assigns each one a named owner, an approval threshold, and written evidence that the check actually happened. The biggest limitation: with a two- or three-person finance team, full segregation of duties is impossible, so “compensating controls” such as owner bank review, dual bank authorization, and outside reconciliation have to carry the load. Controls reduce the chance and cost of fraud and error; they cannot guarantee prevention.

Quick answer

Start with the five money-movement risks below, assign each a control and an owner, set dollar thresholds for dual approval, and keep a simple evidence log proving each check ran. Where one person handles the whole books, compensate with direct owner access to bank statements, bank alerts, dual release on outgoing wires and ACH (Automated Clearing House) payments, and a monthly independent review. None of this requires new software — US accounting tools and banks already support user roles, approvals, and alerts. This article covers control design; for the monthly close routine those controls sit inside, see our guide to the small business month-end close workflow.

What are internal controls, and why do small businesses need them?

The most widely used US framework comes from the Committee of Sponsoring Organizations of the Treadway Commission (COSO), whose Internal Control — Integrated Framework was first issued in 1992 and refreshed in 2013, according to COSO’s internal control guidance (accessed July 28, 2026). COSO organizes internal control into five components — control environment, risk assessment, control activities, information and communication, and monitoring activities. In plain terms for a small business: decide who can do what, check the risky spots regularly, and keep proof that the checks happened.

A note on scope: internal controls are a management practice, not a federal tax or filing requirement for private companies. Section 404 of the Sarbanes-Oxley Act of 2002 (SOX) drives formal control assessments at US public companies — COSO publishes transition guidance for exactly that purpose — but no equivalent federal mandate applies to a small private business. Bookkeepers apply controls to keep the books reliable (whether kept on a cash basis, under US Generally Accepted Accounting Principles (GAAP), or on a tax basis), and the Internal Revenue Service (IRS) separately requires records adequate to support what is on the return, as its recordkeeping guidance for small businesses explains (accessed July 28, 2026). State rules can add retention requirements for payroll and sales tax records, so confirm your state’s periods too.

The reason to bother is measurable. The Association of Certified Fraud Examiners (ACFE) published Occupational Fraud 2026: A Report to the Nations on May 12, 2026, analyzing 2,402 real fraud cases across 143 countries with more than $3.4 billion in losses. Its key findings (accessed July 28, 2026) report a median loss of $104,000 per case, a median scheme duration of 12 months before detection, and this structural warning:

“More than half of all cases involved either a lack of internal controls or an override of existing controls.” — Association of Certified Fraud Examiners

Small organizations are not spared: the ACFE’s 2026 report press release states that smaller businesses experienced the highest median losses of any organization-size group in the study. The same source estimates overall impact at:

“CFEs estimate that 5% of revenue is lost to fraud each year.” — Association of Certified Fraud Examiners

That 5% figure is a global estimate, not a prediction for your company — but it explains why a $2 million-revenue business treats control design as a six-figure-risk question rather than paperwork. Detection matters as much as prevention: 43% of cases in the 2026 study were detected by tips, more than half from employees, and frauds caught within six months had a median loss of $40,000 versus more than $1.1 million for schemes running over five years, per the same findings.

Which money-movement risks should your controls cover first?

Design controls around the five places money or access moves. Copy the matrix below, assign the owner column to real names, and review it quarterly.

Table 1: Risk-control-owner matrix for a small US business (adapt the owner column to your org chart).

Risk areaWhat goes wrongPrimary controlControl ownerEvidence it ran
Vendor paymentsFake vendor; bank details swapped by emailVerify any bank-detail change by phone using the number already on file; dual approval above thresholdOffice managerCall note dated in vendor file; signed approval
PayrollGhost employee; direct-deposit diversionSecond person reviews the payroll register before submission; deposit changes confirmed by a known phone numberOwnerReviewed register initialed each run
Bank and cashUnauthorized withdrawals; errors compoundingMonthly reconciliation by someone who does not initiate payments; bank alerts on every transactionBookkeeperReconciliation report tied to the bank statement
Customer receiptsSkimming; credits posted to hide theftMatch deposits to invoices weekly; route payments through ACH or a lockbox rather than cashBookkeeperDeposit-to-invoice match log
System accessEx-employee logins; shared admin passwordsNamed user accounts, role-based permissions, multifactor authentication (MFA), access removed on departure, quarterly access reviewOwnerDated access-review checklist

Interpretation: every row answers three questions — what could go wrong, who watches it, and what proof exists. If a row has no owner or no evidence, you have a policy, not a control.

Two rows deserve extra sourcing. First, vendor-payment verification: the Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) reports that business email compromise (BEC) — criminals impersonating executives or vendors to redirect legitimate payments — produced $55,499,915,582 in exposed losses worldwide from October 2013 through December 2023, per its September 2024 public service announcement (accessed July 28, 2026). Its first prevention tip:

“Use secondary channels and/or two-factor authentication to verify requests for changes in account information.” — FBI Internet Crime Complaint Center

Second, the access row: the Federal Trade Commission (FTC) draws the same line from its data-security enforcement cases in Start with Security: A Guide for Business (accessed July 28, 2026):

“Not everyone on your staff needs unrestricted access to your network and the information stored on it.” — Federal Trade Commission

The FTC recommends separate user accounts, access on a “need to know” basis, and limiting administrative rights to the people whose jobs require them. Modern accounting software makes this practical: Intuit’s QuickBooks Online user roles documentation (accessed July 28, 2026) describes, for example, separate bill clerk, bill approver, and bill payer roles — one user can enter a bill, another approves it, and a third releases payment — which is segregation of duties built into the tool. The same verify-the-channel habit appears in the US Small Business Administration Office of Inspector General’s scam and fraud guidance (accessed July 28, 2026): “SBA only communicates from email addresses ending in @sba.gov.”

How do you segregate duties in a two-person team?

A two-person office cannot split custody, recording, and authorization three ways. Compensating controls are the accepted answer: extra checks that substitute for the missing third person. The most practical set for a US small business:

Table 2: Compensating controls when one person runs the books.

GapCompensating controlHow it works in practice
Same person enters bills and pays themBank-side dual authorizationSet the business bank account so ACH and wire releases require a second user’s approval in the bank portal; the bookkeeper initiates, the owner releases
Same person records and reconcilesOwner reads the bank statement directlyOwner logs in to the bank monthly (not a forwarded PDF) and scans for unknown payees before the reconciliation is filed
Check fraudPositive payAsk your bank about positive pay, a common US treasury service where the bank matches presented checks against your issued-check file and flags mismatches
No one watching the booksMonthly independent reviewAn outside bookkeeper or accountant reviews the reconciliation, journal entries, and vendor master changes monthly — a genuine second set of eyes
Changes happen silentlyAudit-trail reviewReview the accounting software’s activity/audit log monthly for deleted transactions, new vendors, and changed bank details
Everything flows through emailOut-of-band verification ruleAny emailed request to change payment or payroll details is confirmed by phone on a number already on file — never one supplied in the email itself

Interpretation: none of these add headcount. The bank portal, alerts, and software audit log do the separating; the owner’s monthly thirty minutes does the verifying. One more habit from the same IC3 guidance: if you discover a fraudulent transfer, contact your bank immediately to request a recall and file a complaint at ic3.gov — speed determines recovery odds. And if you operate with a distributed or remote finance setup, our look at whether remote work is a long-term fit covers the operating-model side of that decision.

What approval thresholds make sense?

Thresholds decide which payments need two people. Set them from your own spending, not from a generic number. A defensible method: the dual-approval trigger at roughly 1% of average monthly outflows, and an owner-only-release trigger at roughly 5%. The following is a hypothetical illustration with made-up inputs — a fictional 14-person US marketing agency — showing the method, not a recommendation for your figures.

Inputs (all invented): payroll of $60,000 and vendor spending of $120,000 per month, so $180,000 in total monthly outflows; about 120 vendor payments per month; 18 of those payments exceed $1,800, totaling $86,400.

Table 3: Hypothetical approval thresholds for the fictional agency (made-up inputs).

Control pointMethodOutput
Dual-approval trigger1% × $180,000 monthly outflows$1,800
Owner-only-release trigger5% × $180,000 monthly outflows$9,000
Share of payments needing two approvers18 ÷ 120 payments15%
Share of non-payroll dollars covered$86,400 ÷ $120,00072%

Interpretation: at these invented inputs, reviewing 15% of transactions covers 72% of the non-payroll dollars — the checks land where the money is without slowing every small purchase. Three rules hold regardless of your numbers. First, process changes get verified at any amount: a new vendor, a changed routing number, or a new payroll direct deposit is exactly what BEC targets, and those requests are usually small. Second, recompute thresholds when spending shifts — the 1% and 5% ratios are starting points, not standards. Third, write the thresholds down in the matrix from Table 1; an unwritten threshold is a suggestion.

How do you keep controls from fading?

Controls fail quietly when nobody checks that they ran. The fix is a one-page evidence log — the fourth artifact of this article — that pairs each control with its proof and a review date.

Table 4: Evidence log template (one row per control; review monthly, sign quarterly).

ControlFrequencyEvidence retainedReviewed byLast reviewed
Bank reconciliationMonthlyReconciliation report plus bank statementOwner07/15/2026
Dual approval over thresholdPer paymentApproval record in bank portal or signed formOffice managerOngoing
Vendor bank-detail changesPer changeCall-back note with date, name, number usedOwner07/08/2026
Payroll register reviewEach payrollInitialed registerOwner07/24/2026
User access reviewQuarterlyDated checklist of active users and rolesOwner06/30/2026

Keep the evidence with your accounting records. The IRS recordkeeping guidance cited above says to keep records as long as needed to prove the income or deductions on a return, and specifically:

“Keep all records of employment taxes for at least four years.” — Internal Revenue Service

Treat four years as the floor for payroll-control evidence and check your state’s rules for anything longer; the log also protects honest employees when a payment is questioned. The ACFE’s 2026 findings associate active controls such as management review, proactive data monitoring, and surprise audits with lower losses and faster detection, and organizations training both staff and management saw median losses of $84,000 versus $150,000 where neither was trained. This evidence log is also what an outside reviewer works from; it plugs directly into the broader accounting operations and reporting practices your finance function runs on.

FAQs

Are internal controls legally required for a small US business?

No. Formal internal-control assessment requirements such as SOX Section 404 apply to US public companies. For private small businesses, controls are voluntary risk management — though adequate records are required for tax purposes, and controls are how you produce them reliably.

What is the single most important control if I can only do one?

Independent bank review: the owner reads the bank statement and reconciliation monthly, directly from the bank, looking for unknown payees and unexpected transfers. It costs nothing, catches both fraud and error, and the ACFE links management review to lower losses.

How do controls work when my bookkeeper is remote or outsourced?

The same matrix applies, and distance can help: when your bookkeeper never touches the bank release side, custody and recording are already separated. Keep bank credentials with the owner, use view-only or role-limited access where possible, and keep the monthly owner review.

Will these controls guarantee fraud never happens?

No. Controls reduce opportunity and shorten detection time — the 2026 ACFE study still found frauds at organizations with controls, mainly through override. The goal is a smaller loss caught in months, not a promise of zero incidents.

The bottom line

Pick the five risk rows from Table 1, name an owner for each, set your 1% and 5% thresholds from real spending, and start the evidence log this week — then review the whole matrix quarterly. If you want an outside team to assess your finance controls and run the monthly independent review, our remote bookkeeping services do exactly that, and the Accounting Operations and Reporting hub collects the related guides.

This article provides general educational information, not accounting, tax, legal, or fraud-investigation advice. Control design depends on your facts, bank arrangements, software, and state rules; consult a qualified professional before relying on any control framework for your business.

#internal controls #fraud prevention #segregation of duties #small business accounting #financial risk management