Internal controls are the checks that keep one person from moving money, changing records, or approving their own work without a second set of eyes. For a US small business, a workable set of controls covers five risk areas — vendor payments, payroll, bank and cash, customer receipts, and system access — and assigns each one a named owner, an approval threshold, and written evidence that the check actually happened. The biggest limitation: with a two- or three-person finance team, full segregation of duties is impossible, so “compensating controls” such as owner bank review, dual bank authorization, and outside reconciliation have to carry the load. Controls reduce the chance and cost of fraud and error; they cannot guarantee prevention.
Quick answer
Start with the five money-movement risks below, assign each a control and an owner, set dollar thresholds for dual approval, and keep a simple evidence log proving each check ran. Where one person handles the whole books, compensate with direct owner access to bank statements, bank alerts, dual release on outgoing wires and ACH (Automated Clearing House) payments, and a monthly independent review. None of this requires new software — US accounting tools and banks already support user roles, approvals, and alerts. This article covers control design; for the monthly close routine those controls sit inside, see our guide to the small business month-end close workflow.
What are internal controls, and why do small businesses need them?
The most widely used US framework comes from the Committee of Sponsoring Organizations of the Treadway Commission (COSO), whose Internal Control — Integrated Framework was first issued in 1992 and refreshed in 2013, according to COSO’s internal control guidance (accessed July 28, 2026). COSO organizes internal control into five components — control environment, risk assessment, control activities, information and communication, and monitoring activities. In plain terms for a small business: decide who can do what, check the risky spots regularly, and keep proof that the checks happened.
A note on scope: internal controls are a management practice, not a federal tax or filing requirement for private companies. Section 404 of the Sarbanes-Oxley Act of 2002 (SOX) drives formal control assessments at US public companies — COSO publishes transition guidance for exactly that purpose — but no equivalent federal mandate applies to a small private business. Bookkeepers apply controls to keep the books reliable (whether kept on a cash basis, under US Generally Accepted Accounting Principles (GAAP), or on a tax basis), and the Internal Revenue Service (IRS) separately requires records adequate to support what is on the return, as its recordkeeping guidance for small businesses explains (accessed July 28, 2026). State rules can add retention requirements for payroll and sales tax records, so confirm your state’s periods too.
The reason to bother is measurable. The Association of Certified Fraud Examiners (ACFE) published Occupational Fraud 2026: A Report to the Nations on May 12, 2026, analyzing 2,402 real fraud cases across 143 countries with more than $3.4 billion in losses. Its key findings (accessed July 28, 2026) report a median loss of $104,000 per case, a median scheme duration of 12 months before detection, and this structural warning:
“More than half of all cases involved either a lack of internal controls or an override of existing controls.” — Association of Certified Fraud Examiners
Small organizations are not spared: the ACFE’s 2026 report press release states that smaller businesses experienced the highest median losses of any organization-size group in the study. The same source estimates overall impact at:
“CFEs estimate that 5% of revenue is lost to fraud each year.” — Association of Certified Fraud Examiners
That 5% figure is a global estimate, not a prediction for your company — but it explains why a $2 million-revenue business treats control design as a six-figure-risk question rather than paperwork. Detection matters as much as prevention: 43% of cases in the 2026 study were detected by tips, more than half from employees, and frauds caught within six months had a median loss of $40,000 versus more than $1.1 million for schemes running over five years, per the same findings.
Which money-movement risks should your controls cover first?
Design controls around the five places money or access moves. Copy the matrix below, assign the owner column to real names, and review it quarterly.
Table 1: Risk-control-owner matrix for a small US business (adapt the owner column to your org chart).
| Risk area | What goes wrong | Primary control | Control owner | Evidence it ran |
|---|---|---|---|---|
| Vendor payments | Fake vendor; bank details swapped by email | Verify any bank-detail change by phone using the number already on file; dual approval above threshold | Office manager | Call note dated in vendor file; signed approval |
| Payroll | Ghost employee; direct-deposit diversion | Second person reviews the payroll register before submission; deposit changes confirmed by a known phone number | Owner | Reviewed register initialed each run |
| Bank and cash | Unauthorized withdrawals; errors compounding | Monthly reconciliation by someone who does not initiate payments; bank alerts on every transaction | Bookkeeper | Reconciliation report tied to the bank statement |
| Customer receipts | Skimming; credits posted to hide theft | Match deposits to invoices weekly; route payments through ACH or a lockbox rather than cash | Bookkeeper | Deposit-to-invoice match log |
| System access | Ex-employee logins; shared admin passwords | Named user accounts, role-based permissions, multifactor authentication (MFA), access removed on departure, quarterly access review | Owner | Dated access-review checklist |
Interpretation: every row answers three questions — what could go wrong, who watches it, and what proof exists. If a row has no owner or no evidence, you have a policy, not a control.
Two rows deserve extra sourcing. First, vendor-payment verification: the Federal Bureau of Investigation’s Internet Crime Complaint Center (IC3) reports that business email compromise (BEC) — criminals impersonating executives or vendors to redirect legitimate payments — produced $55,499,915,582 in exposed losses worldwide from October 2013 through December 2023, per its September 2024 public service announcement (accessed July 28, 2026). Its first prevention tip:
“Use secondary channels and/or two-factor authentication to verify requests for changes in account information.” — FBI Internet Crime Complaint Center
Second, the access row: the Federal Trade Commission (FTC) draws the same line from its data-security enforcement cases in Start with Security: A Guide for Business (accessed July 28, 2026):
“Not everyone on your staff needs unrestricted access to your network and the information stored on it.” — Federal Trade Commission
The FTC recommends separate user accounts, access on a “need to know” basis, and limiting administrative rights to the people whose jobs require them. Modern accounting software makes this practical: Intuit’s QuickBooks Online user roles documentation (accessed July 28, 2026) describes, for example, separate bill clerk, bill approver, and bill payer roles — one user can enter a bill, another approves it, and a third releases payment — which is segregation of duties built into the tool. The same verify-the-channel habit appears in the US Small Business Administration Office of Inspector General’s scam and fraud guidance (accessed July 28, 2026): “SBA only communicates from email addresses ending in @sba.gov.”
How do you segregate duties in a two-person team?
A two-person office cannot split custody, recording, and authorization three ways. Compensating controls are the accepted answer: extra checks that substitute for the missing third person. The most practical set for a US small business:
Table 2: Compensating controls when one person runs the books.
| Gap | Compensating control | How it works in practice |
|---|---|---|
| Same person enters bills and pays them | Bank-side dual authorization | Set the business bank account so ACH and wire releases require a second user’s approval in the bank portal; the bookkeeper initiates, the owner releases |
| Same person records and reconciles | Owner reads the bank statement directly | Owner logs in to the bank monthly (not a forwarded PDF) and scans for unknown payees before the reconciliation is filed |
| Check fraud | Positive pay | Ask your bank about positive pay, a common US treasury service where the bank matches presented checks against your issued-check file and flags mismatches |
| No one watching the books | Monthly independent review | An outside bookkeeper or accountant reviews the reconciliation, journal entries, and vendor master changes monthly — a genuine second set of eyes |
| Changes happen silently | Audit-trail review | Review the accounting software’s activity/audit log monthly for deleted transactions, new vendors, and changed bank details |
| Everything flows through email | Out-of-band verification rule | Any emailed request to change payment or payroll details is confirmed by phone on a number already on file — never one supplied in the email itself |
Interpretation: none of these add headcount. The bank portal, alerts, and software audit log do the separating; the owner’s monthly thirty minutes does the verifying. One more habit from the same IC3 guidance: if you discover a fraudulent transfer, contact your bank immediately to request a recall and file a complaint at ic3.gov — speed determines recovery odds. And if you operate with a distributed or remote finance setup, our look at whether remote work is a long-term fit covers the operating-model side of that decision.
What approval thresholds make sense?
Thresholds decide which payments need two people. Set them from your own spending, not from a generic number. A defensible method: the dual-approval trigger at roughly 1% of average monthly outflows, and an owner-only-release trigger at roughly 5%. The following is a hypothetical illustration with made-up inputs — a fictional 14-person US marketing agency — showing the method, not a recommendation for your figures.
Inputs (all invented): payroll of $60,000 and vendor spending of $120,000 per month, so $180,000 in total monthly outflows; about 120 vendor payments per month; 18 of those payments exceed $1,800, totaling $86,400.
Table 3: Hypothetical approval thresholds for the fictional agency (made-up inputs).
| Control point | Method | Output |
|---|---|---|
| Dual-approval trigger | 1% × $180,000 monthly outflows | $1,800 |
| Owner-only-release trigger | 5% × $180,000 monthly outflows | $9,000 |
| Share of payments needing two approvers | 18 ÷ 120 payments | 15% |
| Share of non-payroll dollars covered | $86,400 ÷ $120,000 | 72% |
Interpretation: at these invented inputs, reviewing 15% of transactions covers 72% of the non-payroll dollars — the checks land where the money is without slowing every small purchase. Three rules hold regardless of your numbers. First, process changes get verified at any amount: a new vendor, a changed routing number, or a new payroll direct deposit is exactly what BEC targets, and those requests are usually small. Second, recompute thresholds when spending shifts — the 1% and 5% ratios are starting points, not standards. Third, write the thresholds down in the matrix from Table 1; an unwritten threshold is a suggestion.
How do you keep controls from fading?
Controls fail quietly when nobody checks that they ran. The fix is a one-page evidence log — the fourth artifact of this article — that pairs each control with its proof and a review date.
Table 4: Evidence log template (one row per control; review monthly, sign quarterly).
| Control | Frequency | Evidence retained | Reviewed by | Last reviewed |
|---|---|---|---|---|
| Bank reconciliation | Monthly | Reconciliation report plus bank statement | Owner | 07/15/2026 |
| Dual approval over threshold | Per payment | Approval record in bank portal or signed form | Office manager | Ongoing |
| Vendor bank-detail changes | Per change | Call-back note with date, name, number used | Owner | 07/08/2026 |
| Payroll register review | Each payroll | Initialed register | Owner | 07/24/2026 |
| User access review | Quarterly | Dated checklist of active users and roles | Owner | 06/30/2026 |
Keep the evidence with your accounting records. The IRS recordkeeping guidance cited above says to keep records as long as needed to prove the income or deductions on a return, and specifically:
“Keep all records of employment taxes for at least four years.” — Internal Revenue Service
Treat four years as the floor for payroll-control evidence and check your state’s rules for anything longer; the log also protects honest employees when a payment is questioned. The ACFE’s 2026 findings associate active controls such as management review, proactive data monitoring, and surprise audits with lower losses and faster detection, and organizations training both staff and management saw median losses of $84,000 versus $150,000 where neither was trained. This evidence log is also what an outside reviewer works from; it plugs directly into the broader accounting operations and reporting practices your finance function runs on.
FAQs
Are internal controls legally required for a small US business?
No. Formal internal-control assessment requirements such as SOX Section 404 apply to US public companies. For private small businesses, controls are voluntary risk management — though adequate records are required for tax purposes, and controls are how you produce them reliably.
What is the single most important control if I can only do one?
Independent bank review: the owner reads the bank statement and reconciliation monthly, directly from the bank, looking for unknown payees and unexpected transfers. It costs nothing, catches both fraud and error, and the ACFE links management review to lower losses.
How do controls work when my bookkeeper is remote or outsourced?
The same matrix applies, and distance can help: when your bookkeeper never touches the bank release side, custody and recording are already separated. Keep bank credentials with the owner, use view-only or role-limited access where possible, and keep the monthly owner review.
Will these controls guarantee fraud never happens?
No. Controls reduce opportunity and shorten detection time — the 2026 ACFE study still found frauds at organizations with controls, mainly through override. The goal is a smaller loss caught in months, not a promise of zero incidents.
The bottom line
Pick the five risk rows from Table 1, name an owner for each, set your 1% and 5% thresholds from real spending, and start the evidence log this week — then review the whole matrix quarterly. If you want an outside team to assess your finance controls and run the monthly independent review, our remote bookkeeping services do exactly that, and the Accounting Operations and Reporting hub collects the related guides.
This article provides general educational information, not accounting, tax, legal, or fraud-investigation advice. Control design depends on your facts, bank arrangements, software, and state rules; consult a qualified professional before relying on any control framework for your business.