Internal financial controls.

 

Internal Financial Controls

1. Introduction

Internal financial controls (IFC) are the policies, procedures, systems and checks established by an organisation to ensure that its financial activities are properly authorised, accurately recorded, protected from misuse, and carried out in accordance with applicable law.

In the Indian corporate context, internal financial controls are particularly important under the Companies Act, 2013. Section 134(5)(e) defines internal financial controls with reference to the company and explains their objectives, including orderly and efficient conduct of business, adherence to company policies, safeguarding assets, prevention and detection of fraud and errors, accuracy and completeness of accounting records, and timely preparation of reliable financial information.

2. Meaning of Internal Financial Controls

Internal financial controls are not limited to accounting entries.

They cover the entire financial control environment, including:

  • authorisation of expenditure;
  • approval of payments;
  • segregation of duties;
  • accounting and record-keeping;
  • bank reconciliation;
  • protection of company assets;
  • prevention of unauthorised transactions;
  • inventory controls;
  • payroll controls;
  • procurement controls;
  • financial reporting;
  • fraud prevention and detection;
  • access controls over financial systems.

The objective is to reduce the possibility of financial error, fraud, misuse or inaccurate reporting.

3. Statutory Framework in India

Section 134(5)(e), Companies Act, 2013

The directors' responsibility statement is required to state, among other matters, that the directors have laid down internal financial controls to be followed by the company and that such controls are adequate and operating effectively.

The provision connects internal financial controls with:

  1. orderly and efficient conduct of business;
  2. adherence to company policies;
  3. safeguarding assets;
  4. prevention and detection of frauds and errors;
  5. accuracy and completeness of accounting records; and
  6. timely preparation of reliable financial information.

Section 143(3)(i)

The statutory auditor is required to report whether the company has adequate internal financial controls with reference to financial statements and whether such controls were operating effectively.

This makes IFC an important component of statutory audit and corporate financial reporting.

4. Main Components of Internal Financial Controls

A. Segregation of Duties

Different employees should ideally be responsible for different stages of a financial transaction.

For example:

  • one employee creates a purchase order;
  • another approves it;
  • another receives the goods;
  • another processes the invoice;
  • another authorises payment.

This reduces the possibility that one person can initiate and conceal an unauthorised transaction.

B. Authorisation Controls

Financial transactions should require appropriate approval.

Examples include:

  • expenditure approval limits;
  • purchase approvals;
  • payment authorisations;
  • loan approvals;
  • investment approvals;
  • write-off approvals.

The authority should correspond to the employee's designated financial powers.

C. Accounting Controls

Accounting records should be:

  • complete;
  • accurate;
  • supported by documents;
  • recorded in the appropriate period;
  • properly reconciled.

Controls should also exist over journal entries and adjustments.

D. Bank Reconciliation

Regular bank reconciliation helps identify:

  • unauthorised payments;
  • duplicate transactions;
  • recording errors;
  • outstanding cheques;
  • unexplained differences;
  • fraudulent transactions.

Large or unexplained differences should be investigated promptly.

E. Asset Safeguarding

Companies should maintain controls over:

  • cash;
  • inventory;
  • fixed assets;
  • intellectual property;
  • financial instruments;
  • company-owned equipment.

Physical verification and asset registers can help detect loss or misuse.

5. Internal Controls and Fraud Prevention

Internal financial controls play an important role in preventing and detecting fraud.

However, internal controls cannot guarantee that fraud will never occur.

Fraud may involve:

  • collusion between employees;
  • management override;
  • falsification of documents;
  • manipulation of accounting records;
  • unauthorised payments;
  • vendor-related fraud;
  • payroll fraud.

Therefore, organisations should combine preventive controls with detective controls and periodic independent review.

6. Internal Financial Controls and Management Responsibility

Management is responsible for designing and maintaining an appropriate control environment.

This includes:

  • establishing financial policies;
  • setting approval limits;
  • maintaining accounting systems;
  • implementing access controls;
  • monitoring compliance;
  • responding to control deficiencies;
  • correcting identified weaknesses.

The board and audit committee also have important oversight responsibilities, particularly in larger companies.

7. Internal Financial Controls and Statutory Audit

The statutory auditor does not merely examine whether financial statements exist.

Where applicable, the auditor evaluates whether internal financial controls over financial reporting are:

adequately designed and
operating effectively.

A deficiency may arise where:

  • a control is absent;
  • a control is poorly designed;
  • a properly designed control is not implemented;
  • a control fails to operate consistently.

The seriousness of a deficiency depends upon its potential effect and likelihood of resulting in a material misstatement or other financial consequence.

8. Important Case Laws

1. Sunil Mehta v. State of Gujarat (2013)

The Supreme Court considered issues relating to corporate financial transactions and the liability of persons associated with corporate affairs.

Principle: Corporate financial responsibility must be examined with reference to the person's actual role and statutory responsibility rather than merely because the person holds a corporate position.

Relevance to IFC: Proper allocation of financial responsibilities and documentation of decision-making helps establish who was responsible for particular financial controls.

2. Official Liquidator v. P.A. Tendolkar (1973)

The Supreme Court examined the responsibility of directors in relation to the affairs of a company.

The Court recognised that directors cannot simply rely upon their formal position without paying appropriate attention to the company's affairs and responsibilities.

Principle: Directors have responsibilities concerning supervision of corporate affairs.

IFC relevance: Effective internal financial controls require appropriate oversight by those responsible for corporate management.

3. N. Narayanan v. Adjudicating Officer, SEBI (2013)

The Supreme Court dealt with corporate governance, disclosure requirements and the responsibilities of directors.

The Court emphasised the importance of transparency, proper disclosures and responsible corporate administration.

Principle: Corporate governance requires responsible supervision and accurate financial and corporate disclosures.

IFC relevance: Internal financial controls support reliable financial reporting and corporate transparency.

4. Sahara India Real Estate Corporation Ltd. v. SEBI (2012)

The Supreme Court considered extensive issues concerning corporate disclosures, investor protection and compliance with securities regulations.

The judgment demonstrates the importance of maintaining accurate corporate records and complying with regulatory requirements.

IFC relevance: Strong financial and record-keeping controls are essential for companies dealing with investors and regulated financial transactions.

5. T. Nagappa v. Y.R. Muralidhar (2008)

The Supreme Court considered principles concerning corporate and financial documentation in the context of legal proceedings.

Principle: Documentary records can have significant evidentiary importance in establishing financial transactions and responsibilities.

IFC relevance: Properly maintained financial documentation and audit trails can assist in demonstrating that transactions were properly authorised and recorded.

6. Iridium India Telecom Ltd. v. Motorola Incorporated (2011)

The Supreme Court examined corporate criminal liability and the circumstances in which a company may be held responsible for criminal conduct.

The decision is relevant to the broader principle that a company can act through its officers and employees.

IFC relevance: Companies should establish effective systems capable of preventing and detecting unlawful financial conduct by individuals acting within the corporate structure.

7. Standard Chartered Bank v. Directorate of Enforcement (2005)

The Supreme Court considered the criminal liability of corporations and recognised that a company can be prosecuted for offences, subject to the governing law.

Principle: Corporate status does not by itself immunise a company from legal consequences arising from unlawful conduct.

IFC relevance: Effective financial controls help companies reduce the risk of regulatory and legal violations.

9. Internal Financial Controls and Documentation

Documentation is one of the most important aspects of IFC.

A company should maintain evidence of:

  • who initiated a transaction;
  • who approved it;
  • when approval was given;
  • supporting invoices/documents;
  • payment details;
  • accounting entries;
  • reconciliation;
  • subsequent review.

An effective audit trail allows an organisation and its auditors to reconstruct a transaction from beginning to end.

10. Internal Controls in Procurement

A strong procurement system may include:

Purchase requisition → approval → vendor selection → purchase order → goods receipt → invoice verification → payment approval → payment → accounting entry

The use of a three-way match between purchase order, goods receipt and invoice is a common control mechanism.

11. Internal Controls in Payroll

Payroll controls may include:

  • employee master-data approval;
  • attendance verification;
  • salary calculation review;
  • approval of increments;
  • approval of new employees;
  • controls over bank-account changes;
  • segregation between payroll preparation and payment approval;
  • periodic reconciliation of payroll with HR records.

These controls reduce the risk of fictitious employees, duplicate payments and unauthorised salary changes.

12. Technology and Internal Financial Controls

Modern financial controls increasingly depend on information technology.

Important controls include:

  • password protection;
  • role-based access;
  • multi-factor authentication;
  • approval workflows;
  • access logs;
  • segregation of system permissions;
  • backup procedures;
  • change-management controls;
  • monitoring of unusual transactions.

For example, an employee who can create a vendor should not automatically have unrestricted authority to create and approve payments to that vendor.

13. Internal Financial Controls and Internal Audit

Internal audit provides an independent or objective review of the effectiveness of internal controls.

An internal audit may examine:

  • financial transactions;
  • procurement;
  • payroll;
  • inventory;
  • bank accounts;
  • tax compliance;
  • expense claims;
  • vendor management;
  • system access;
  • fraud risks.

Internal audit findings should be documented and followed by corrective action.

14. Control Deficiencies

A control deficiency may occur where:

Design Deficiency

The control itself is inadequately designed.

Example: No approval is required for large-value payments.

Operating Deficiency

The control exists but is not consistently followed.

Example: A company requires two signatures for payments, but employees regularly bypass the second approval.

Documentation Deficiency

The control may have been performed, but there is insufficient evidence to demonstrate that it was performed.

15. Practical IFC Framework

A company can establish an effective internal financial control system through the following steps:

Step 1 — Identify Financial Risks

Identify areas vulnerable to error, fraud or misuse.

Step 2 — Map Financial Processes

Document the flow of money and financial information.

Step 3 — Assign Responsibility

Clearly identify who initiates, approves, records and reviews transactions.

Step 4 — Establish Approval Limits

Set financial authority levels.

Step 5 — Segregate Duties

Avoid concentrating incompatible financial functions with one individual.

Step 6 — Maintain Documentation

Preserve invoices, approvals, reconciliations and supporting records.

Step 7 — Monitor Controls

Conduct periodic reviews and internal audits.

Step 8 — Correct Deficiencies

Record deficiencies and implement corrective measures.

Step 9 — Review Technology Controls

Periodically review system access and financial software permissions.

Step 10 — Report Material Issues

Significant control deficiencies should be appropriately escalated to management, the audit committee and the board, as applicable.

16. Importance in Corporate Governance

Internal financial controls contribute to:

  • reliable financial statements;
  • prevention and detection of fraud;
  • protection of corporate assets;
  • regulatory compliance;
  • accountability;
  • transparency;
  • effective corporate governance;
  • investor confidence.

They also create an institutional framework in which financial decisions can be reviewed independently rather than relying solely on individual employees.

17. Conclusion

Internal financial controls form an important part of corporate governance, financial reporting and fraud-risk management. Under the Companies Act, 2013, directors and statutory auditors have specific responsibilities concerning internal financial controls over financial reporting.

An effective IFC framework should combine segregation of duties, authorisation, documentation, reconciliation, asset protection, information-technology controls, monitoring and independent review. The objective is not merely to detect wrongdoing after it occurs but to establish systems that reduce the likelihood of errors, fraud and unauthorised financial activity.

The principles emerging from cases such as Official Liquidator v. P.A. Tendolkar, N. Narayanan v. Adjudicating Officer, SEBI, Sahara India Real Estate Corporation Ltd. v. SEBI, Iridium India Telecom Ltd. v. Motorola Incorporated, Standard Chartered Bank v. Directorate of Enforcement and related corporate-governance decisions reinforce the importance of responsible corporate supervision, accurate records, transparency and accountability.

LEAVE A COMMENT