A control can exist in the policy manual, be signed off annually, and fail every single day in practice. This is the most common finding in internal risk work: not that controls are missing, but that the documented process and the real one stopped matching some time ago, and nobody was tasked with noticing.
The gap is easy to miss from inside. The policy is current, the approval matrix is on the intranet, and the people doing the work are competent and honest. What has happened is more mundane: the business grew, a workaround was invented to keep things moving, the workaround became normal, and the written control quietly stopped describing anything real.
This article covers the difference between a control that is well designed and one that actually operates, five ways controls fail without ever being removed, what a review examines, and the findings that come up most often. It follows on from The Decisions Nobody Questioned: Warning Signs of Weak Internal Governance, which deals with the culture around decisions rather than the mechanics.
Key Takeaways
- Design and operation are different questions. A control can be well written and never performed; both need testing separately.
- Controls fail without being removed. They are outgrown, unowned, bypassed by exception, unevidenced, or simply too late to matter.
- “It happens, we just don’t document it” is a finding. A control you cannot evidence is one you cannot rely on or demonstrate to anyone else.
- Segregation of duties is the single most common gap in owner-managed and fast-growing organisations.
- Findings must go somewhere independent. A report delivered only to the managers reviewed removes the point of the exercise.
What This Article Covers
- Design effectiveness vs operating effectiveness
- Five ways a control fails without being removed
- The six domains a review examines
- What reviews find most often
- What an internal risk review is not
- How a review runs in practice
- Frequently asked questions
Design Effectiveness vs Operating Effectiveness
Design effectiveness asks whether a control would prevent or detect the risk if it were performed exactly as written. Operating effectiveness asks whether it is actually performed that way, consistently, by someone, with evidence that it happened. These are separate tests, and most organisations only ever run the first one.
The distinction matters because a well-designed control that nobody performs offers no protection whatsoever — while providing considerable reassurance, which makes it worse than having no control at all. Leadership believes the risk is covered. The policy says it is covered. Nothing is covering it.
A control that cannot be evidenced is indistinguishable, to anyone outside the organisation, from a control that never ran.
Five Ways a Control Fails Without Being Removed
Controls are almost never deleted. They decay while remaining formally in place, which is why an inventory of policies tells you very little. Five failure modes account for the majority of what reviews uncover, and each requires a different fix.
1. Outgrown — designed for a smaller organisation
The approval process was written when the founder saw every invoice. At three hundred people and four locations, the same process either creates an unmanageable bottleneck or is quietly bypassed. Controls have a capacity, and exceeding it does not trigger an alert.
2. Unowned — no named person performs it
The policy describes what must happen but not who does it. Responsibility sits with a department rather than an individual, which in practice means it sits with nobody. This surfaces immediately when a reviewer asks who performed the check last month and receives a job title instead of a name.
3. Bypassed — the exception became the process
An urgent case justified going around the control. It worked, nothing went wrong, and the shortcut became the normal route for anything time-sensitive. Nobody decided to abandon the control; it simply stopped being the path of least resistance.
4. Unevidenced — performed but not recorded
The reconciliation happens, the review happens, the approval is given verbally. Everyone involved is confident it took place. There is nothing to demonstrate it, which means the organisation cannot rely on it in a dispute, an investigation, or a due diligence process it is subject to.
5. Mistimed — detective where prevention was needed
The control identifies the problem accurately, one quarter after the money left. Detective controls have real value, but placing one where a preventive control was required means the organisation is designed to discover losses rather than avoid them.
The Six Domains a Review Examines
Scope should follow the organisation’s actual risk profile rather than a standard template, but six domains appear in nearly every engagement because they are where value most commonly leaves a business without anyone deciding that it should.
- Delegation of authority and approvals — who can commit the organisation to what, whether limits are observed, and how exceptions are granted and counted.
- Payments and procurement — segregation of duties across requesting, approving, executing, and reconciling; supplier onboarding; and how bank details are changed.
- Related parties and conflicts — whether interests are declared before transactions, and whether related-party terms are comparable to arm’s length.
- System and data access — who holds administrative rights, whether access is removed when roles change, and who can alter records after approval.
- People and key-person risk — concentration of knowledge or relationships in single individuals, and what happens operationally when one of them leaves.
- Third parties and outsourced processes — agents, distributors, and outsourced functions operating with authority but outside internal oversight. Where the concern is who the third party actually is, that is Counterparty Risk Review rather than a controls question.
What Reviews Find Most Often
The recurring findings are remarkably consistent across industries and sizes. None of them involve wrongdoing. All of them create exposure that the organisation had not priced in, and most can be closed without significant cost once identified.
- One person can initiate, approve, and execute the same transaction. Usually a trusted long-serving employee, which is precisely why it was never questioned.
- Supplier bank details can be changed without independent verification. This is the single most exploited weakness in payment fraud, and the fix costs nothing.
- System access outlives the role. People who changed department two years ago retain rights to the systems they no longer need; leavers occasionally retain them entirely.
- Exceptions are approved by the person who requested them, or by someone junior to them, and no running total of exceptions exists.
- The policy was updated; the practice was not. A new procedure was issued, communicated once, and never adopted by the team that had to implement it.
- Related-party arrangements exist without documentation. Everyone knows; nothing is declared; the terms have never been benchmarked.
- An outsourced process has no oversight. A third party performs a function with real authority, and no one internally reviews how they perform it.
- Nothing can be evidenced. The controls may well be operating. There is no record capable of showing it to a buyer, a regulator, or an insurer.
What an Internal Risk Review Is Not
A review is frequently resisted because of what people assume it is. Being clear about the boundaries usually removes most of the objection, and materially improves the quality of what the review is told.
It is not a statutory audit. An audit examines financial statements against an accounting standard and issues an opinion. A review looks at operational and governance risk whether or not it touches the accounts, and produces findings and recommendations rather than an opinion.
It is not a compliance check. Compliance asks whether external rules are being met. A review asks whether the organisation’s own arrangements work — a question that remains live even where every external obligation is satisfied.
It is not an investigation into individuals. The subject is the process, not the person. Where a specific allegation exists, that is separate work with a different method, and conflating the two makes both harder to do well.
How a Review Runs in Practice
A proportionate review follows five stages. The critical one is the third: walking a real transaction end to end, rather than reading the procedure that describes how it should have gone.
- Set scope by risk, not by department. Identify where the organisation would lose most if a control failed, and start there rather than reviewing everything shallowly.
- Read the design. Collect the policies, approval matrices, and procedures as written, and assess whether they would work if followed exactly.
- Walk real transactions. Take actual cases from the past year and trace each one end to end — who requested, who approved, what evidence exists, and whether it matches the documented route. This is where the gaps appear.
- Interview the people who do the work. Not their managers. The person performing a task daily knows exactly where the workarounds are and will usually explain them if the framing is about process rather than blame.
- Report to someone independent, and rank by exposure. Findings go to the board, audit committee, or owner — not solely to the managers reviewed — ordered by what they could cost rather than by how easy they are to fix.
Our case study Internal Risk & Governance Review illustrates this sequence in a representative engagement. Where the underlying concern is the quality of the information reaching decisions rather than the controls around them, see Why Strategy Fails: When Good Decisions Are Built on Incomplete Information.
Frequently Asked Questions
An internal risk review is an independent examination of whether an organisation's controls and processes work in practice, not only on paper. It tests how approvals, payments, access rights, conflicts, and third-party arrangements actually operate day to day, and identifies where the documented process and the real one have diverged.
A statutory audit is a formal examination of financial statements against an accounting standard, resulting in an opinion. An internal risk review is broader and advisory: it looks at operational and governance risk regardless of whether it affects the accounts, and produces findings and recommendations for management rather than a formal opinion.
Typically six domains: delegation of authority and approvals, payments and procurement including segregation of duties, related parties and conflicts of interest, system and data access rights, key-person and people risk, and third-party or outsourced processes. Scope is set by the organisation's actual risk profile rather than a standard template.
Design effectiveness asks whether a control would prevent or detect the risk if it were performed as written. Operating effectiveness asks whether it is actually performed that way, consistently, and whether evidence exists to demonstrate it. A well-designed control that nobody performs provides no protection at all.
A focused review of one or two domains in a single business unit can usually be completed in two to three weeks. A broader review covering multiple domains across an organisation generally takes four to eight weeks, depending on the number of locations, the quality of existing documentation, and how readily records and people can be accessed.
Findings should go to a recipient who is independent of the areas reviewed, typically the board, an audit committee, or the owner. If the report is delivered only to the managers whose processes were examined, the review loses the independence that made it worth commissioning.
How Nexus Strategic Intelligence Conducts Internal Risk Reviews
Nexus Strategic Intelligence is an independent advisory firm based in Thailand. We test how controls operate rather than how they are documented, we speak to the people who perform the work, and we report to a recipient independent of the areas examined.
- Governance & Internal Risk Advisory — independent review of controls, authority, conflicts, and internal risk exposure.
- Counterparty Risk Review — verification of the suppliers, agents, and related parties that internal controls depend on.
- Executive Strategic Retainer — ongoing independent perspective for leadership between formal reviews.
- Pre-Investment Intelligence — applied where control weaknesses in a target are relevant to an investment decision.
Related reading: The Decisions Nobody Questioned: Warning Signs of Weak Internal Governance.
Not sure whether your controls still describe how the business actually runs? Request a confidential consultation and we will scope a review proportionate to where your real exposure sits.
About the Author
Sawit Tantisilapanon is CEO and Founder of Nexus Strategic Intelligence, an independent advisory firm based in Thailand. He works with owners, boards, and executives on internal risk, governance, and counterparty verification — with a focus on the distance between what an organisation documents and what it actually does.
Connect on LinkedIn or request a confidential consultation.
This article is provided for general information and does not constitute legal, financial, audit, or investment advice. Nexus Strategic Intelligence is not a law firm and does not provide statutory audit services. Specific decisions should be taken with appropriately qualified professional advisors.