Skip to main content
All articles

Fraud Risk

Internal Controls to Reduce Fraud Risk in a Small Business

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

Internal Controls to Reduce Fraud Risk in a Small Business: original RiskSensai editorial cover

Follow the money and the authority

A small business does not need to begin with a large control manual. Start by identifying where a person could redirect money, create a false record or conceal a transaction. Then ask what would prevent the action and what would reveal it if prevention failed.

High-consequence paths often include supplier bank changes, payment approval, payroll changes, refunds, inventory adjustments and administrator access. The actual priorities depend on your business. A cash retailer and a software company should not receive identical control lists merely because both are small.

The GAO's 2025 Green Book emphasizes risk assessment, preventive controls and management responsibility.1 It sets federal-agency standards; the examples here use its general control-design ideas as a reference, not as a private-business mandate.

Distinguish prevention, detection and correction

A preventive control operates before an unauthorized transaction occurs. A detective control identifies a suspicious or incorrect result. Corrective work addresses the issue and its underlying cause. A useful process often combines them.

For example, requiring independent approval for a supplier bank change can help prevent a redirected payment. Reviewing the change report can identify unauthorized changes. Investigating an exception and restoring correct access is corrective work. A monthly bank reconciliation alone may discover a problem only after money has left.

Define the control precisely: who performs it, what population it covers, when it operates, which criteria are checked and what evidence remains. “Management reviews payments” is an intention. “The owner compares the payment batch to approved invoices and supplier-change confirmations before release” is a procedure.

Original priority-control inventory

The following examples are starting proposals. Adjust them to actual roles, systems, transaction volume and legal requirements.

Risk pathPreventive ideaDetective ideaEvidence to retain
Supplier bank changeIndependent verification through an established contactReview all bank-detail changesConfirmation, approver and change log
Duplicate or fictitious invoiceMatch invoice to authorized purchase and receiptReview duplicates and unusual suppliersPurchase, receipt and exception resolution
Unauthorized payroll changeSeparate change preparation and approvalCompare payroll changes and totalsApproved changes and review notes
Inappropriate refundRequire authorization outside the requester where feasibleReview unusual refund patternsTransaction and approval record
Inventory adjustmentRestrict adjustment rights and require reasonsReconcile counts and investigate differencesCount results and approved adjustments
Administrator misuseLimit privilege and approve changesReview relevant administrator activityAccess decision and review evidence

Do not gather more sensitive information than the review requires. Store payroll and account-detail evidence with appropriate restrictions rather than attaching it to a general task list.

Worked example: the supplier email change

Fictional scenario: An office manager receives an email that appears to come from a long-standing supplier. It requests new bank details and says a payment is urgent.

The manager records the request but does not use its new phone number as the verification channel. The designated approver contacts the supplier through a previously verified route, compares the change with the supplier record and documents the result before payment preparation.

If verification fails, the change remains blocked and the issue is escalated. If it succeeds, a separate authorized person releases the payment where staffing allows. A reviewer later checks the complete bank-change report against approved changes, including changes that did not immediately produce a payment.

FTC small-business scam guidance identifies impersonation and urgency as warning signs and recommends clear invoice and payment checks.2 The fictional workflow applies that principle without assuming every unusual request is fraud or promising that one callback defeats every attack.

Make approvals substantive

An approval should reflect a check, not simply a second login. Give the approver access to the underlying information, enough time to review it and authority to reject the transaction. Specify what needs escalation, such as an unusual supplier, changed payee or missing receipt.

Record the reasons for exceptions. If the owner must approve their own reimbursement because no alternative reviewer exists, document that conflict and an appropriate additional review. Do not label the procedure independent when the same person controls preparation, approval and reconciliation.

Avoid predictable loopholes. Splitting one purchase into smaller transactions can evade an amount threshold. Examine connected payments, unusual timing and repeat exceptions where relevant. These are proposed review considerations, not evidence that a fraud-detection system is operating.

Handle small-team limitations honestly

Sometimes full segregation of duties is impractical. Additional review can address the specific missing separation, but it should not become a blanket excuse for unchecked authority. University of Florida's institutional guidance treats compensating controls as a fallback when ideal separation is unavailable.3

A small company might give its owner direct access to bank statements and require a documented reconciliation review, while an external bookkeeper checks selected high-risk changes. The business must decide whether that arrangement is suitable; the example does not promise equivalent protection or prescribe an engagement.

Name the residual limitation. If one administrator can change records and logs, reviewing their own report may not meaningfully challenge their activity. Consider how the reviewer obtains evidence from a source the operator cannot silently alter.

Check whether controls actually operate

Select a recent, defined period and inspect a bounded set of transactions. Include ordinary transactions and the exceptions most likely to challenge the control. Ask whether approvals preceded payment, whether verification used the correct contact and whether discrepancies were resolved.

Keep the population, selection method and limitations with the result. A sample of five invoices does not establish that every invoice was appropriate. A signed policy establishes the instruction, not performance throughout the period.

When a control fails, describe the condition and business exposure before blaming a person. “Three bank changes had no documented verification” is a useful observation. “The finance team is dishonest” is an unsupported conclusion and can create serious harm.

Protect the reporting route

Provide employees a monitored route for concerns and a clear alternative if the concern involves their manager. Explain how reports are handled and protect information appropriately. Do not invite staff to conduct their own surveillance or access records outside their authorization.

For suspected misconduct, preserve relevant information and obtain appropriate legal and investigative expertise. Routine control monitoring is different from establishing wrongdoing. Avoid accusations based on an unexplained exception alone.

An achievable first-month plan

In the first week, map the highest-consequence transaction paths and actual access. In the second, agree on two or three preventive checks and the necessary review evidence. In the third, run the procedures on normal work and resolve usability problems. In the fourth, inspect a sample and revise the design based on findings.

Assign ownership for ongoing review and material changes. A new payroll supplier, bank platform or departing employee can change the control environment. The segregation-of-duties examples provide a more detailed way to map conflicts.

Questions business owners ask

Does trust make controls unnecessary?

No. Clear controls protect trusted employees as well as the organization by making expectations, approvals and evidence visible.

Should every payment need two people?

Design the process for risk, practicality and applicable requirements. The key is a reviewed rationale and safeguards that actually operate—not a universal rule copied without context.

Can software guarantee fraud prevention?

No. Access controls and records can support a process, but people must design and operate it. The readiness assessment offers a general planning starting point; it is not a fraud investigation or verification of control effectiveness.

Sources and references

  1. U.S. Government Accountability Office. Standards for Internal Control in the Federal Government: 2025 Green Book (2025-05-15). Federal-agency framework, effective FY2026; voluntary reference here for private-business control design. ↩

  2. Federal Trade Commission. Scams and Your Small Business: A Guide for Business. Business-scam guidance supports invoice verification and staff awareness. ↩

  3. University of Florida CFO Division. Compensating Controls. Institutional control guidance illustrating alternatives when staff limitations prevent ideal separation. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • Internal Controls
  • Payment Controls
  • Small Business
Connecting to your conversation workspace…