Internal controls are the policies, procedures, system configurations, and oversight mechanisms that an enterprise maintains to achieve reliable financial reporting, protect assets from loss or misappropriation, ensure compliance with laws and regulations, and promote operational efficiency. They represent the formal framework through which the finance function manages the risk that financial information is incorrect, that transactions are unauthorised, or that assets are exposed to misuse.
The practitioner distinction: internal controls are categorised by their nature and timing. Preventive controls stop errors or fraud from occurring — access restrictions, approval requirements, system configuration locks. Detective controls identify errors or fraud that have already occurred — reconciliations, exception reports, internal audit reviews. A control environment that relies exclusively on detective controls accepts that errors will happen and discovers them after the fact. A balanced control environment is predominantly preventive, with detective controls as the verification layer.
In the Context of Egypt and the GCC
Internal control governance requirements in the GCC have strengthened significantly. The Saudi Central Bank (SAMA) governance framework for financial institutions mandates specific internal control structures, with board-level accountability for the adequacy of the control environment. ZATCA’s audit authority — with access to the full transactional record and the ability to assess penalties for control failures that enable tax understatement — has elevated internal control compliance from a finance best practice to a regulatory requirement for Saudi businesses. In Egypt, the Financial Regulatory Authority’s requirements for listed companies include internal control disclosures in the annual report, requiring finance teams to document and certify the control environment annually.
How This Connects to EPM and Systems
EPM implementations introduce new internal control considerations. Who can adjust the budget? Who can post a consolidation journal? Who can override an intercompany elimination? These are control questions as much as system configuration questions. Oracle EPM applications provide role-based access control at the form, dimension, and cell level — but the control is only as effective as the access design. An EPM where every finance user has write access to every planning form provides no separation between budget preparation and budget approval. The EPM system configuration must reflect the control framework, not circumvent it.
What Goes Wrong
The failure that makes internal controls a documentation exercise rather than a protection mechanism is the gap between designed controls and operating controls. An organisation’s internal control documentation describes a robust three-way match process for accounts payable, a mandatory dual-approval requirement for manual journal entries above a threshold, and a monthly balance sheet reconciliation sign-off. In practice: the three-way match has a 40% exception rate processed manually; the journal approval workflow has been bypassed for a specific user class for two years; and the reconciliation sign-off is a rubber stamp performed the day before the auditor visits. The controls exist on paper. They do not operate in practice. The gap between the two is the actual risk.
How Loop Wise Solutions Encounters This
Internal control assessment — comparing designed controls to operating controls — is a standard component of our finance function advisory work and a prerequisite for any finance automation engagement. We find the gap between designed and operating controls in every organisation we assess. Closing that gap requires both process change and system configuration change, and the two must be addressed simultaneously — a better process with the same permissive system configuration will not sustain the control improvement.