{"id":3406,"date":"2024-10-23T21:56:00","date_gmt":"2024-10-23T14:56:00","guid":{"rendered":"https:\/\/audithink.com\/?p=3406"},"modified":"2026-06-22T22:39:27","modified_gmt":"2026-06-22T15:39:27","slug":"internal-control","status":"publish","type":"post","link":"https:\/\/audithink.com\/en\/blog\/pengendalian-internal\/","title":{"rendered":"Internal Control: Definition, Purpose, Types, &amp; COSO Components"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Every company faces the risk of recording errors, misuse of assets, non-compliance, data breaches, and even fraud. These risks can arise from procedural weaknesses, unclear division of responsibilities, or lack of oversight of operational activities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To minimize these risks, companies need internal controls that are designed and implemented consistently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Internal control is a process implemented by the board of commissioners, management, and all organizational personnel to provide reasonable assurance that operational, reporting, and compliance objectives can be achieved.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control extends beyond auditing financial statements. This system encompasses policies, procedures, delegation of authority, transaction approvals, asset security, technology access controls, and follow-up monitoring.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Internal Control Summary<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some important things to understand about internal control are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Internal control is a process that involves all parts of the organization.<\/li>\n\n\n\n<li>The objectives include operational effectiveness, reporting reliability, and compliance.<\/li>\n\n\n\n<li>The COSO framework divides internal control into five main components.<\/li>\n\n\n\n<li>Control can be preventive, detective, or corrective.<\/li>\n\n\n\n<li>Management is the owner and the main person responsible for control.<\/li>\n\n\n\n<li>Internal audit is tasked with independently evaluating the effectiveness of controls.<\/li>\n\n\n\n<li>Internal controls provide reasonable assurance, not absolute assurance, that all risks will disappear.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">What is Internal Control?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control is a set of processes, policies, procedures, and activities designed to help an organization achieve its objectives while managing risks that could hinder that achievement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Based on <strong><a href=\"https:\/\/audithink.com\/en\/article\/coso-framework\/\" data-type=\"post\" data-id=\"3979\">COSO framework or <em>Committee of Sponsoring Organizations of the Treadway Commission<\/em><\/a><\/strong>Internal control is influenced by the board of directors, management, and other personnel. This process is designed to provide reasonable assurance regarding the achievement of the organization's objectives in the areas of operations, reporting, and compliance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thus, internal control is more than just a standard operating procedure (SOP) document. Controls must be thoroughly implemented, documented, tested, and updated as risks and business processes change.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A simple example of internal control is:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Payment transactions must obtain the approval of authorized officials.<\/li>\n\n\n\n<li>The person receiving the money should not be the one recording the transaction.<\/li>\n\n\n\n<li>Bank account reconciliation is done periodically.<\/li>\n\n\n\n<li>Access to the financial system is restricted based on position.<\/li>\n\n\n\n<li>Changes to vendor data must go through a verification process.<\/li>\n\n\n\n<li>Inventory is checked through stock taking activities.<\/li>\n\n\n\n<li>Audit findings are monitored until corrective actions are completed.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Definition of Internal Control According to Experts<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the following we present what the internal control system is in the opinion of some experts in full.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>According To Horngren (2009)<\/strong>internal control encompasses all plans and actions taken within an organization to protect assets, ensure employees comply with company policies, maintain the accuracy of accounting records, and improve efficiency in operational processes.<br><\/li>\n\n\n\n<li><strong>Hery (2016)<\/strong> explain that internal control consists of a collection of policies and procedures designed to protect company assets from misuse, ensure the accuracy of accounting information, and ensure that all regulations, laws, and management policies are complied with by all employees.<br><\/li>\n\n\n\n<li><strong>Dasaratha V. Rama dan Frederick L. Jones (2008 film<\/strong> states that internal control is a process that is influenced by the board of Directors, management, and other staff within the company. This process aims to ensure the achievement of several objectives, including operational effectiveness and efficiency, accuracy of financial statements, and compliance with applicable regulations.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">From this information, it can be concluded that internal control is a set of policies designed to ensure that the company's operational processes run in accordance with established rules and regulations.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The policy will be standardized into a system in the company known as the internal control system. This system takes the form of a structured framework.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why is Internal Control Important for a Company?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Company growth typically comes with an increase in transactions, employees, systems, branches, vendors, and compliance obligations. Without adequate controls, this complexity can increase the risk of errors and irregularities.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control is needed to help companies:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Protect assets from theft, misuse, or loss.<\/li>\n\n\n\n<li>Maintain the accuracy and completeness of company data.<\/li>\n\n\n\n<li>Reduce the risk of fraud and human error.<\/li>\n\n\n\n<li>Ensure transactions are properly authorized.<\/li>\n\n\n\n<li>Improve the efficiency of operational activities.<\/li>\n\n\n\n<li>Maintain compliance with policies and regulations.<\/li>\n\n\n\n<li>Support decision making based on reliable information.<\/li>\n\n\n\n<li>Strengthening the accountability of each work unit.<\/li>\n\n\n\n<li>Maintaining the reputation and trust of stakeholders.<\/li>\n\n\n\n<li>Make it easier <strong><a href=\"https:\/\/audithink.com\/en\/article\/audit-process\/\" data-type=\"post\" data-id=\"3511\">the audit process<\/a><\/strong> and management evaluation.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Good internal controls also help companies detect irregularities early before they cause greater losses.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Purpose Of Internal Control<\/h2>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"2560\" height=\"1707\" src=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-scaled.webp\" alt=\"Systematic financial statements as a result of Internal Control\" class=\"wp-image-3415\" style=\"object-fit:cover\" title=\"\" srcset=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-scaled.webp 2560w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-300x200.webp 300w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-1024x683.webp 1024w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-768x512.webp 768w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-1536x1024.webp 1536w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-2048x1365.webp 2048w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/2_Pexels_Laporan-Keuangan-Sistemasi-sebagai-Hasil-Dari-Pengendalian-Internal_11zon-2-18x12.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><figcaption class=\"wp-element-caption\">Source: Pexels<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In general, internal control objectives can be grouped into three main categories.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Increase Operational Effectiveness and Efficiency<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Internal controls help ensure that company resources are used appropriately, activities are carried out according to procedures, and operational targets are achieved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples include limiting purchasing authority, evaluating supplier performance, inventory control, and budget monitoring.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Maintaining Reporting Reliability<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Companies need financial and non-financial information that is accurate, complete, relevant, and available in a timely manner.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Controls in the recording, reconciliation, journal approval, and report closing processes help reduce the risk of misstatement or manipulation of information.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Ensuring Compliance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Internal controls help ensure that a company complies with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Legislation.<\/li>\n\n\n\n<li>Regulatory provisions.<\/li>\n\n\n\n<li>Internal policies.<\/li>\n\n\n\n<li>Contract agreement.<\/li>\n\n\n\n<li>Industry standards.<\/li>\n\n\n\n<li>Tax requirements.<\/li>\n\n\n\n<li>Data security and protection provisions.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">In addition to these three main objectives, control also plays a role in protecting assets, maintaining organizational integrity, and supporting healthy corporate governance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Types of Internal Control<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">A. Based On The Benefits<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This policy is categorized into 3 based on its benefits, namely preventive, corrective, and Detective.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. Preventive Control<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Preventive controls are designed to prevent errors or risks before they occur. This type of Control focuses on trying to minimize the possibility of risks appearing by controlling the activities carried out. Examples of preventive internal controls include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Automatic application control to prevent incorrect data input or unauthorized activities.<\/li>\n\n\n\n<li>Access restrictions where only certain people are authorized to access sensitive data or systems.<\/li>\n\n\n\n<li>Validation procedures to ensure that a transaction or process is verified before proceeding.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">2. Corrective Control<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Corrective control is used after an error or problem occurs. This type of Control aims to correct inappropriate or undesirable situations, so that the effects of errors are minimized. Corrective control usually involves:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Change or correct incorrect data after an error is found.<\/li>\n\n\n\n<li>Take action to restore compromised systems or data.<\/li>\n\n\n\n<li>Provide training for employees after errors are found in the performance of duties.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">3. Detective Control<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Detective Control aims to detect errors or problems after the occurrence of a process. These controls do not prevent errors, but help identify problems so that further action can be taken before they become larger. Examples of Detective control include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/audithink.com\/en\/article\/audit-definition\/\" data-type=\"post\" data-id=\"1097\"><strong>Tax Audit<\/strong><\/a> to periodically check financial statements or systems to detect irregularities.<\/li>\n\n\n\n<li>Activity Monitoring to oversee transactions or activities <em>operated<\/em> to detect anomalies.<\/li>\n\n\n\n<li>Recheck documents and transactions to make sure there are no errors.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">B. By Purpose&nbsp;<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control by its purpose is divided into accounting and administrative internal control.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. Internal Control Accounting<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Accounting internal control focuses on the management and control of a company's financial data. Its purpose is to ensure that all transactions and financial information generated are reliable, accurate and well protected.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This process includes a variety of steps, from data verification to separation of duties, to prevent errors and fraud that can harm the company. When the integrity of financial statements is maintained, the company can minimize the risk of financial and reputational losses.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. Internal Control Administration<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Administrative internal control is concerned with the efficiency and effectiveness of administrative management in an organization. This control ensures that administrative processes run optimally to support business objectives<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition, administrative internal control also includes regular monitoring and evaluation of existing procedures and policies, so that any potential obstacles can be identified and overcome quickly.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">C. Based On The Coverage<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control by Scope is divided into general and application categories.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">1. General Control<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This control includes all activities related to <a href=\"https:\/\/audithink.com\/en\/article\/data-management\/\" data-type=\"post\" data-id=\"2878\"><strong>data management<\/strong><\/a> in the computer system. The main goal is to ensure that data is managed securely and regularly. Managed elements include separation of responsibilities and data processing.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">2. Application Control<\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">This control focuses on monitoring transactions and application usage. The main elements include transaction recording, authorization, and reporting on the application. This control aims to ensure the accuracy and security of every transaction that occurs through the application.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Five Components of Internal Control According to COSO<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The COSO framework divides the internal control system into five interrelated components.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-full\"><img decoding=\"async\" width=\"2560\" height=\"1707\" src=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-scaled.webp\" alt=\"Communication process to implement Internal control\" class=\"wp-image-3416\" style=\"object-fit:cover\" title=\"\" srcset=\"https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-scaled.webp 2560w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-300x200.webp 300w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-1024x683.webp 1024w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-768x512.webp 768w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-1536x1024.webp 1536w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-2048x1365.webp 2048w, https:\/\/audithink.com\/wp-content\/uploads\/2024\/10\/3_Pexels_Proses-Komunikasi-untuk-Menerapkan-Pengendalian-Internal_11zon-18x12.webp 18w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><figcaption class=\"wp-element-caption\">Source: Pexels<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th>COSO Components<\/th><th>Primary Focus<\/th><th>Examples Of Implementation<\/th><\/tr><\/thead><tbody><tr><td>Control environment<\/td><td>Culture, integrity, structure and accountability<\/td><td>Code of ethics, organizational structure, division of authority<\/td><\/tr><tr><td>Risk assessment<\/td><td>Risk identification and analysis<\/td><td>Risk register and fraud risk assessment<\/td><\/tr><tr><td>Control activities<\/td><td>Policies and procedures for managing risks<\/td><td>Authorization, reconciliation, segregation of duties<\/td><\/tr><tr><td>Information and communication<\/td><td>Provision and delivery of information<\/td><td>Internal reporting, complaint channels, dashboard<\/td><\/tr><tr><td>Monitoring<\/td><td>Evaluation of control effectiveness<\/td><td>Internal audit, control self-assessment, follow-up<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">1. Control Environment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The control environment is the foundation of the entire internal control system. This component reflects the leadership's attitude and organizational culture toward integrity, accountability, and the importance of risk management.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The control environment includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Commitment to integrity and ethical values.<\/li>\n\n\n\n<li>Oversight by the board of commissioners or audit committee.<\/li>\n\n\n\n<li>Organizational structure and division of authority.<\/li>\n\n\n\n<li>Employee competency development.<\/li>\n\n\n\n<li>Determination of responsibility and accountability.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If management ignores procedures or sets inconsistent examples, other controls risk becoming ineffective even if they are well documented.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Risk Assessment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Risk assessment is the process of identifying and analyzing events that may hinder the achievement of organizational goals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Risk assessment includes:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Define the organization's goals clearly.<\/li>\n\n\n\n<li>Identify operational, financial, compliance, and technology risks.<\/li>\n\n\n\n<li>Assess the likelihood and impact of risks.<\/li>\n\n\n\n<li>Considering the risk of fraud.<\/li>\n\n\n\n<li>Analyze significant business changes.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Examples of changes that need to be considered are the implementation of new systems, opening branches, regulatory changes, changes in key personnel, organizational restructuring, and the use of artificial intelligence technology.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Control Activities<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Control activities are policies and procedures implemented to help ensure that responses to risks are carried out appropriately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Control activities can be:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Transaction approval and authorization.<\/li>\n\n\n\n<li>Separation of duties.<\/li>\n\n\n\n<li>Data reconciliation.<\/li>\n\n\n\n<li>Document verification.<\/li>\n\n\n\n<li>System access restrictions.<\/li>\n\n\n\n<li>Physical security of assets.<\/li>\n\n\n\n<li>Performance check.<\/li>\n\n\n\n<li>Control over system changes.<\/li>\n\n\n\n<li>Application usage and automatic control.<\/li>\n\n\n\n<li>Standardization of procedures through SOPs.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Control activities must have a responsible person, frequency of implementation, documentation method, and auditable evidence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Information and communication<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Organizations need relevant and quality information so that every control can run effectively.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This information needs to be communicated to the right parties, at the right time, and through the right channels.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Examples of its application include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Periodic financial and operational reports.<\/li>\n\n\n\n<li>Risk monitoring dashboard.<\/li>\n\n\n\n<li>Socialization of policies to employees.<\/li>\n\n\n\n<li>Issue escalation mechanism.<\/li>\n\n\n\n<li>Kanal whistleblowing.<\/li>\n\n\n\n<li>Communication with auditors and regulators.<\/li>\n\n\n\n<li>Reporting control weaknesses to management.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Ineffective communication can cause employees to not understand the authority, procedures, or actions to be taken when they discover irregularities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Monitoring<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Monitoring aims to assess whether internal controls are still designed appropriately and implemented consistently.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Monitoring can be done through:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Routine supervision by superiors.<\/li>\n\n\n\n<li>Periodic check-up.<\/li>\n\n\n\n<li>Self-evaluation by work units.<\/li>\n\n\n\n<li>Audit internal.<\/li>\n\n\n\n<li>Data analysis and exception reporting.<\/li>\n\n\n\n<li>Follow-up monitoring of findings.<\/li>\n\n\n\n<li>Separate evaluation by an independent party.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Any weaknesses discovered must be communicated to the authorities and followed by measurable corrective actions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Understanding the 17 COSO Principles of Internal Control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The five COSO components are further broken down into 17 principles.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Control Environment<\/h3>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Demonstrate commitment to integrity and ethical values.<\/li>\n\n\n\n<li>Carry out supervisory responsibilities.<\/li>\n\n\n\n<li>Establish structure, authority, and responsibility.<\/li>\n\n\n\n<li>Demonstrate commitment to competence.<\/li>\n\n\n\n<li>Enforcing accountability.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Risk Assessment<\/h3>\n\n\n\n<ol start=\"6\" class=\"wp-block-list\">\n<li>Set appropriate goals.<\/li>\n\n\n\n<li>Identify and analyze risks.<\/li>\n\n\n\n<li>Considering the potential for fraud.<\/li>\n\n\n\n<li>Identify and analyze significant changes.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Control Activities<\/h3>\n\n\n\n<ol start=\"10\" class=\"wp-block-list\">\n<li>Select and develop control activities.<\/li>\n\n\n\n<li>Select and develop general controls over technology.<\/li>\n\n\n\n<li>Implementing controls through policies and procedures.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Information and communication<\/h3>\n\n\n\n<ol start=\"13\" class=\"wp-block-list\">\n<li>Using relevant and quality information.<\/li>\n\n\n\n<li>Carry out internal communication.<\/li>\n\n\n\n<li>Carry out external communications.<\/li>\n<\/ol>\n\n\n\n<h3 class=\"wp-block-heading\">Monitoring<\/h3>\n\n\n\n<ol start=\"16\" class=\"wp-block-list\">\n<li>Conduct ongoing evaluations or separate evaluations.<\/li>\n\n\n\n<li>Evaluate and communicate control weaknesses.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">A control system can be considered effective if the relevant components and principles are available, functioning, and working in an integrated manner.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Important Elements in Control Activities<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Some control elements that are commonly applied in companies include:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Separation of Duties<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The tasks of authorization, recording, asset storage, and inspection should not be performed by the same person.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Segregation of duties can reduce the opportunity for someone to commit and hide errors or fraud.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Transaction Authorization<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each transaction must obtain approval according to the established authority limits.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The higher the value or risk of the transaction, the higher the level of approval required.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Adequate Documentation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each transaction must have complete supporting documents and evidence, be easily traceable, and be stored according to the retention period.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Asset Security<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Both physical and digital assets must be protected through access restrictions, use of secure storage, inventory, encryption, and backup mechanisms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Reconciliation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Data from two different sources need to be compared periodically to find differences or discrepancies.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Independent Review<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Certain activities need to be reviewed by parties not directly involved in the execution of the transaction.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Access Control<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Access to applications and data should be granted based on job requirements or principles. <em>least privilege<\/em>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Examples of Internal Control in a Company<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here are some examples of internal controls based on business processes.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th>Business Process<\/th><th>Risks<\/th><th>Example of Control<\/th><\/tr><\/thead><tbody><tr><td>Procurement<\/td><td>Fictitious or non-needed purchases<\/td><td>Purchase order approval and vendor evaluation<\/td><\/tr><tr><td>Payment<\/td><td>Double or invalid payment<\/td><td>Three-way matching and tiered authorization<\/td><\/tr><tr><td>Sale<\/td><td>Selling to risky customers<\/td><td>Credit limit approval<\/td><\/tr><tr><td>Accounts receivable<\/td><td>Bad debts<\/td><td>Accounts receivable aging analysis and customer confirmation<\/td><\/tr><tr><td>What<\/td><td>Embezzlement of receipts<\/td><td>Bank reconciliation and separation of cashier functions<\/td><\/tr><tr><td>Preparation<\/td><td>Loss or difference in stock<\/td><td>Stocktaking and warehouse access restrictions<\/td><\/tr><tr><td>Payroll<\/td><td>Fictitious employees<\/td><td>Reconciliation of HR and payroll data<\/td><\/tr><tr><td>Reporting<\/td><td>Misstatement of the report<\/td><td>Journal review and account reconciliation<\/td><\/tr><tr><td>Information Technology<\/td><td>Unauthorized access<\/td><td>MFA, access review, backup, and log monitoring<\/td><\/tr><tr><td>Data vendor<\/td><td>Fake account changes<\/td><td>Independent verification of data changes<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Examples of Controls in the Payment Process<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In the vendor payment process, companies can implement controls in the form of:<\/p>\n\n\n\n<ol start=\"1\" class=\"wp-block-list\">\n<li>Purchase orders must be approved by authorized officials.<\/li>\n\n\n\n<li>Goods or services must be confirmed as received.<\/li>\n\n\n\n<li>The invoice is compared with the purchase order and proof of receipt.<\/li>\n\n\n\n<li>Vendor account changes are independently verified.<\/li>\n\n\n\n<li>Payments above a certain limit require two approvals.<\/li>\n\n\n\n<li>Proof of payment is stored and can be traced.<\/li>\n\n\n\n<li>Bank accounts are reconciled by a party that does not process payments.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">How to Implement an Internal Control System<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The implementation of internal control can be carried out through the following stages.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Set Goals<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Companies need to determine the objectives of the processes to be controlled, such as reporting accuracy, asset security, compliance, or operational efficiency.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Mapping Business Processes<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Document the process stages, parties involved, systems used, documents produced, and decision-making points.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Identifying Risks<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Identify risks that could prevent objectives from being achieved, including risks of error, fraud, non-compliance, system failure, and operational disruption.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Assess the Risk Level<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Assess each risk based on the likelihood of it occurring and the magnitude of the impact it could cause.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Designing Control Activities<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Determine appropriate controls to reduce the risk to an acceptable level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each control should have:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Name and purpose of control.<\/li>\n\n\n\n<li>Risks handled.<\/li>\n\n\n\n<li>Person responsible.<\/li>\n\n\n\n<li>Frequency of implementation.<\/li>\n\n\n\n<li>Type of control.<\/li>\n\n\n\n<li>Proof of implementation.<\/li>\n\n\n\n<li>Testing method.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">6. Develop Policies and SOPs<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Control needs to be outlined in policies and SOPs so that it can be understood and implemented consistently.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">7. Conducting Socialization<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Employees must understand the purpose of control, their individual responsibilities, and the consequences if procedures are not followed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">8. Testing Control Effectiveness<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Testing is done to determine whether the control:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Precisely designed.<\/li>\n\n\n\n<li>Really implemented.<\/li>\n\n\n\n<li>Implemented by the authorities.<\/li>\n\n\n\n<li>Have sufficient evidence.<\/li>\n\n\n\n<li>Successfully reduced risk.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">9. Fixing Weaknesses<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Each weakness needs to have a recommendation, a person responsible for action, a time target, and a monitoring mechanism.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">10. Conduct Continuous Evaluation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Controls must be updated when there are changes in processes, organizational structure, regulations, technology, or risk profiles.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Simple Control Matrix Example<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Companies can use <em>risk and control matrix<\/em> to link objectives, risks, and controls.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th>Risks<\/th><th>Control<\/th><th>Responsible Person<\/th><th>Frequency<\/th><th>Proof<\/th><\/tr><\/thead><tbody><tr><td>Fictitious invoice payments<\/td><td>Three-way matching<\/td><td>Supervisor Account Payable<\/td><td>Every transaction<\/td><td>PO, invoice, and proof of receipt<\/td><\/tr><tr><td>Unauthorized vendor account changes<\/td><td>Verify with the vendor's official contact<\/td><td>Procurement Manager<\/td><td>Every change<\/td><td>Verification form<\/td><\/tr><tr><td>Bank balance difference<\/td><td>Bank reconciliation<\/td><td>Finance Supervisor<\/td><td>Monthly<\/td><td>Reconciliation document<\/td><\/tr><tr><td>Former employee access is still active<\/td><td>User access review<\/td><td>IT Security<\/td><td>Monthly<\/td><td>User access review report<\/td><\/tr><tr><td>Missing setup<\/td><td>Stock shot<\/td><td>Warehouse Supervisor<\/td><td>Monthly or quarterly<\/td><td>Stock take minutes<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">This type of documentation helps management and auditors understand whether significant risks have adequate controls.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ineffective Internal Control Indicators<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Companies need to be aware of the following signs:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>The same audit findings keep repeating themselves.<\/li>\n\n\n\n<li>Reconciliation is often late.<\/li>\n\n\n\n<li>Many transactions lack supporting documentation.<\/li>\n\n\n\n<li>System accounts are shared.<\/li>\n\n\n\n<li>Approval is done after the transaction takes place.<\/li>\n\n\n\n<li>Inventory discrepancies were not investigated.<\/li>\n\n\n\n<li>Access rights are not reviewed periodically.<\/li>\n\n\n\n<li>Critical data changes have no audit trail.<\/li>\n\n\n\n<li>Corrective action exceeded the target time.<\/li>\n\n\n\n<li>Management often ignores SOPs.<\/li>\n\n\n\n<li>No party is responsible for any control.<\/li>\n\n\n\n<li>Control is only carried out prior to the audit.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Such findings do not necessarily prove fraud, but may indicate that risks have not been adequately managed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Limitations of Internal Control<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internal controls can reduce risk, but cannot provide absolute assurance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some limitations of internal control include:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Human Error<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Employees may misunderstand instructions, make recording errors, or make poor decisions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Collusion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Two or more parties may work together to circumvent controls that have been implemented.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Management Override<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Management has the authority to ignore or bypass procedures.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Cost and Benefit Considerations<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The cost of implementing controls needs to be commensurate with the level of risk and the value of the assets being protected.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Changing Business Conditions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Previously effective controls may become irrelevant after changes in systems, processes, regulations, or business models.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Dependence on Technology<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configuration errors, system disruptions, or improper access can reduce the effectiveness of automated controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Due to these limitations, internal controls need to be monitored and evaluated periodically.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Differences between Internal Control and Internal Audit<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control and internal audit are closely related, but they are not the same thing.<\/p>\n\n\n\n<figure class=\"wp-block-table is-style-stripes\"><table class=\"has-fixed-layout\"><thead><tr><th>Aspect<\/th><th>Internal Control<\/th><th>Internal Audit<\/th><\/tr><\/thead><tbody><tr><td>Definition of<\/td><td>Processes and activities to manage risk<\/td><td>Independent assurance and consulting activities<\/td><\/tr><tr><td>Person responsible<\/td><td>Management and all personnel<\/td><td>Internal audit function<\/td><\/tr><tr><td>Implementation<\/td><td>Be part of daily activities<\/td><td>Implemented based on the audit plan<\/td><\/tr><tr><td>Purpose<\/td><td>Reduce risks and help achieve goals<\/td><td>Assess and improve control effectiveness<\/td><\/tr><tr><td>Roles<\/td><td>Running control<\/td><td>Evaluate the design and implementation of controls<\/td><\/tr><tr><td>Independency<\/td><td>It is the responsibility of the process owner<\/td><td>Must be objective and independent of the activity being audited.<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Management should not cede ownership of control to internal auditors. Internal auditors may make recommendations, but implementing and maintaining controls remains management's responsibility.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Role of Technology in Internal Control Evaluation<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The more complex the organization, the more difficult it is to test and monitor controls using only separate documents, spreadsheets, or email communications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Technology can help internal audit teams in:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Compile a risk assessment.<\/li>\n\n\n\n<li>Linking processes, risks and controls.<\/li>\n\n\n\n<li>Save the program and <strong><a href=\"https:\/\/audithink.com\/en\/article\/audit-working-papers\/\" data-type=\"post\" data-id=\"1683\">audit working papers<\/a><\/strong>.<\/li>\n\n\n\n<li>Documenting evidence of the inspection.<\/li>\n\n\n\n<li>Record findings and recommendations.<\/li>\n\n\n\n<li>Communicate with <strong><a href=\"https:\/\/audithink.com\/en\/article\/auditee-definition\/\" data-type=\"post\" data-id=\"756\">auditee<\/a><\/strong>.<\/li>\n\n\n\n<li>Monitor corrective actions.<\/li>\n\n\n\n<li>Compile audit reports.<\/li>\n\n\n\n<li>View audit progress centrally.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The use of applications does not replace management's responsibilities or the auditor's professional judgment. However, an integrated system can improve documentation consistency, information traceability, and follow-up monitoring.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Manage Internal Control Evaluation with Audithink<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internal controls need to be evaluated regularly to keep them aligned with changes in the company's risks and business processes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/audithink.com\/en\/\" data-type=\"page\" data-id=\"794\">Audithink helps internal audit teams<\/a><\/strong> manage the audit process in a more structured manner, starting from risk assessment, audit planning, program preparation, documentation of audit results, discussion of recommendations, to monitoring auditee follow-up.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With an integrated process, companies can monitor audit findings, ensure recommendations are acted upon, and obtain better information to strengthen internal controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/audithink.com\/en\/demo\/\" data-type=\"page\" data-id=\"1010\">Schedule an Audithink demo<\/a><\/strong> to find out how internal audit applications can help improve the efficiency and traceability of your company's audit processes.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Internal control is a process designed to provide reasonable assurance that an organization's operational, reporting, and compliance objectives are achieved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An effective control system needs to include the five COSO components, namely the control environment, risk assessment, control activities, information and communication, and monitoring.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, control is more than just a set of SOPs. Controls must be implemented, documented, tested, and adjusted as risks evolve.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Through adequate controls and regular internal audit evaluations, companies can reduce the risk of errors, fraud, non-compliance, and operational losses.<\/p>","protected":false},"excerpt":{"rendered":"<p>Setiap perusahaan menghadapi risiko kesalahan pencatatan, penyalahgunaan aset, ketidakpatuhan, kebocoran data, hingga kecurangan. Risiko tersebut dapat muncul karena kelemahan prosedur, pembagian tanggung jawab yang tidak jelas, atau kurangnya pengawasan terhadap aktivitas operasional. Untuk meminimalkan risiko tersebut, perusahaan membutuhkan pengendalian internal yang dirancang dan dijalankan secara konsisten. Pengendalian internal adalah proses yang diterapkan oleh dewan komisaris, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3412,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15],"tags":[27],"class_list":["post-3406","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-manajemen-audit"],"acf":[],"_links":{"self":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts\/3406","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/comments?post=3406"}],"version-history":[{"count":4,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts\/3406\/revisions"}],"predecessor-version":[{"id":5289,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/posts\/3406\/revisions\/5289"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/media\/3412"}],"wp:attachment":[{"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/media?parent=3406"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/categories?post=3406"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/audithink.com\/en\/wp-json\/wp\/v2\/tags?post=3406"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}