Skip to content

Guide to internal controls and risk

Audit term definitions, a description of roles and responsibilities, goals of best practice internal controls, common weaknesses in financial processes, how to avoid them, and answers to your internal control questions.

Topics on this page:

What are risks?

A risk is anything that could prevent or jeopardize the achievement of the University’s objectives.

Risk is a natural and unavoidable part of the University of Rochester’s mission, its operations, and the day‑to‑day work performed by every member of our community. Risks arise in all areas of the institution and can affect teaching, research, patient care, financial sustainability, compliance, and reputation.

Risks can fall into one or more of the following categories:

  • Operational
  • Financial
  • Strategic
  • Reputational
  • Regulatory / Compliance
  • Health and Safety
  • Information Technology, Data and Cybersecurity

Risk is often evaluated on a two-dimensional scale:

  • What is the likelihood of occurrence?
  • How significant would the impact be if the risk were to occur?

Some risks can be avoided, transferred, or accepted. However, when a risk cannot be eliminated, it must be mitigated through effective internal controls, which help reduce the likelihood and/or impact of adverse events and support the University’s ability to achieve its objectives.

What are internal controls?

The Institute of Internal Auditors (IIA) defines internal control as a process, effected by an entity’s board of directors, management, and other personnel, designed to provide reasonable assurance regarding the achievement of objectives.

In practical terms, internal controls are the everyday practices, processes, and safeguards used across the University to help ensure goals are achieved, resources are protected, information is reliable, and operations run safely, efficiently, and in compliance with laws and policies. They are simply good business practices that provide reasonable assurance that our work is carried out effectively and responsibly.

Internal controls, if designed and implemented properly, assist in mitigating the risk of errors, fraud, and abuse.

 

Internal controls can take many forms, but most fall into two helpful distinctions:

Manual and Automated Controls

Manual Controls

Manual controls are performed by people. They rely on human judgment and oversight.

Examples: reviewing reports from UR Financials, reviewing/approving purchases, reconciling accounts, and verifying supporting documentation.

Automated Controls

Automated controls are built into systems or technologies—such as Workday, clinical systems, or research administration systems—and operate consistently without human intervention.

Examples: system access restrictions, routing rules for transaction approvals, and programmed error checks.

Using both manual and automated controls provides balanced assurance, leveraging human insight alongside system‑driven processes.

Preventive and Detective Controls

Internal controls also differ based on whether they aim to stop issues before they happen or identify them after they occur:

Preventive Controls

Preventive controls are designed to avoid errors, misuse, or noncompliance from occurring in the first place.

Example: A manager’s review and approval of a purchase before it is finalized.

Detective Controls

Detective controls identify issues after they have occurred so they can be corrected or escalated.

Example: Comparing a monthly ledger report to supporting documentation to detect incorrect transactions or fraud.

Together, preventive and detective controls help ensure the University’s operations remain accurate, efficient, and aligned with policies and expectations

Examples of internal controls

  • Written policies, procedures and standardized processes
  • Establishing appropriate segregation of duties within key operational, financial and administrative processes
  • System access controls
  • Electronic approval routing
  • Financial Reviews and Reconciliations, including budget to actual and trend analysis
  • Physical access controls

The Office of University Audit provides independent evaluation of the adequacy of internal controls and makes specific recommendations for improvements.

Goals of internal controls

The establishment of internal controls aims to:

  • Safeguard University assets – protecting physical property, cash, data, research materials, and other resources from loss, misuse, or damage.
  • Ensure compliance – promoting adherence to laws, regulations, grant requirements, University policies, and accreditation standards.
  • Promote accurate and reliable information – ensuring financial, operational, academic, and research data are complete, timely, and trustworthy.
  • Support efficient and effective operations – helping departments run smoothly by reducing errors, improving consistency, and minimizing waste of time or resources.
  • Identify and mitigate risks – reducing the likelihood and impact of risks that could affect the University’s goals, programs, research, patient care, or reputation.
  • Strengthen accountability – ensuring roles, responsibilities, approvals, and monitoring activities are clear and properly executed.
  • Enable sound decision‑making – producing reliable information and well‑designed processes that support informed leadership decisions.
  • Prevent and detect fraud or misuse – establishing practices that deter inappropriate activity and identify issues quickly if they occur.

Internal control responsibilities

Internal controls are everyone’s responsibility.

Role of University Audit

University Audit provides an independent assessment of risk and an evaluation of existing internal controls and reports the results to University management and the Audit Committee of the Board of Trustees.

Role of management

Management is responsible for establishing and maintaining internal controls that support the University’s mission and objectives. This includes continually assessing risks, monitoring changes in the operating environment, and modifying or adding controls as needed to ensure that risks are appropriately managed.

Everyone’s role

Internal control relies on the commitment and action of people. Every member of the University community plays a role in maintaining effective internal controls. Each individual is responsible for understanding the risks related to their work and following established policies and procedures to help protect the University’s people, assets, and mission.

Related offices and departments

Other resources