Skip to content

Recommended internal controls for financial management

Definitions of terms and an introduction to internal control procedures including analysis, review, and reconciliation measures necessary to mitigate risk in financial management for each Financial Activity Object (FAO).

Topics on this page:

Popular resources

Financial management activities

A risk is anything that could prevent or jeopardize the achievement of the University’s objectives.

A critical component of the University’s internal control environment over financial transactions is the departmental Financial Management activities of analyzing, reviewing and reconciling transactions in a timely manner.

The purpose of this document is to:

    1. Define key internal control terminology
    2. Recommend internal control procedures.

The expectations and recommendations outlined in this document are proven to be effective measures for Financial Management and provide reasonable assurance that errors, misuse or fraud would be detected in a timely manner.

The objective is to have an effective and efficient process in place for each Financial Activity Object (FAO) utilizing the following internal controls:

    1. Financial Analysis
    2. FAO Review
    3. FAO Reconciliation

Effective financial management must balance the risk associated with each FAO and the resources available to complete the internal control procedures.

This document describes expectations for proper internal controls over all FAOs, including those associated with the Sponsored Awards. However, this document does not replace or override documented guidelines provided by ORPA, ORACS or CLASP.

Implementing FAO internal controls

The first step is completing a FAO Inventory and Self-Analysis Worksheet. The FAO Inventory identifies all FAOs within a department. Performing the Self-Analysis assists in determining which internal control procedures will be used to address the risk associated with each FAO and documents department management’s expectations.

Definitions

Cost benefit analysis

Weighing the total expected cost of an internal control activity against the total expected benefits in order to choose the most cost effective risk mitigation strategy.

Detective controls

Internal controls designed to provide reasonable assurance that errors, abuse and fraud will be detected in a timely manner. Examples of detective controls include: financial analysis, FAO review and FAO reconciliation.

High risk areas

  • Transactions that are high dollar amounts, unusual, unrecognized, and/or susceptible to fraud.
  • PCards, gift cards, petty cash, payments to study participants, check requests, cell phone usage, and payroll (including Extra Compensation).
  • Travel and conference reimbursements and other reimbursements to employees such as mileage, food, and supplies.

Internal controls

An organization’s methods, systems and procedures for (1) protecting resources from waste, loss, theft or misuse (2) ensuring that resources are used in accordance with law, business and donor intent and (3) producing reliable financial statements based on accurate and verifiable data.

Preventive controls

Internal Controls designed to provide reasonable assurance that errors, abuse and fraud will be
prevented. Examples of preventive controls include: system ID/password protections, authorization policies, segregation of duties and physical asset safeguarding.

Segregation of duties

Segregation of duties is a basic preventive control. The four functions that should be performed by separate individuals are authorization, custody, record keeping, and reconciliation. No one person should have control over two or more of these responsibilities.

Financial Activity Object (FAO)

FAOs replace the account numbers in FRS. There are currently six FAO tags, GR (Grant), OP
(Operating Program), GF (Gift), PR (Project), DS (Debt Service) and LN (Loan Program).

Supporting documentation

Purchase requisitions, invoices, receipts, packaging slips, purchase orders, contracts, written
notes/memos and other paper work that provide evidence of the validity and appropriateness of a financial transaction. Supporting documentation should always be self-explanatory and not require verbal explanation.

Risk assessment

An analysis designed to identify events that could adversely impact the achievement of objectives (i.e., risks). Identified risks are evaluated in terms of likelihood of occurrence and perceived impact. Risks that are ranked high should be mitigated by internal controls.

Fiscally authorized responsible individual

Person or persons (i.e., the Chair, Director, Dean, VP or PI) with the direct responsibility to ensure that departmental FAOs are properly managed and are being utilized for appropriate business purposes.

Overview of FAO internal controls

The following section provides a summary of the three FAO internal controls discussed in this document.

Required documentation

The completion of the FAO internal control activities (financial analysis, FAO review, FAO reconciliation) should be documented. There are several acceptable practices for documenting the completion of FAO controls; however, all should contain an acknowledgement that the control activity was completed, signatures or initials (electronic is acceptable) by the completing individual, title and date completed. Examples include:

a. A sign-off form showing department, month, year, FAO numbers, comments, and signatures.

b. Initialing and dating the hard copy of the printed FAO transaction detail

c. An electronic log

d. Emails indicating review and approval

Documentation related to these controls should be maintained per the University’s record retention policy.

Related offices and departments