Preventive vs Detective vs Corrective Controls: Types of Internal Controls Explained with Examples

Preventive vs detective vs corrective controls in business internal control systems

Introduction

Good accounting, financial management, risk management and business governance cannot do without internal controls. They are the policies, procedures, systems and activities an organization implements to control risks, safeguard assets, maintain a working and reliable record and ensure adherence to legal and internal policies. While businesses may talk about internal controls as a singular entity, the internal controls they have implemented can be utilized for various uses and for a variety of risks depending on when and how they are employed. There are three main types of internal controls; preventive, detective and corrective. It becomes clear to business owners, managers, accountants, auditors and finance teams when they understand the difference between these categories that they can create a more robust control environment. A good system not only will try to prevent fraud, it will also detect fraud when it occurs, and will offer a framework for rectifying weaknesses, recovering losses and minimizing chances of reoccurrence.

What Internal Controls?

Internal controls are management’s organized measures designed to give reasonable assurance to an organization that it meets important operational, financial reporting, and compliance goals. These can range from approvals, segregation of duties, reconciliations, physical security, access controls, audit trails, system alerts, to management reviews. Internal controls are significant because of risks that may be encountered by the organization, such as human error, fraud, theft, unauthorized transaction, inaccurate reporting, cyber security incident, regulatory violation, and inefficient processes. A control system cannot guarantee that all problems will be avoided as employees may make errors and people may choose deliberately to ignore a procedure. Rather, an effective internal control system provides multiple lines of defense. These layers should complement each other in such a way that if one layer of control fails, there is no automatic and catastrophic loss of money and/or operation. The ultimate goal is to increase the trust, transparency, accountability and resilience of key business processes.

Three Main Types of Internal Controls

There are three types of internal controls preventive, detective and corrective. The most significant difference between them is the time when a risk is dealt with. Preventive controls include measures taken to prevent an unwanted event from happening. Detective controls are those checks conducted after or during an event to detect any errors, irregularities or violations that have occurred or are occurring. Corrective controls are measures taken to address a problem that has been identified and to mitigate the impact of the problem and to help prevent another problem from occurring. These categories are not mutually exclusive, but rather are examples. All three are usually necessary because no matter how much prevention is undertaken, there are still risks that will be present, and no matter how well any detection is done, it cannot solve the problem, and if the problem is not addressed with prevention or detection, losses can continue without realizing that anything is wrong. Working together, these control types can provide a multi-layered risk management strategy to safeguard financial information, assets, employees, customers and the organization’s reputation.

What are Preventive Controls?

Preventive controls are controls put in place to avoid errors, fraud, unauthorized activities, or other undesirable events from happening in the first place. These are often seen as a first line of defence as they try to tackle a risk at source instead of it causing damage. These measures can include approving purchases above a certain threshold, having multiple employees responsible for approving and recording transactions, requiring passwords and multi-factor authentication, limiting access to accounting software, background checks for positions with high-risk duties, and having clear accounting procedures. In the field of accounting, preventive controls can be extremely useful as many financial issues become more costly and problematic after the transaction is finalized. For instance, a company might allow payments to be made by only certain employees, and require a second employee to approve the payments, which decreases the chance of a payment being made without authorization in the first place.

Examples of Preventive Controls

One of the preventive controls is segregation of duties. In such a scenario, the authorization, recording of the transaction, handling of the concerned asset and checking of the transaction is done by different people where practical. This makes it harder to cover up and commit fraud without being caught by one of the employees. For purchases, for instance, an approval process can be created. A company might have to ask employees permission to purchase equipment, services or supplies at specific amounts. Another way to prevent is with access controls. An accounting system can be designed to allow only certain functionality to certain users of the system based on their job role, so that other users cannot modify vendor details, financial records or make payments. This includes physical controls, as well. Some of the controls that are implemented to prevent the use or theft of assets prior to loss include locked storage areas, restricted offices, inventory security, and controlled access to cash.

Benefits and Drawbacks of Preventive Controls

There are a number of benefits of using preventive controls as they can minimize the number of problems that may occur and the cost if they do occur. They can also inspire staff to adopt standard procedures, make clear duties and establish accountability culture. Preventative controls are not infallible, however. Human error, compromised credentials, inadequate design of controls or improper or intentional use by authorized users can all result in error. In addition, there is the potential for building a large body of preventative measures that will impede normal business operations without any significant impact on risk. As a result, there should be a risk assessment to determine the importance and the probability of each risk before introducing controls. A control should be commensurate to the threat it is going to combat. There might be multiple steps required to approve higher-cost payments, and lower-cost and routine payments might require only a more basic approval process. This is why it’s essential to have a balance between the effective preventive control and an unnecessary bureaucracy that would make it easier for employees to circumvent the system.

What is Detective Controls?

A detective control is one that detects an error, fraud, or other irregularity when it occurs or it does at some time in the future. They do not always prevent events from occurring like preventive controls do. They instead offer transparency on what went wrong, enabling management to take action and investigate and respond. Because, even with great preventive measures, it is possible for them to fail, detective controls are of special interest. Some examples are bank reconciliations, inventory counts, internal audits, variance analysis, exception reports, transaction monitoring, review of journal entries, automated system alerts and surprise cash counts. Detective controls can be used in accounting to uncover transactions that don’t match supporting documents, odd increases in expenses, duplicate payments, discrepancies in the accounting records, and bank statements, or unexpected shifts in inventory. How fast they’re identified and investigated will create a significant difference in their effectiveness. A detective control that will identify a problem after the fact, many months later, may be useful, but might offer less protection than a control that will give a warning the first time the problem occurs.

Examples of Detective Controls

One of the most common detective controls for accountants is bank reconciliation. An employee looks at the company’s accounting records and reviews the discrepancy between the company’s records and the bank statement. This procedure can uncover unrecorded transactions, bank mistakes, unauthorized withdrawals, duplicate entry, or entry inaccuracies. Another example would be inventory counts. A business can compare the amount of goods that it has on hand to the amount of goods that it has on file in their inventory system. The differences will show up if there is any of the following: theft, damage, error in recording, operational issues. Management review is also a detective control as managers review financial reports and investigate any unusual results. An increase in the amount of a company’s monthly expenses, for instance, by 40 percent without a corresponding rise in revenue or business activity could be reason to review the transactions that led to the change. An additional level can be provided by automated alerts which flag out-of-the-ordinary payment amounts, repeat transactions, changes to supplier information or transactions outside of normal hours for further investigation.

Advantages and Limitations of Detective Controls

Detective controls are an important safety net as they are able to detect issues, before they occur, that preventive controls may not have prevented. They also can provide valuable insights into the areas of the business processes that need improvement. By studying those exceptions that regularly happen, an organization can find out that a process for approving is ambiguous, an employee has too much access to the system or a supplier-management process could be enhanced. But, the general rule of detective controls is that they are used after the risk has occurred and so may not prevent the first loss. The control is able to see the problem because when the monthly reconciliation is done several weeks later, the cash is short by an amount equal to the theft. The control has identified the problem, but the control has not prevented the theft. When exceptions are created so many times that they are overlooked by employees, then the detective controls can become ineffective. In this regard, the monitoring should be structured based on meaningful risk indicators and have clear responsibilities for the investigation of exceptions. The detection of a problem should result in action, not be a form of routine reporting with no follow-up action.

What are Corrective Controls?

Corrective controls are those controls put in place once a problem is detected to address the problem, to mitigate the impact of the problem and to minimize the risk of re-occurrence. One of the reasons why they are important is because the discovery of a control failure is just the start of the action. Management needs to find out what went wrong, deal with the consequences, correct any inaccurate records (where applicable) and enhance the process that led to the occurrence of the problem. Some examples of corrective controls are: undoing an incorrect accounting entry, recovering an unauthorized payment, recovering data from a secure backup, changing access privileges, retraining employees, updating policies, adding more restrictions to the systems, or adding more conditions to the approval process. Disciplinary action, or indeed senior management action, may also be necessary in some cases in order to achieve the necessary corrective action. This is dependent on the kind and magnitude of the incident. A small accounting error might call for a straightforward correction and an employee reminder, whereas a large scale fraud could result in a thorough investigation, recovery, legal proceedings, and complete redesign of the controls for this type of fraud.

Examples of Corrective Controls

Now think of the time when a company finds that one employee has been able to set up a fake supplier to pay for and has been able to do too many things in the accounting system. Corrective action might involve cancelling or reclaiming unauthorized payments, termination of the fictitious supplier, audit of past payments and a search of the employee’s work. Management could then re-engineer the creation of suppliers to ensure that the new supplier information is independently verified by a second authorized person. An additional example is of accounting error. When a financial statement is prepared with the wrong expense classification, the organization could amend the journal entry, check the transactions with the financial statement, and determine the root cause of the error. If the root cause is they have not trained their employees correctly, then management can give more training, along with updating their accounting procedures. This way, the corrective controls don’t simply fix the obvious issue, they also target the root cause of the issue.

Comparison of preventive detective and corrective controls with examples

Three types of controls: Preventive, Detective, Corrective.

To learn what the differences between the three controls categories are, you should think of how and why they were used, that is, consider when they were used and what they were intended to do. Preventive controls are controls that are implemented before a risk event occurs and try to prevent the event from occurring. Detective controls detect damage after it happens or in the process of developing. Corrective controls will address identified problems by repairing damages and enhancing the control environment. For instance, if a company is looking to minimize the chances of unauthorized payments, they might want to implement a payment verification system to ensure only authorized users can access and make transactions. A preventive control may need to be backed by the signature of two qualified employees for payment to be made above a certain limit. An example of a detective control would be to examine bank statements and payment records for any unusual transactions. Some of the corrective controls might include the freezing of an unauthorized payment account, recovering of funds, correction of accounting records, investigation of the incident, and a change in access permission. The three controls thus are designed to address a single risk in multiple ways. They are most effective when applied in combination with each other rather than any one control since each control can offer protection where the other might have a limitation.

Why Businesses Need a Balanced Control System

A balanced internal control system is a mix of preventive, detective and corrective controls that taking into account the risks of the organization, its size, industry, technology and operating environment. A sole prevention system can give an illusion of security due to the lack of perfection in preventive systems. Likewise, if detection is the main focus, then it is likely that an organization will continue to lose money before it is noticed. Corrective controls must be put in place when a failure occurs, but should not be an excuse to have weaknesses that were preventable or identified earlier. Multiple layers of protection will be established in a balanced system. Preventive controls minimize the risk and potential of an incident; detective controls maximize the chances of finding a failure; and corrective controls limit the impact if an incident occurs by responding to the failure when it is detected. This multi-layered approach can be particularly beneficial in financial transactions with cash-based payments, payroll, procurement, inventory, accounts receivable, accounts payable, financial reporting and access to accounting systems.

Design of Effective Internal Controls.

The first step organizations should take is to determine which controls to implement are to identify what the most crucial risks are. Management can review key business processes and consider what could go wrong, what is the likelihood of the event happening, what is the potential impact if it happens and what controls do they have in place to address the risk in their business? Next, it is important to identify if the control already in place is of the preventive type, detective type, corrective type or a mixture of these types. The duties of who does what, who reviews it, how often it happens and what evidence is required to be kept should be clearly defined so that the employees know what they are responsible for. In addition, documentation of controls should be written in a language that the employees can understand and adhere to. Technology can augment this structure with automated approvals, access controls, audit trails, exception reporting and ongoing monitoring. Nevertheless, technology should be used to complement the sound processes and not to supplant the thoughtful management! Automated controls need to be reviewed in a timely manner to make sure they are set up and used properly and continue to be suitable for the organization’s evolving needs.

Employees and Management take a vital part in this Process.

Accountants and auditors are not alone in having responsibility for internal controls. Different levels of employees have different influences on working of controls. Staff should be aware of the procedures to which they are subject to the various aspects of their work, and how to report any suspicious transactions, errors, conflict of interest or control failure. Managers need to set standards, keep standards being met, investigate why standards are not being met and ensure that there is sufficient capacity to ensure the control activities are carried out. Senior leaders play a particular role as staffs are likely to model their behavior on those of senior staff. If managers routinely ignore the controls for convenience, employees may think that the controls are not required. However, when leaders routinely adhere to procedures and act appropriately for violations, leaders establish a norm of accountability. It is also a good practice for organizations to make it safe for employees to come forward should any issues be raised without the threat of reprisal. However, in addition to policies and software, ethical behavior, effective communication, proper supervision and a willingness to investigate issues openly are key factors to a strong internal control environment.

Internal Controls and Fraud Prevention

One of the primary purposes that organizations put in place internal controls is to help prevent fraud, but internal controls should not be interpreted as a sure-fire way to prevent fraud. Collusion between staff, override by management, stolen credentials, falsified documents, record manipulation or exploitation of a vulnerability not previously identified are all examples of fraud. Fraudulent activity can be made more difficult with preventive controls, increased chances for detection with detective controls and response with corrective controls. For instance, segregation of duties can minimize the chance of one employee to start up and cover up an unauthorized transaction. Unusual activity can be detected using transaction monitoring and access review can be used to ascertain what has occurred following an alert. This can help the organization reinforce the impacted process. This mix highlights the need for fraud risk management to be seen as a process or cycle of preventing, detecting, responding to, and improving on fraud, not just a compliance check.

Common Mistakes that an Organization should avoid

A frequent error is putting in controls without first knowing the hazards which the control is designed to address. This can lead to time consuming procedures and not controlling the important risks. The other error is overlooking controls when there are business process changes. A business can switch to a different system of bookkeeping, hire more staff, expand its presence in new regions or embrace new payment techniques without updating the procedures for an old operating system. Failing to have clear responsibilities are another cause of failure in controls. Workers might not be aware of the exceptions or transaction approval required by their manager or supervisor. The second issue is when organizations conduct a reconciliation/review only in accordance with policy but fail to investigate any unusual results. Last but not least, management might be more oriented toward the prevention of problems than detection and correction. Maintaining effective control systems will need to involve regular testing, evidence, investigations and continual improvement to ensure weaknesses that become identified are addressed before they develop into bigger issues.

Conclusion

The purpose of preventive, detective and corrective controls in an organization’s internal control framework are complementary but different. Preventative controls attempt to prevent errors, frauds and unauthorized activities from occurring. Detective controls detect issues that are not prevented, corrective controls address issues and repair the damage created by the issues and corrects processes to decrease the likelihood of future issues. None of the three types of constraints is alone enough to guarantee it. They are tied together in a strong organization based on the financial, operational, technological and compliance risk of the activities they conduct. The controls should be regularly reviewed to determine if they are effective and if responsibilities are still clear, and if any new risks are present that need new controls. Having a well-rounded system that avoids losses and identifies issues promptly, while addressing weaknesses efficiently and effectively, can boost the precision of financial reporting, protect assets, enhance accountability, combat fraud risks, and provide a more stable basis for long-term success.

Get more well researched information about Preventive vs Detective vs Corrective Controls here.

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
0
Would love your thoughts, please comment.x
()
x