Skip to content

Audit support

Internal controls documentation

Short answer

Internal controls documentation from Finbryn sets out how your financial close, purchase ledger, sales ledger and payroll actually run across a Riyadh, Jeddah or Dammam operation: who approves what, how often, and where duties are split. Our accounting team builds the control matrix and names gaps in plain language.

Auditor request list

Illustrative client · August 2026

SAR

  1. Trial balance and general ledger exportDone
  2. Bank confirmations and statementsDone
  3. Receivables and payables listingsDone
  4. Fixed asset register with additionsIn progress
  5. Accruals and prepayments supportNext

Illustrative. An example of the document, not a client's figures.

Starting from the payroll cycle, not a policy binder

We start most engagements by watching an actual payroll run rather than reading a policy document. Who enters a new starter into the system, who approves the run before it goes through the Wage Protection Program via Mudad, and who separately checks the GOSI contribution matches, are three roles that frequently sit with one person in a lean Saudi finance team, whether the company is Saudi-owned or MISA-licensed and foreign-owned.

Turning the walkthrough into a matrix

From that walkthrough, and equivalent ones for the financial close, the purchase ledger and the sales ledger, we build a control matrix: each control named, an owner attached, a frequency attached, and a plain note on how it is evidenced. The document describes what actually happens today, not an aspirational process nobody follows.

Naming a concentration risk directly

Where one person can both raise a payment and approve it, we say so in the matrix rather than softening it into a generic recommendation, and propose something workable, most often a second sign-off above an agreed value, rather than a rule that adds friction to every transaction regardless of size.

A living document, not a one-time report

A control document goes stale the moment a role changes, a new system replaces an old one, or a company grows past the point where one person can reasonably hold three responsibilities. We date every version and revisit the matrix when your team tells us something in the process has changed, rather than waiting for the next audit cycle to catch it.

Where documentation stops and audit begins

Writing down how a control works is not the same as certifying that it operated effectively throughout a period. That certification, where a customer or regulator asks for one, sits with a SOCPA-licensed audit firm. A company later facing a service organisation examination for a US or European customer typically reuses this same matrix as the starting point for SOC readiness bookkeeping, and an auditor asking for evidence of a specific control usually finds it referenced inside working papers.

Questions

Frequently asked questions: Internal controls documentation

Is this required for a small Saudi company?

No regulation requires it at small scale, but a bank, investor or first-time auditor often expects to see it, and it is far easier to write down before a problem forces the question.

Will you tell us if a control is missing, even if it is uncomfortable?

Yes. A gap we do not flag is a gap your auditor or lender will find instead, so we write it down plainly along with a workable fix.

Do you implement the controls, or just document them?

We document the process and matrix, and help your team design a practical fix for a gap. Building a new approval workflow inside your systems is done together with whoever owns that software.

Does the matrix cover WPS submissions through Mudad specifically?

Yes. It names who sets up the payroll run, who approves it before submission, and who separately reconciles it against GOSI contributions. Making the actual WPS submission stays with whoever administers it inside your business.

Is this a certification of our controls?

No. We document how controls actually work today and flag gaps; any formal attestation or opinion comes from an independent, credentialed auditor you engage separately.

Do we need this if we are a small company?

Even a lean team benefits from writing down who approves what. It shortens the questions an auditor or lender asks and reduces the risk of a single person controlling a whole process.

How do we get started with internal controls documentation?

Getting started with internal controls documentation begins with a short review of your current records and software access. Once that is done we confirm scope and timing in writing, and ongoing work begins on the schedule agreed with you.

What if our records for internal controls documentation are not up to date?

If your records are behind, we scope a catch-up first so internal controls documentation starts from a clean, reconciled base. That catch-up is priced and timed separately from the ongoing engagement, so you always know what each part costs.

Next step

Talk to the team that would run your books

A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.