Audit support
Internal controls documentation
Internal controls documentation from Finbryn sets out how your financial close, purchase ledger, sales ledger and payroll actually run across a Riyadh, Jeddah or Dammam operation: who approves what, how often, and where duties are split. Our accounting team builds the control matrix and names gaps in plain language.
Auditor request list
Illustrative client · August 2026
SAR
- Trial balance and general ledger exportDone
- Bank confirmations and statementsDone
- Receivables and payables listingsDone
- Fixed asset register with additionsIn progress
- Accruals and prepayments supportNext
Illustrative. An example of the document, not a client's figures.
Starting from the payroll cycle, not a policy binder
We start most engagements by watching an actual payroll run rather than reading a policy document. Who enters a new starter into the system, who approves the run before it goes through the Wage Protection Program via Mudad, and who separately checks the GOSI contribution matches, are three roles that frequently sit with one person in a lean Saudi finance team, whether the company is Saudi-owned or MISA-licensed and foreign-owned.
Turning the walkthrough into a matrix
From that walkthrough, and equivalent ones for the financial close, the purchase ledger and the sales ledger, we build a control matrix: each control named, an owner attached, a frequency attached, and a plain note on how it is evidenced. The document describes what actually happens today, not an aspirational process nobody follows.
Naming a concentration risk directly
Where one person can both raise a payment and approve it, we say so in the matrix rather than softening it into a generic recommendation, and propose something workable, most often a second sign-off above an agreed value, rather than a rule that adds friction to every transaction regardless of size.
A living document, not a one-time report
A control document goes stale the moment a role changes, a new system replaces an old one, or a company grows past the point where one person can reasonably hold three responsibilities. We date every version and revisit the matrix when your team tells us something in the process has changed, rather than waiting for the next audit cycle to catch it.
Where documentation stops and audit begins
Writing down how a control works is not the same as certifying that it operated effectively throughout a period. That certification, where a customer or regulator asks for one, sits with a SOCPA-licensed audit firm. A company later facing a service organisation examination for a US or European customer typically reuses this same matrix as the starting point for SOC readiness bookkeeping, and an auditor asking for evidence of a specific control usually finds it referenced inside working papers.
Questions
Frequently asked questions: Internal controls documentation
Is this required for a small Saudi company?
No regulation requires it at small scale, but a bank, investor or first-time auditor often expects to see it, and it is far easier to write down before a problem forces the question.
Will you tell us if a control is missing, even if it is uncomfortable?
Yes. A gap we do not flag is a gap your auditor or lender will find instead, so we write it down plainly along with a workable fix.
Do you implement the controls, or just document them?
We document the process and matrix, and help your team design a practical fix for a gap. Building a new approval workflow inside your systems is done together with whoever owns that software.
Does the matrix cover WPS submissions through Mudad specifically?
Yes. It names who sets up the payroll run, who approves it before submission, and who separately reconciles it against GOSI contributions. Making the actual WPS submission stays with whoever administers it inside your business.
Is this a certification of our controls?
No. We document how controls actually work today and flag gaps; any formal attestation or opinion comes from an independent, credentialed auditor you engage separately.
Do we need this if we are a small company?
Even a lean team benefits from writing down who approves what. It shortens the questions an auditor or lender asks and reduces the risk of a single person controlling a whole process.
How do we get started with internal controls documentation?
Getting started with internal controls documentation begins with a short review of your current records and software access. Once that is done we confirm scope and timing in writing, and ongoing work begins on the schedule agreed with you.
What if our records for internal controls documentation are not up to date?
If your records are behind, we scope a catch-up first so internal controls documentation starts from a clean, reconciled base. That catch-up is priced and timed separately from the ongoing engagement, so you always know what each part costs.
Related services
- Audit supportWorking paper preparationSupporting schedules and reconciliations built the way an auditor expects to see them, cross-referenced to the trial balance, so review comments come back with fewer open questions.
- Audit supportSOC readiness bookkeepingFinancial recordkeeping and evidence-gathering support for companies preparing for a service-organization examination, keeping the accounting-side documentation consistent while the technical control work is led by your security team or examiner.
Industries
- Startups and VC-backed companiesBookkeeping and reporting for early-stage, venture-backed companies watching burn, runway and investor reporting closely.
- Professional servicesBookkeeping for professional service firms such as engineering, architecture and IT consulting billing clients by project or retainer.
Next step
Talk to the team that would run your books
A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.