Skip to content

Audit support

Internal controls documentation

Short answer

Internal controls documentation from Finbryn writes down how your financial close, purchase ledger, sales ledger and payroll processes actually run: who approves what, how often, and where duties are split. Our accounting team builds the control matrix and flags gaps in plain language; any formal opinion on those controls comes from a registered auditor.

Auditor request list

Illustrative client · August 2026

GBP

  1. Trial balance and general ledger exportDone
  2. Bank confirmations and statementsDone
  3. Receivables and payables listingsDone
  4. Fixed asset register with additionsIn progress
  5. Accruals and prepayments supportNext

Illustrative. An example of the document, not a client's figures.

The question behind the question

When a lender or a registered auditor raises internal controls, they are rarely asking whether your business has any. They want one specific thing demonstrated: who signed off last month's biggest payment run, who reconciled the account it left from, and whether one person could have raised, approved and reconciled that same entry without a second pair of eyes. A gap that only exists in someone's memory is a gap they will surface for you if you have not already found it yourself.

Turning a process into a document

Our route into this is to sit alongside your team through a full financial close, then through the purchase ledger, the sales ledger and payroll as they actually run day to day, not the version described in a policy nobody has reread in years. What comes out is a narrative of the real process and a control matrix built from it: each control named, an owner attached, a frequency attached.

Where small teams run thin

A common pattern in a lean UK finance function is one person holding three roles at once: setting up a new supplier, releasing the payment to them, and reconciling the account afterwards. We name that concentration plainly and propose something workable, commonly a second sign-off above an agreed value, rather than adding a line to a checklist nobody will follow.

The boundary we keep

Writing the process down is not the same as certifying it works, or giving any opinion that it operates effectively across a period. Where that judgement is required, it belongs to a registered auditor operating under the Companies Act 2006 and their Recognised Supervisory Body's standards, never to us.

Companies later facing a service organisation examination for an overseas customer tend to reuse this matrix inside SOC readiness bookkeeping, and an auditor asking for evidence of a specific control usually finds it inside working papers. We keep every version dated, since a control document nobody updates goes stale the moment a role or a system changes underneath it.

Questions

Frequently asked questions: Internal controls documentation

Is this required for a small UK company?

No regulation requires it at small scale, but a lender, investor or first-time auditor often expects to see it, and it is far easier to write down before a problem forces the question.

Will you tell us if a control is missing, even if it is uncomfortable?

Yes. A gap we do not flag is a gap your auditor or funder will find instead, so we write it down plainly along with a workable fix.

Do you implement the controls, or just document them?

We document the process and matrix, and help your team design a practical fix for a gap. Implementing a new approval workflow inside your systems is done together with whoever owns that software.

How often should controls documentation be refreshed?

Annually at minimum, or sooner if your approval chain, software stack or headcount changes materially, since documentation describing a process you no longer follow is worse than no documentation at all. We flag when a described control no longer matches what is actually happening.

Does this cover IT and access controls, or only financial process controls?

The core documentation focuses on financial process controls, such as payment approval and reconciliation review. Access and IT controls are covered at a summary level where they affect financial reporting, but a full IT security review sits outside this service and would need a dedicated specialist.

Is this a certification of our controls?

No. We document how controls actually work today and flag gaps; any formal attestation or opinion comes from an independent, credentialed auditor you engage separately.

Do we need this if we are a small company?

Even a lean team benefits from writing down who approves what. It shortens the questions an auditor or lender asks and reduces the risk of a single person controlling a whole process.

How do we get started with internal controls documentation?

Getting started with internal controls documentation begins with a short review of your current records and software access. Once that is done we confirm scope and timing in writing, and ongoing work begins on the schedule agreed with you.

What if our records for internal controls documentation are not up to date?

If your records are behind, we scope a catch-up first so internal controls documentation starts from a clean, reconciled base. That catch-up is priced and timed separately from the ongoing engagement, so you always know what each part costs.

Next step

Talk to the team that would run your books

A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.