Audit support
Internal controls documentation
Internal controls documentation writes down how your QuickBooks Online, Xero or NetSuite close, AP, AR and payroll cycles actually run today: who approves a payment, who reconciles an account, and how often. Finbryn's team builds the control matrix, flags segregation-of-duties gaps in plain language, and hands you a version-controlled document, while any formal opinion on control effectiveness stays with a licensed auditor.
Auditor request list
Illustrative client ยท August 2026
USD
- Trial balance and general ledger exportDone
- Bank confirmations and statementsDone
- Receivables and payables listingsDone
- Fixed asset register with additionsIn progress
- Accruals and prepayments supportNext
Illustrative. An example of the document, not a client's figures.
An auditor, a bank, or a new investor rarely asks in the abstract whether your company has internal controls. They ask a specific question: who approved this $40,000 wire, who reconciled the account it left, and could the same person have done both. If the true answer only lives in one controller's head, that gap surfaces at the worst possible time, usually mid-fieldwork or mid-diligence.
We start by walking your finance team through the financial close, accounts payable, accounts receivable, and payroll cycles as they run today, not as a policy document says they should run. That distinction matters. A lot of small and mid-sized companies have a controls memo from three years and two systems ago that describes a process nobody follows anymore. We document the current state, then build a control matrix that lists each control, its owner, how often it operates, and what evidence it leaves behind.
Segregation of duties gets specific attention because it is where lean teams get exposed. A five-person finance team often has one person who can add a vendor, approve the payment to that vendor, and reconcile the bank account the payment cleared through. That is not a hypothetical fraud scenario, it is a structural gap that shows up in almost every first-time audit or SOC 2 readiness assessment we see. Where a true three-way split is not realistic given headcount, we design a compensating control instead, such as a second approver above a dollar threshold or a monthly exception review, so the gap is managed rather than ignored.
The output is built around the COSO Internal Control, Integrated Framework, the model most US auditors and lenders reference, covering control environment, risk assessment, control activities, information and communication, and monitoring. We are not issuing a COSO attestation. We are using the same structure your auditor already thinks in, so the document reads as familiar rather than as a translation exercise during fieldwork.
This work sits upstream of two other things you likely need eventually. If you are preparing for a service-organization examination, the control matrix becomes the backbone of your SOC readiness bookkeeping evidence. If an auditor asks to see how a specific control operated during the year, the working papers we or your team prepare cross-reference directly back to this document instead of starting from a blank page.
Nothing here is a certification, an opinion, or an attestation on whether your controls operated effectively over any period. That determination, where a formal one is needed such as under SOC 2 or an integrated audit under PCAOB standards, comes only from a licensed, independent audit firm you engage separately. Our job is to make sure that firm is looking at an accurate, current picture of how the money actually moves through your business, and that your own team understands it well enough to answer questions about it without us in the room.
What is included
The core deliverable is a control matrix: one row per control, columns for the process it belongs to (close, AP, AR, payroll), the control owner by name or role, the frequency (transaction-level, daily, monthly, quarterly), the type of evidence it leaves (a sign-off email, a system approval log, a reconciliation tie-out), and a plain-language description of what actually happens. Alongside the matrix, each major cycle gets a short process narrative, typically one to two pages, that a new hire or an outside reviewer could read and understand without a walkthrough call.
We also produce a segregation-of-duties review specific to your access setup in QuickBooks Online, Xero, NetSuite, or Bill.com, showing who has create, approve, and reconcile permissions across vendor records, bill payment, and bank reconciliation. Where one person holds an incompatible combination, we note it against the control matrix rather than leaving it as a separate, easy-to-ignore memo.
How the process works
We open with a scoping call to understand your current systems, headcount, and any existing policy documents, even outdated ones, since they show what the business intended even if practice has drifted. Interviews with whoever actually performs each step follow: the person who codes a bill, the person who approves it, the person who reconciles the account. We do not rely solely on a manager's description of how the process runs, because that description and the actual practice diverge more often than either side expects.
A draft matrix and narrative set goes back to your team for correction, since only the people doing the work can confirm we captured it accurately. After that review round, we finalize the document, log it with a version number and date, and walk your controller or CFO through the gaps we flagged along with a proposed fix for each one, sized to your headcount rather than copied from a Fortune 500 controls library.
Who this is for
Companies heading into a first external audit, a Series A or later diligence process, a bank covenant review, or SOC 2 readiness are the most common fit, because each of those counterparties will ask the same underlying question in a different wrapper. Nonprofits preparing for a single audit under 2 CFR 200 also need this, since the control environment around federal award spending gets specific scrutiny in that context.
It is also worth doing before any of those triggers exist. A company with ten to thirty employees and no written controls is usually fine day to day. The risk shows up the first time someone new joins finance, a system gets replaced, or a dollar figure moves that nobody can immediately explain, and there is no document to point to.
Common problems we fix
The most frequent finding across engagements is one person holding vendor-create, payment-approval, and bank-reconciliation access at the same time, usually because the company started with one bookkeeper and never revisited access as headcount grew. Close behind that is a manual journal entry process where the person recording an adjusting entry also approves it, with no second reviewer before it posts to the general ledger.
Payroll is another recurring gap: whoever runs payroll in Gusto or ADP frequently also has the ability to change their own pay rate or add themselves as a new employee, without a compensating review catching that specific combination. We also see stale user access, former employees or contractors who still have login credentials to the accounting system months after they left, which is one of the easiest findings for an auditor or examiner to flag and one of the cheapest to fix.
Software and integrations
We document controls inside whatever system you already run: QuickBooks Online or Xero for the general ledger, Bill.com for AP approval routing and vendor payment workflows, and Excel for the matrix and narrative deliverables themselves, since most auditors expect that format and it stays portable regardless of which accounting platform you use next. Where payroll runs through Gusto, ADP, Rippling, or Deel, we review the access and approval settings inside that specific platform rather than assuming a generic payroll control applies uniformly.
Nothing about your existing subscriptions changes. We work inside your login, under access you grant and can revoke, and the finished document belongs to you, not to a proprietary platform we control.
What it costs
This engagement is scoped separately from ongoing monthly bookkeeping because the work is front-loaded: interviews, drafting, and a review round happen over a defined window rather than every month. Cost depends mainly on how many process cycles need documentation, revenue, purchasing, payroll and cash disbursement are the most common, and how many systems and approval steps sit inside each one. A single-entity business running one accounting platform with straightforward approvals costs less to document than a multi-location business with several systems, manual sign-off steps, and no consistent approval trail to start from. See the pricing note below for how to get an exact figure once we understand your process count.
How we measure quality
A finished control matrix should let someone outside your finance team, an auditor, a lender's credit analyst, or a new controller, answer three questions without a follow-up call: who approves what, how often each control runs, and what evidence proves it happened. If a reviewer still needs to ask 'but who actually does this in practice,' the narrative was not specific enough, and we treat that as a defect to fix, not a normal caveat.
We also track how many gaps flagged in one engagement recur unresolved at the next review cycle. A gap that stays open for a year despite being written down plainly is a signal the fix we proposed did not fit how the team actually works, and we revise the recommendation rather than repeat it.
How we work
The process
- 1
Scoping call
Review current systems, headcount, access setup, and any existing policy documents, even outdated ones, to understand intended versus actual practice.
- 2
Process interviews
Talk to the person who actually performs each step in close, AP, AR, and payroll, not just their manager's description of the process.
- 3
Draft the matrix and narratives
Build the control matrix and one-to-two-page narrative per cycle, mapped to the five COSO components.
- 4
Segregation-of-duties review
Pull actual system permissions from QuickBooks, Xero, NetSuite, or Bill.com and flag any incompatible access combination by name.
- 5
Team review round
Send the draft back to the people interviewed to correct anything that does not match how they actually work day to day.
- 6
Finalize and version
Lock the reviewed document, log the version and date, and walk your controller or CFO through each flagged gap with a proposed fix.
- 7
Ongoing updates
Revise the document when a role changes, a system is replaced, or a new process is added, so it stays current between audit cycles.
Internal controls documentation
Common problems we fix
The problem
How we fix it
- One person can create a vendor, approve the payment and reconcile the accountAdd a second approver above a set dollar threshold or a monthly exception review as a compensating control.
- A manual journal entry is recorded and posted by the same person with no second reviewRequire a named reviewer to approve any entry above a materiality threshold before it posts.
- Whoever runs payroll can also change their own pay rate or add themselves as an employeeRoute self-service payroll changes through a second approver inside Gusto or ADP's permission settings.
- Former employees or contractors still have active logins to the accounting systemAdd offboarding access removal as its own control, checked on a fixed monthly cadence rather than left to memory.
- A controls memo describes a process the company stopped following years agoReplace the stale document with a narrative built from current interviews, then version and date it going forward.
Pricing
Internal controls documentation is scoped once we know how many process cycles and systems are in play; it runs separately from ongoing monthly bookkeeping. Current published tiers and add-ons are on the /us/pricing rate card, and your exact fee for this engagement is confirmed in writing before work starts.
Internal controls documentation
Glossary
- Segregation of duties
- Splitting a process across more than one person so no single individual can both create and approve the same transaction.
- Control matrix
- A document listing each financial control, who owns it, how often it runs, and what evidence proves it happened.
- COSO framework
- The Internal Control, Integrated Framework used by most US auditors, covering control environment, risk assessment, control activities, information and communication, and monitoring.
- Compensating control
- An alternative safeguard, such as a second approver or periodic review, used when full segregation of duties is not realistic given headcount.
- Control narrative
- A written, plain-language description of how a specific financial process actually runs today, used alongside the control matrix.
Questions
Frequently asked questions: Internal controls documentation
Is this required for a small business?
No regulation requires it at small scale, but a lender, investor or first-time auditor often expects to see it. Writing it down before someone asks for it is far cheaper than reconstructing it under a deadline.
Will you tell us if a control is missing, even if it is uncomfortable?
Yes. A gap we do not flag is a gap your auditor, lender or funder will find instead, so we write it down plainly along with a workable, right-sized fix rather than a generic checklist item.
Do you implement the controls, or just document them?
We document the process, build the matrix, and design a practical fix for each gap alongside your team. Implementing a new approval workflow inside your own systems, such as a new Bill.com approval tier, is done together with whoever owns that software.
How is a control matrix different from a policy manual?
A policy manual describes how a process should ideally work. A control matrix documents how it actually runs today, with a named owner, a frequency, and evidence that proves it happened, which is what an auditor or examiner actually tests against.
How long does the first version take to build?
Most engagements run four to eight weeks from the first interview to a finalized, version-one document, depending on how many process cycles and systems are in scope and how quickly your team can review drafts.
What does internal controls documentation actually include, month to month?
Internal controls documentation covers process narratives for the financial close, AP, AR and payroll cycles, along with a control matrix listing each control, its owner and how often it runs. The work runs inside Excel, QuickBooks Online, Xero or Bill.com, the file stays under your own subscription, and a senior reviewer checks the output before it reaches you.
What access do you need to start?
View or edit access to Excel, QuickBooks Online, Xero or Bill.com is enough to begin. Nothing about your existing subscription or login changes on our side, and any additional access needed for a specific deliverable is agreed with you first and set out in your engagement letter.
Does this help if we are heading into SOC 2 readiness next?
Yes. The control matrix built here becomes the starting point for SOC readiness bookkeeping, since much of the financial evidence a SOC examiner requests traces back to a control that needs to be documented and evidenced consistently first.
Is this a certification of our controls?
No. We document how controls actually work today and flag gaps; any formal attestation or opinion comes from an independent, credentialed auditor you engage separately.
Do we need this if we are a small company?
Even a lean team benefits from writing down who approves what. It shortens the questions an auditor or lender asks and reduces the risk of a single person controlling a whole process.
How do we get started with internal controls documentation?
Getting started with internal controls documentation begins with a short review of your current records and software access. Once that is done we confirm scope and timing in writing, and ongoing work begins on the schedule agreed with you.
What if our records for internal controls documentation are not up to date?
If your records are behind, we scope a catch-up first so internal controls documentation starts from a clean, reconciled base. That catch-up is priced and timed separately from the ongoing engagement, so you always know what each part costs.
Related services
- Audit supportWorking paper preparationSupporting schedules and reconciliations built the way an auditor expects to see them, cross-referenced to the trial balance, so review comments come back with fewer open questions.
- Audit supportSOC readiness bookkeepingFinancial recordkeeping and evidence-gathering support for companies preparing for a service-organization examination, keeping the accounting-side documentation consistent while the technical control work is led by your security team or examiner.
- Audit supportAudit-ready booksMonthly and year-end books maintained with the support and schedules an external auditor expects to see on day one, so fieldwork starts without a scramble to reconstruct records.
Industries
- Startups and VC-backed companiesBookkeeping and reporting for early-stage, venture-backed companies watching burn, runway and investor reporting closely.
- SaaSBookkeeping and reporting for subscription software businesses tracking recurring revenue, deferred revenue and burn.
- NonprofitsFund accounting for nonprofits tracking restricted and unrestricted funds, grants and donor reporting.
- Professional servicesBookkeeping for professional service firms such as engineering, architecture and IT consulting billing clients by project or retainer.
Related guides
- BookkeepingHow to Design a Chart of Accounts (With SaaS and Ecommerce Examples)How to number and structure a chart of accounts, with worked SaaS and ecommerce examples and the mistakes that force a costly rebuild later.
- BookkeepingThe Month-End Close Checklist: Day by Day, Close by Business Day 5A day-by-day month-end close checklist covering reconciliations, accruals, deferred revenue and review, so your books close by business day 5 every month.
- BookkeepingHow to Switch Bookkeepers Without Losing Your BooksA practical checklist for changing bookkeepers safely: what to demand in an exit pack, who owns your QuickBooks or Xero file, and how to time the move.
Sources
- [1]COSO Internal Control, Integrated Framework overview, September 2026
- [2]Baker Tilly on the COSO internal control framework, September 2026
- [3]Guzman Gray, The Five Components of Internal Control Explained, September 2026
Next step
Talk to the team that would run your books
A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.
Need this in writing? Download a one to two page scope sheet for Internal controls documentation: what is included, the process, and where pricing lives.
Download the scope sheet