Skip to content

Audit support

Internal controls documentation

Short answer

Internal controls documentation writes down how your QuickBooks Online, Xero or NetSuite close, AP, AR and payroll cycles actually run today: who approves a payment, who reconciles an account, and how often. Finbryn's team builds the control matrix, flags segregation-of-duties gaps in plain language, and hands you a version-controlled document, while any formal opinion on control effectiveness stays with a licensed auditor.

Auditor request list

Illustrative client ยท August 2026

USD

  1. Trial balance and general ledger exportDone
  2. Bank confirmations and statementsDone
  3. Receivables and payables listingsDone
  4. Fixed asset register with additionsIn progress
  5. Accruals and prepayments supportNext

Illustrative. An example of the document, not a client's figures.

An auditor, a bank, or a new investor rarely asks in the abstract whether your company has internal controls. They ask a specific question: who approved this $40,000 wire, who reconciled the account it left, and could the same person have done both. If the true answer only lives in one controller's head, that gap surfaces at the worst possible time, usually mid-fieldwork or mid-diligence.

We start by walking your finance team through the financial close, accounts payable, accounts receivable, and payroll cycles as they run today, not as a policy document says they should run. That distinction matters. A lot of small and mid-sized companies have a controls memo from three years and two systems ago that describes a process nobody follows anymore. We document the current state, then build a control matrix that lists each control, its owner, how often it operates, and what evidence it leaves behind.

Segregation of duties gets specific attention because it is where lean teams get exposed. A five-person finance team often has one person who can add a vendor, approve the payment to that vendor, and reconcile the bank account the payment cleared through. That is not a hypothetical fraud scenario, it is a structural gap that shows up in almost every first-time audit or SOC 2 readiness assessment we see. Where a true three-way split is not realistic given headcount, we design a compensating control instead, such as a second approver above a dollar threshold or a monthly exception review, so the gap is managed rather than ignored.

The output is built around the COSO Internal Control, Integrated Framework, the model most US auditors and lenders reference, covering control environment, risk assessment, control activities, information and communication, and monitoring. We are not issuing a COSO attestation. We are using the same structure your auditor already thinks in, so the document reads as familiar rather than as a translation exercise during fieldwork.

This work sits upstream of two other things you likely need eventually. If you are preparing for a service-organization examination, the control matrix becomes the backbone of your SOC readiness bookkeeping evidence. If an auditor asks to see how a specific control operated during the year, the working papers we or your team prepare cross-reference directly back to this document instead of starting from a blank page.

Nothing here is a certification, an opinion, or an attestation on whether your controls operated effectively over any period. That determination, where a formal one is needed such as under SOC 2 or an integrated audit under PCAOB standards, comes only from a licensed, independent audit firm you engage separately. Our job is to make sure that firm is looking at an accurate, current picture of how the money actually moves through your business, and that your own team understands it well enough to answer questions about it without us in the room.

What is included

The core deliverable is a control matrix: one row per control, columns for the process it belongs to (close, AP, AR, payroll), the control owner by name or role, the frequency (transaction-level, daily, monthly, quarterly), the type of evidence it leaves (a sign-off email, a system approval log, a reconciliation tie-out), and a plain-language description of what actually happens. Alongside the matrix, each major cycle gets a short process narrative, typically one to two pages, that a new hire or an outside reviewer could read and understand without a walkthrough call.

We also produce a segregation-of-duties review specific to your access setup in QuickBooks Online, Xero, NetSuite, or Bill.com, showing who has create, approve, and reconcile permissions across vendor records, bill payment, and bank reconciliation. Where one person holds an incompatible combination, we note it against the control matrix rather than leaving it as a separate, easy-to-ignore memo.

How the process works

We open with a scoping call to understand your current systems, headcount, and any existing policy documents, even outdated ones, since they show what the business intended even if practice has drifted. Interviews with whoever actually performs each step follow: the person who codes a bill, the person who approves it, the person who reconciles the account. We do not rely solely on a manager's description of how the process runs, because that description and the actual practice diverge more often than either side expects.

A draft matrix and narrative set goes back to your team for correction, since only the people doing the work can confirm we captured it accurately. After that review round, we finalize the document, log it with a version number and date, and walk your controller or CFO through the gaps we flagged along with a proposed fix for each one, sized to your headcount rather than copied from a Fortune 500 controls library.

Who this is for

Companies heading into a first external audit, a Series A or later diligence process, a bank covenant review, or SOC 2 readiness are the most common fit, because each of those counterparties will ask the same underlying question in a different wrapper. Nonprofits preparing for a single audit under 2 CFR 200 also need this, since the control environment around federal award spending gets specific scrutiny in that context.

It is also worth doing before any of those triggers exist. A company with ten to thirty employees and no written controls is usually fine day to day. The risk shows up the first time someone new joins finance, a system gets replaced, or a dollar figure moves that nobody can immediately explain, and there is no document to point to.

Common problems we fix

The most frequent finding across engagements is one person holding vendor-create, payment-approval, and bank-reconciliation access at the same time, usually because the company started with one bookkeeper and never revisited access as headcount grew. Close behind that is a manual journal entry process where the person recording an adjusting entry also approves it, with no second reviewer before it posts to the general ledger.

Payroll is another recurring gap: whoever runs payroll in Gusto or ADP frequently also has the ability to change their own pay rate or add themselves as a new employee, without a compensating review catching that specific combination. We also see stale user access, former employees or contractors who still have login credentials to the accounting system months after they left, which is one of the easiest findings for an auditor or examiner to flag and one of the cheapest to fix.

Software and integrations

We document controls inside whatever system you already run: QuickBooks Online or Xero for the general ledger, Bill.com for AP approval routing and vendor payment workflows, and Excel for the matrix and narrative deliverables themselves, since most auditors expect that format and it stays portable regardless of which accounting platform you use next. Where payroll runs through Gusto, ADP, Rippling, or Deel, we review the access and approval settings inside that specific platform rather than assuming a generic payroll control applies uniformly.

Nothing about your existing subscriptions changes. We work inside your login, under access you grant and can revoke, and the finished document belongs to you, not to a proprietary platform we control.

What it costs

This engagement is scoped separately from ongoing monthly bookkeeping because the work is front-loaded: interviews, drafting, and a review round happen over a defined window rather than every month. Cost depends mainly on how many process cycles need documentation, revenue, purchasing, payroll and cash disbursement are the most common, and how many systems and approval steps sit inside each one. A single-entity business running one accounting platform with straightforward approvals costs less to document than a multi-location business with several systems, manual sign-off steps, and no consistent approval trail to start from. See the pricing note below for how to get an exact figure once we understand your process count.

How we measure quality

A finished control matrix should let someone outside your finance team, an auditor, a lender's credit analyst, or a new controller, answer three questions without a follow-up call: who approves what, how often each control runs, and what evidence proves it happened. If a reviewer still needs to ask 'but who actually does this in practice,' the narrative was not specific enough, and we treat that as a defect to fix, not a normal caveat.

We also track how many gaps flagged in one engagement recur unresolved at the next review cycle. A gap that stays open for a year despite being written down plainly is a signal the fix we proposed did not fit how the team actually works, and we revise the recommendation rather than repeat it.

How we work

The process

  1. 1

    Scoping call

    Review current systems, headcount, access setup, and any existing policy documents, even outdated ones, to understand intended versus actual practice.

  2. 2

    Process interviews

    Talk to the person who actually performs each step in close, AP, AR, and payroll, not just their manager's description of the process.

  3. 3

    Draft the matrix and narratives

    Build the control matrix and one-to-two-page narrative per cycle, mapped to the five COSO components.

  4. 4

    Segregation-of-duties review

    Pull actual system permissions from QuickBooks, Xero, NetSuite, or Bill.com and flag any incompatible access combination by name.

  5. 5

    Team review round

    Send the draft back to the people interviewed to correct anything that does not match how they actually work day to day.

  6. 6

    Finalize and version

    Lock the reviewed document, log the version and date, and walk your controller or CFO through each flagged gap with a proposed fix.

  7. 7

    Ongoing updates

    Revise the document when a role changes, a system is replaced, or a new process is added, so it stays current between audit cycles.

Internal controls documentation

Common problems we fix

  • One person can create a vendor, approve the payment and reconcile the account
    Add a second approver above a set dollar threshold or a monthly exception review as a compensating control.
  • A manual journal entry is recorded and posted by the same person with no second review
    Require a named reviewer to approve any entry above a materiality threshold before it posts.
  • Whoever runs payroll can also change their own pay rate or add themselves as an employee
    Route self-service payroll changes through a second approver inside Gusto or ADP's permission settings.
  • Former employees or contractors still have active logins to the accounting system
    Add offboarding access removal as its own control, checked on a fixed monthly cadence rather than left to memory.
  • A controls memo describes a process the company stopped following years ago
    Replace the stale document with a narrative built from current interviews, then version and date it going forward.

Pricing

Internal controls documentation is scoped once we know how many process cycles and systems are in play; it runs separately from ongoing monthly bookkeeping. Current published tiers and add-ons are on the /us/pricing rate card, and your exact fee for this engagement is confirmed in writing before work starts.

See pricing

Internal controls documentation

Glossary

Segregation of duties
Splitting a process across more than one person so no single individual can both create and approve the same transaction.
Control matrix
A document listing each financial control, who owns it, how often it runs, and what evidence proves it happened.
COSO framework
The Internal Control, Integrated Framework used by most US auditors, covering control environment, risk assessment, control activities, information and communication, and monitoring.
Compensating control
An alternative safeguard, such as a second approver or periodic review, used when full segregation of duties is not realistic given headcount.
Control narrative
A written, plain-language description of how a specific financial process actually runs today, used alongside the control matrix.

Questions

Frequently asked questions: Internal controls documentation

Is this required for a small business?

No regulation requires it at small scale, but a lender, investor or first-time auditor often expects to see it. Writing it down before someone asks for it is far cheaper than reconstructing it under a deadline.

Will you tell us if a control is missing, even if it is uncomfortable?

Yes. A gap we do not flag is a gap your auditor, lender or funder will find instead, so we write it down plainly along with a workable, right-sized fix rather than a generic checklist item.

Do you implement the controls, or just document them?

We document the process, build the matrix, and design a practical fix for each gap alongside your team. Implementing a new approval workflow inside your own systems, such as a new Bill.com approval tier, is done together with whoever owns that software.

How is a control matrix different from a policy manual?

A policy manual describes how a process should ideally work. A control matrix documents how it actually runs today, with a named owner, a frequency, and evidence that proves it happened, which is what an auditor or examiner actually tests against.

How long does the first version take to build?

Most engagements run four to eight weeks from the first interview to a finalized, version-one document, depending on how many process cycles and systems are in scope and how quickly your team can review drafts.

What does internal controls documentation actually include, month to month?

Internal controls documentation covers process narratives for the financial close, AP, AR and payroll cycles, along with a control matrix listing each control, its owner and how often it runs. The work runs inside Excel, QuickBooks Online, Xero or Bill.com, the file stays under your own subscription, and a senior reviewer checks the output before it reaches you.

What access do you need to start?

View or edit access to Excel, QuickBooks Online, Xero or Bill.com is enough to begin. Nothing about your existing subscription or login changes on our side, and any additional access needed for a specific deliverable is agreed with you first and set out in your engagement letter.

Does this help if we are heading into SOC 2 readiness next?

Yes. The control matrix built here becomes the starting point for SOC readiness bookkeeping, since much of the financial evidence a SOC examiner requests traces back to a control that needs to be documented and evidenced consistently first.

Is this a certification of our controls?

No. We document how controls actually work today and flag gaps; any formal attestation or opinion comes from an independent, credentialed auditor you engage separately.

Do we need this if we are a small company?

Even a lean team benefits from writing down who approves what. It shortens the questions an auditor or lender asks and reduces the risk of a single person controlling a whole process.

How do we get started with internal controls documentation?

Getting started with internal controls documentation begins with a short review of your current records and software access. Once that is done we confirm scope and timing in writing, and ongoing work begins on the schedule agreed with you.

What if our records for internal controls documentation are not up to date?

If your records are behind, we scope a catch-up first so internal controls documentation starts from a clean, reconciled base. That catch-up is priced and timed separately from the ongoing engagement, so you always know what each part costs.

Related services

Industries

Related guides

All services in Audit and compliance support

Next step

Talk to the team that would run your books

A short call covers your setup, your software and what a first month would look like. You get a written scope and price after it.

Need this in writing? Download a one to two page scope sheet for Internal controls documentation: what is included, the process, and where pricing lives.

Download the scope sheet