Internal controls and risk
Stronger controls for a business growing faster than its processes
We replace informal, person-dependent practice with documented, testable financial and operational controls, proportionate to the stage of the business.
Less leakage, clearer accountability, and a business that can scale safely.
Control that scales with you.
Documented, proportionate and testable controls
The problem
Warning signs we look for
- One person can create, approve and pay a transaction.
- Access rights are never revoked after a role changes.
- Management learns about errors far too late to act.
- Approvals happen informally, with no evidence trail.
- Policies exist on paper but are never actually tested.
Control design
- Process risk assessment.
- A risk and control matrix.
- Segregation of duties.
- An approval and delegation-of-authority matrix.
- Maker-checker and exception controls.
- System and access controls.
Testing and improvement
- Walkthroughs and design review.
- Operating-effectiveness testing.
- Exception reporting.
- Corrective-action design.
- Retesting and closure.
Governance outputs
- A risk register.
- A management control dashboard.
- Named owner and reviewer for each control.
- A quarterly control-certification workflow.
- Board or management reporting.
5th Quadrant designs, documents and tests internal financial controls. A statutory auditor's opinion on internal financial controls, where required, is issued independently by the company's appointed statutory auditor.
Practical outputs
What you receive
- Risk register.
- Risk and control matrix.
- Delegation-of-authority and approval matrix.
- Segregation-of-duties review.
- Control testing report.
- Corrective-action tracker.
Ask us for our Finance Controls Self-Assessment when you get in touch.
Evidence
Evidence, not assertion
Anonymised sample deliverables and case studies for this service are in preparation. Ask us for examples relevant to your industry, and we will take you through our review controls, reporting frequency and the roles accountable for each.
Frequently asked questions
What are internal financial controls?
The policies and procedures that make sure transactions are authorised, recorded accurately and protected from error or misuse — things like approval limits, segregation of duties, and reconciliation checks.
Does every small business need documented controls?
Not on day one, but the need grows quickly with headcount, locations or transaction volume. We assess where you are and recommend controls proportionate to your current stage, not a generic heavy framework.
What is segregation of duties?
Making sure no single person can both create and approve the same transaction end-to-end — for example, the person raising a payment shouldn't also be the one approving it.
Can controls be built without slowing the business down?
Yes — the goal is controls that fit how the business actually operates. Overly rigid controls that get bypassed in practice are worse than no controls at all, so we design for what your team will actually follow.
What is the difference between control design and testing?
Design is building the right control for the risk. Testing checks whether that control is actually being followed in practice — the two are separate steps, and we do both.
Can 5th Quadrant issue the statutory auditor's IFC opinion?
No. Any statutory auditor's opinion on internal financial controls must be issued by the company's eligible statutory auditor. We can document and test controls to make that audit smoother.
The connected picture
Build the next layer.
Internal audit
We conduct independent internal audits that identify control gaps, leakage and process weakness — and track corrective action through to closure.
Learn more →SOP and process consulting
We convert undocumented, person-dependent finance work into measurable operating procedures, so the process holds when a key person is unavailable.
Learn more →ESG and sustainability advisory
We convert sustainability expectations — from regulators, investors and customers — into governance, policy, data, operational change and reporting the organisation can evidence.
Learn more →