---
title: "The Internal Control System: A Record of How Much a Company Trusts Its Own Numbers"
description: "In an investment review, the internal control system determines whether a company's reported figures can be verified. Where it is weak, the effect surfaces not in the income statement but in the confidence interval around the earnings base to which the multiple is applied. Reviewers care less whether controls are written down than whether they operate independently of the founder and whether exceptions are logged."
url: https://www.beirek.com/en/blog/internal-control-system-valuation-diligence
canonical: https://www.beirek.com/en/blog/internal-control-system-valuation-diligence
published: 2026-08-04
modified: 2026-08-04
category: "Board & Governance"
category_url: https://www.beirek.com/en/blog/category/board-governance
language: en-US
reading_time_minutes: 8
publisher: BEIREK LLC
publisher_url: https://www.beirek.com
license: "© BEIREK LLC — citation with attribution and link permitted"
keywords: ["internal control system","segregation of duties","due diligence","escrow and representations","founder dependency","board oversight"]
topics: ["Internal control design and testing in mid-market companies","How control weaknesses are absorbed into deal structure rather than headline price","Board-level oversight of control exceptions and reporting rhythm","Compensating controls where segregation of duties is not achievable"]
alternate_language_url: https://www.beirek.com/tr/blog/internal-control-system-valuation-diligence
---

# The Internal Control System: A Record of How Much a Company Trusts Its Own Numbers

> **In short:** In an investment review, the internal control system determines whether a company's reported figures can be verified. Where it is weak, the effect surfaces not in the income statement but in the confidence interval around the earnings base to which the multiple is applied. Reviewers care less whether controls are written down than whether they operate independently of the founder and whether exceptions are logged.

*Internal control is not an appendix to the audit report but the chain of assurance standing behind every figure a company produces. What a review table looks for is not the existence of a control list, but whom the control operates independently of, how often it is tested, and how the exception is recorded.*

---

Asked in a diligence session who approves purchase orders, a finance director will typically answer in two movements: an approval threshold is described first, and then, often within the second half of the same sentence, the circumstances under which that threshold is relaxed for urgent orders are explained. Asked in the same session how many times the threshold was relaxed over the preceding twelve months, the reply is rarely a number; it is usually an estimate of frequency, occasionally accompanied by an assurance that such cases are exceptional. The distance between those two answers carries more information about the actual state of the internal control system than the entire policy document does, the first describing design and the second describing operation. What the reviewer records at that moment is not whether the order was approved, but whether the deviation was captured inside the organization as an event.

The same pattern recurs wherever the conversation turns to bank account access, customer discount authority, inventory count variances, or changes to vendor master data. In the company's own account of itself these areas are controlled, because each of them has an experienced and trusted person attached to it; the question the review asks, however, is not about trustworthiness but about substitutability. What determines the quality of a control is not the diligence of the person performing it, but whether the process proceeds to the same standard when that person is unreachable for a week. In mid-market companies this proposition has often never been tested, for the simple reason that no event has yet arisen that would require the test to be run.

The mechanism underneath this behaviour is not negligence but a cost calculation. In a growing company a control, at the moment of its installation, is pure friction: it adds an approval step, slows a decision, and, substituting procedure for confidence in individual judgment, reads culturally as a signal of distrust. At the scale where the founder's or the senior team's direct field of view still covers the whole business, avoiding that friction is entirely rational, since in a visible organization a second signature genuinely does provide only marginal protection. The difficulty lies not in the shortcut itself but in its survival after the condition that justified it has lapsed — once branch count, product lines, supplier base and staff turnover have moved past the threshold of direct observation, the control gap remains exactly where it was, protecting nothing.

A second mechanism operates through the way the existence of control is evidenced. In many companies an internal control document was written once, on the occasion of an audit requirement or a credit application, signed and filed; the text is accurate and the processes are correctly described, but since the date it was written the organizational chart has changed twice, an ERP has been implemented once, and the supplier payment flow has been reconfigured repeatedly. Because the document is not refreshed, the gap between policy and practice widens quietly over time, and the gap is never visible internally as a problem, for the straightforward reason that nobody reads the document. It surfaces only when an outsider reads the text and compares it against practice, and that moment is, characteristically, the review table.

The institutional cost arrives through a channel other than the one first expected. In most companies the cost of weak internal control does not appear in the income statement as a realized misappropriation or loss item; the visible portion is usually small and can be explained as a one-off expense. The substantive cost is the rise in the verification burden attached to every number the company produces: an intercompany balance that is not reconciled on a regular cycle, an inventory line without a recorded variance history, or a discount policy with no approval trail is not rejected in diligence, but it is made subject to additional procedure. Additional procedure produces time, fees and — most consequentially — uncertainty in the closing calendar, and on the buy side that uncertainty is rarely articulated as an open price negotiation; it is typically absorbed into the structure instead.

The forms that absorption takes are well defined. Representation and warranty coverage broadens, since the buyer must rest every unverifiable area on seller statement; escrow ratio and escrow duration are pushed upward, because something must stand behind that statement; and corrections that would ordinarily be left to integration migrate onto the conditions precedent list. In some transactions a portion of the consideration is instead, or additionally, shifted into an earn-out whose measurement base is anchored — with a certain irony — to the same reporting infrastructure whose reliability was questioned, which then becomes the most productive source of post-closing calculation disputes. The valuation multiple frequently remains unchanged; what moves is the confidence interval around how much of the earnings base to which that multiple is applied will convert to cash.

The ownership dimension is where this cost reads most directly. In companies with no institutional owner for internal control, responsibility has in practice collapsed into the finance function and, within finance, onto one person; the same individual records the transaction, performs the reconciliation, and approves the exception. Beyond generating a technical finding on segregation of duties, this configuration is the most legible evidence of founder dependency to be found outside the balance sheet, since the reviewing party is obliged to work out what the company's capacity to produce its own numbers would look like were that person to depart after closing. At board level the question is simpler — on what cycle, in what format, and from whom does the board see internal control exceptions. Where that question cannot be answered with an agenda item and a line in the minutes, the board's oversight function is effectively undefined.

What is sought in the measurement dimension is not, contrary to common expectation, a low error rate. A system reporting zero exceptions demonstrates not that it is working well but that it is not recording exceptions, and a mature reviewer reads this as a measurement gap rather than a signal of assurance. The informative indicator is the stage at which an error is caught: at source, at reconciliation, at period close, or at external audit. The movement of that distribution over time, taken together with a handful of plain measures such as month-end close duration or the number of adjusting entries, describes whether the control environment is maturing far more reliably than any policy text can.

BEIREK's intervention in this area begins not with drafting a new control policy but with mapping the practice that already exists. Who actually approves what across the cash, procurement, sales pricing, inventory and master data lines is reconstructed backwards from real transaction samples of the recent period rather than from the system authorization matrix, and every divergence between the policy text and that reconstruction is logged as an exception before it is corrected. Three components are then established: compensating controls at the points where segregation of duties cannot in fact be achieved — second review, periodic independent reconciliation, dual approval above a stated threshold; a single register in which exceptions are recorded centrally and with dates; and a reporting rhythm carrying that register to the board as a standing agenda item.

Continuity is treated as a separate design decision, since binding a control to a role rather than to a person is possible only where the role has been made transferable. For each critical control, accordingly, a handover procedure is defined that simulates a week in which the person performing it is absent, and the procedure is actually exercised at least once a year; a redundancy plan that is never exercised carries the same verification value as one that was never written. The same logic governs documentation: control descriptions are refreshed against event triggers — organizational change, system change, the opening of a new business line — rather than through a calendar-based annual review, because calendar review rarely coincides with the moment at which the change occurred.

The cumulative effect of these interventions shows up in how the company answers questions once it enters review. In a business where the control system has been built, the answer to how many times the approval threshold was relaxed is a number, and behind it sits a dated record; the presence of deviations does not make such a company weak, it makes it measurable. What the reviewing party prices is not the absence of risk — no operating business can claim that — but whether the risk is known, and known risk is managed within the structure through a narrow, specific heading, whereas unknown risk converts into a broadly scoped demand for security. In most mid-market transactions the difference between those two outcomes is several times the total cost of putting the control infrastructure in place.

The single most revealing question that can be asked about a company's internal control system is not how many controls are defined, but how many controls were subject to an exception last year, and by whom, when and against what record those exceptions were approved; an organization that has the answer ready has demonstrated its confidence in its own numbers through evidence rather than through assertion.

## Key Points

- The real test of internal control is not whether a policy exists but whether the process runs identically during the week the person who performs the control is unavailable.
- A control that is not documented is treated as absent at the review table, and practice that cannot be verified widens representation and warranty coverage while pushing escrow ratios upward.
- In companies that do not log control exceptions, risk does not disappear; it merely becomes unmeasurable, and that uncertainty is priced as a discount somewhere in the deal structure.
- Concentrating approval authority in a single signature is the most legible evidence of founder dependency outside the balance sheet and raises post-closing transition risk directly.
- A control system becomes measurable not by reporting a zero error rate but by showing at which stage errors are caught — at source, at reconciliation, at period close, or at external audit.

## Questions

### How is the valuation of a company with weak internal control affected?

The effect usually appears in the transaction structure rather than in the multiple itself. Unverifiable areas broaden representation and warranty coverage, push escrow ratio and duration upward, and lengthen the conditions precedent list. In some deals part of the consideration shifts into an earn-out. The result is that net cash reaching the seller falls even where the headline price is unchanged, and the closing calendar becomes less predictable.

### What can be done where a small company cannot achieve segregation of duties?

Where headcount does not permit segregation, compensating controls are installed: second approval above a stated threshold, periodic and independent bank and account reconciliation, cyclical review of master data changes, and sample testing by an external accountant or adviser. What matters is that these compensating controls are defined, dated and operated on the record; a practice maintained only verbally is not treated as verifiable at the review table.

### How often should internal control documentation be updated?

A calendar-driven annual review is usually insufficient, because change does not arrive on the calendar. The more effective approach ties updates to events: a change in organizational structure, the commissioning of a new system or ERP module, entry into a new business line or geography, and turnover in a critical role. Adding a single annual scope check on top of those triggers limits how far the gap between document and practice can widen.

### What does an investor examine first in an internal control review?

Not the policy text, but the cash and authority lines: who holds access to bank accounts, how many signatures complete a payment approval, and who is able to change sales discounts and vendor master data. Actual application of the policy is then reconstructed backwards from real transaction samples of the recent period. A system reporting zero exceptions is read as a sign of a measurement gap rather than as assurance.

---

Source: https://www.beirek.com/en/blog/internal-control-system-valuation-diligence
Publisher: BEIREK LLC — https://www.beirek.com
