Asked in a diligence session who approves purchase orders, a finance director will typically answer in two movements: an approval threshold is described first, and then, often within the second half of the same sentence, the circumstances under which that threshold is relaxed for urgent orders are explained. Asked in the same session how many times the threshold was relaxed over the preceding twelve months, the reply is rarely a number; it is usually an estimate of frequency, occasionally accompanied by an assurance that such cases are exceptional. The distance between those two answers carries more information about the actual state of the internal control system than the entire policy document does, the first describing design and the second describing operation. What the reviewer records at that moment is not whether the order was approved, but whether the deviation was captured inside the organization as an event.
The same pattern recurs wherever the conversation turns to bank account access, customer discount authority, inventory count variances, or changes to vendor master data. In the company's own account of itself these areas are controlled, because each of them has an experienced and trusted person attached to it; the question the review asks, however, is not about trustworthiness but about substitutability. What determines the quality of a control is not the diligence of the person performing it, but whether the process proceeds to the same standard when that person is unreachable for a week. In mid-market companies this proposition has often never been tested, for the simple reason that no event has yet arisen that would require the test to be run.
The mechanism underneath this behaviour is not negligence but a cost calculation. In a growing company a control, at the moment of its installation, is pure friction: it adds an approval step, slows a decision, and, substituting procedure for confidence in individual judgment, reads culturally as a signal of distrust. At the scale where the founder's or the senior team's direct field of view still covers the whole business, avoiding that friction is entirely rational, since in a visible organization a second signature genuinely does provide only marginal protection. The difficulty lies not in the shortcut itself but in its survival after the condition that justified it has lapsed — once branch count, product lines, supplier base and staff turnover have moved past the threshold of direct observation, the control gap remains exactly where it was, protecting nothing.
A second mechanism operates through the way the existence of control is evidenced. In many companies an internal control document was written once, on the occasion of an audit requirement or a credit application, signed and filed; the text is accurate and the processes are correctly described, but since the date it was written the organizational chart has changed twice, an ERP has been implemented once, and the supplier payment flow has been reconfigured repeatedly. Because the document is not refreshed, the gap between policy and practice widens quietly over time, and the gap is never visible internally as a problem, for the straightforward reason that nobody reads the document. It surfaces only when an outsider reads the text and compares it against practice, and that moment is, characteristically, the review table.
The institutional cost arrives through a channel other than the one first expected. In most companies the cost of weak internal control does not appear in the income statement as a realized misappropriation or loss item; the visible portion is usually small and can be explained as a one-off expense. The substantive cost is the rise in the verification burden attached to every number the company produces: an intercompany balance that is not reconciled on a regular cycle, an inventory line without a recorded variance history, or a discount policy with no approval trail is not rejected in diligence, but it is made subject to additional procedure. Additional procedure produces time, fees and — most consequentially — uncertainty in the closing calendar, and on the buy side that uncertainty is rarely articulated as an open price negotiation; it is typically absorbed into the structure instead.
The forms that absorption takes are well defined. Representation and warranty coverage broadens, since the buyer must rest every unverifiable area on seller statement; escrow ratio and escrow duration are pushed upward, because something must stand behind that statement; and corrections that would ordinarily be left to integration migrate onto the conditions precedent list. In some transactions a portion of the consideration is instead, or additionally, shifted into an earn-out whose measurement base is anchored — with a certain irony — to the same reporting infrastructure whose reliability was questioned, which then becomes the most productive source of post-closing calculation disputes. The valuation multiple frequently remains unchanged; what moves is the confidence interval around how much of the earnings base to which that multiple is applied will convert to cash.
The ownership dimension is where this cost reads most directly. In companies with no institutional owner for internal control, responsibility has in practice collapsed into the finance function and, within finance, onto one person; the same individual records the transaction, performs the reconciliation, and approves the exception. Beyond generating a technical finding on segregation of duties, this configuration is the most legible evidence of founder dependency to be found outside the balance sheet, since the reviewing party is obliged to work out what the company's capacity to produce its own numbers would look like were that person to depart after closing. At board level the question is simpler — on what cycle, in what format, and from whom does the board see internal control exceptions. Where that question cannot be answered with an agenda item and a line in the minutes, the board's oversight function is effectively undefined.
What is sought in the measurement dimension is not, contrary to common expectation, a low error rate. A system reporting zero exceptions demonstrates not that it is working well but that it is not recording exceptions, and a mature reviewer reads this as a measurement gap rather than a signal of assurance. The informative indicator is the stage at which an error is caught: at source, at reconciliation, at period close, or at external audit. The movement of that distribution over time, taken together with a handful of plain measures such as month-end close duration or the number of adjusting entries, describes whether the control environment is maturing far more reliably than any policy text can.
BEIREK's intervention in this area begins not with drafting a new control policy but with mapping the practice that already exists. Who actually approves what across the cash, procurement, sales pricing, inventory and master data lines is reconstructed backwards from real transaction samples of the recent period rather than from the system authorization matrix, and every divergence between the policy text and that reconstruction is logged as an exception before it is corrected. Three components are then established: compensating controls at the points where segregation of duties cannot in fact be achieved — second review, periodic independent reconciliation, dual approval above a stated threshold; a single register in which exceptions are recorded centrally and with dates; and a reporting rhythm carrying that register to the board as a standing agenda item.
Continuity is treated as a separate design decision, since binding a control to a role rather than to a person is possible only where the role has been made transferable. For each critical control, accordingly, a handover procedure is defined that simulates a week in which the person performing it is absent, and the procedure is actually exercised at least once a year; a redundancy plan that is never exercised carries the same verification value as one that was never written. The same logic governs documentation: control descriptions are refreshed against event triggers — organizational change, system change, the opening of a new business line — rather than through a calendar-based annual review, because calendar review rarely coincides with the moment at which the change occurred.
The cumulative effect of these interventions shows up in how the company answers questions once it enters review. In a business where the control system has been built, the answer to how many times the approval threshold was relaxed is a number, and behind it sits a dated record; the presence of deviations does not make such a company weak, it makes it measurable. What the reviewing party prices is not the absence of risk — no operating business can claim that — but whether the risk is known, and known risk is managed within the structure through a narrow, specific heading, whereas unknown risk converts into a broadly scoped demand for security. In most mid-market transactions the difference between those two outcomes is several times the total cost of putting the control infrastructure in place.
The single most revealing question that can be asked about a company's internal control system is not how many controls are defined, but how many controls were subject to an exception last year, and by whom, when and against what record those exceptions were approved; an organization that has the answer ready has demonstrated its confidence in its own numbers through evidence rather than through assertion.
