Audit & Assurance

6 Internal Control Failures Enterprises Should Identify Before They Become Financial Risks

14 min read Expert verified
TL;DR Summary
Enterprises with ₹100 Cr+ turnover and multi-location operations most often lose control over segregation of duties, approval matrices, and ERP access rights. Left unaddressed, these gaps show up as financial misstatements, fraud, or compliance findings during statutory audit. PKC India helps CFOs and audit committees identify and remediate these failures through a structured internal controls review.

Your finance team just discovered a ₹2.5 crore discrepancy, six weeks before the statutory audit. Now the CFO must sign off this year’s board certification that internal financial controls are adequate and operating effectively, the representation your statutory auditor will independently test under Section 143(3)(i). 

For a multi-location manufacturing business, this is not just compliance, its real exposure. Inventory misstatements, approval bypasses, and unreconciled RPTs can become financial, regulatory, reputational, and operational risks.

You may already have documented policies and an ERP. The real question is: where are your controls failing, and how serious are those gaps?

This article highlights the most important and sometimes overlooked control failures auditors, regulators, and fraud investigators repeatedly encounter in Indian enterprises.

If any of these sound familiar, you need to act before your next audit cycle.

Why Internal Control Failures Go Unnoticed Until They Become Expensive

For a manufacturing business with plants in three states and a corporate office in a fourth, an internal control failure is not something that will result in immediate financial loss. Your business will not stop functioning, the books will still close on schedule, GST returns will still get filed. The bank reconciliation will still balance. 

That is exactly why control weaknesses can go undetected for years. Your output looks fine even when the process behind it isn’t.

Let’s take an example.

The same storekeeper counts the stock and maintains the inventory records. When there is no independent check, the numbers can easily be made to match.

The problem may only be discovered when a bank’s auditor finds a difference or when a loss occurs and someone investigates how long the discrepancy existed.

Control weaknesses surface in some of the ways including:

  • A CARO 2020 observation on the internal audit system
  • A qualification in the statutory audit report
  • Due diligence before a credit facility renewal or a fundraise
  • A fraud discovered only after the business suffers a financial loss

The cost increases at each stage.

If your internal audit finds a weakness, it usually requires a process fix. If the statutory auditor finds it, it can result in a qualification that the board must explain. If a lender finds it during a renewal, it can delay the facility, trigger a remediation plan, or even affect disbursement.

Whether you need a formal internal financial controls review, separate from your statutory audit, depends also on the size of your business. Under Section 138 of the Companies Act, 2013, read with Rule 13 of the Companies (Accounts) Rules, 2014, internal audit becomes mandatory once a company crosses certain thresholds.

Below these thresholds, businesses may rely on informal, promoter-led reviews. Above them, a documented internal audit function is expected. CARO 2020 also requires the statutory auditor to comment on whether the internal audit system is appropriate for the size and nature of the business.

So, the immediate question for your management is therefore not if your company has a control policy on paper. It is whether the controls over revenue, procurement, inventory, payments, user access, reconciliations, related party transactions and financial reporting are clearly assigned, consistently performed, documented and independently tested.

If your finance team already performs these checks effectively, an additional review will not add much value. But if responsibilities are unclear, evidence of control performance is inconsistent, or your business has grown faster than its finance processes, a structured internal control assessment with experts like PKC Management Consulting can identify weaknesses before they turn up in your audit reports, cause funding obstacles or direct financial losses.

1. Segregation of Duties Gaps in Finance Teams Spread Across Plants and Branches

Segregation of duties is the most fundamental internal control principle: no single person should have the ability to initiate, approve, and record a transaction. 

Yet many multi-location businesses frequently violate this. 

One person controlling the entire transaction cycle at plant level

For a multi-location manufacturing business with lean finance teams, segregation of duties may look adequate at corporate headquarters but break down at individual plants.

At one plant, a single accountant may handle vendor creation, purchase orders, goods receipts, invoice checks, and payment initiation. Each task may seem reasonable on its own, but together they give one person control over the entire transaction cycle.

The risk is that the same user could create a fake vendor, record a delivery that never happened, approve the invoice, and initiate payment. Inventory records could also be changed to hide shortages or theft. 

With limited corporate oversight, these issues may go undetected for months.

This is exactly what internal financial controls testing looks for. This includes walkthroughs, reviewing user access, sampling transactions where the same user ID performs multiple stages, and checking whether ERP roles match the documented controls.

No compensating control where a full split of duties isn’t staffed

Hiring more people at every location is not always the realistic solution and most CFOs are aware of this. In such cases, the best option is compensating control. 

For example, a vendor master changes at any plant require second level review by someone at head office, payment release needs dual authorisation regardless of location, and the ERP is configured so no single login can both create a vendor and release a payment to it. 

The idea is to make sure that wherever one person in your organisation holds conflicting duties, someone independently reviews their work on a defined cycle.

Fixing this is also usually the cheapest solution. Reassigning who can approve a goods receipt note, or adding a second sign off on vendor bank detail changes, doesn’t require new headcount or a system upgrade. 

Simply identify, plant by plant, where one user has multiple control roles and fix the ERP access.

2. Weak Approval Matrices for High-Value Transactions

Approval matrices define who can authorise what, up to what value. They may seem sufficient on paper but on ground they are often outdated, inconsistently applied, or simply bypassed.

Approval thresholds getting bypassed

An MD has signing authority up to ₹50 lakh. Anything above that requires Board approval. But the MD routinely approves ₹70-80 lakh purchase orders because waiting for the Board meeting would delay production. The finance team processes these payments because they do not want to stall operations. 

The approval matrix exists on paper but is not followed.  This is a control failure.

You may think this is just an operational shortcut. But auditors see a bigger issue: a control that is regularly bypassed is not an effective control. If ₹80 lakh can bypass the limit, what stops someone from bypassing it for ₹8 crore? Nothing. 

For multi-location businesses, delegated limits can vary or become outdated. As the business grows, approval limits must be reviewed and updated.

The fix is more than updating a document. Approval limits should be built into the ERP, reviewed regularly, and supported by audit trails showing who approved what and when. PKC’s approach to internal controls consulting includes drafting remediation plans and SOPs and configuring systems for control execution.

Vendor bank detail changes & Capex approvals

Vendor master and bank account changes is a gap that gets less attention than it deserves. 

Vendor bank changes are often treated like routine master data updates. But unlike a simple address change, a bank account change can directly redirect payments. 

This makes it a common fraud risk, especially when requests come from spoofed vendor emails. These changes should require independent verification and a second approval.

Approval matrices should also clearly identify matters that require Board approval under Section 179(3) of the Companies Act. 

This is especially important in multi-location businesses, where authority is often delegated to plant or regional heads. 

Capital expenditure  is another risk area. Large projects may be split across multiple purchase orders for machinery, installation, and civil work so that no single approval crosses the threshold that would otherwise require board sign off, a pattern auditors reviewing capital additions specifically look for.

3. Manual Journal Entries Without Independent Review

Most ERP transactions follow built-in checks, such as matching purchase orders, goods receipts, and invoices. 

Manual journal entries bypass these checks becoming one of the highest-risk areas in financial reporting. 

The control failure occurs when manual journal entries are not subject to independent review. 

In many mid-market companies, the same person who prepares the journal entry also approves it. There is no segregation of duties. There is no second set of eyes. 

This is precisely the kind of control weakness that auditors look for during IFC testing enterprise-wide.

NFRA inspections have flagged control gaps in revenue and related-party transactions, where manual journal entries are often used. Fraud investigations have also found cases where manual journals bypassed normal controls.

A few patterns draw the most scrutiny once an internal or statutory auditor pulls the complete journal entry log: 

  • entries posted outside normal working hours or on weekends, round number adjustments with no supporting calculation
  • entries reversed and reposted close to period end, and any entry made directly to a control account such as accounts receivable or inventory that normally only moves through automated sub ledger postings. 

None of these are automatically wrong, but they should get a second look before the books close.

The risk of missing these can be severe

In manufacturing, manual journals may be used for inventory adjustments, cost allocations, and inter-plant transfers. These involve judgment and can lead to errors or manipulation if not properly reviewed. The consequences can be severe. 

A CFO or CEO who knowingly certifies that everything is adequate when serious problems exist, or hides fraud, can be held legally responsible under the Companies Act. They may also face professional and reputational consequences.

The fix cannot be eliminating manual entries, because for a business that large, that would be unrealistic. Restrict ERP access, require approval for high-value entries, document supporting evidence, and have the controller or CFO review the full journal log monthly.

4. Inventory and Fixed Asset Verification Shortfalls

For a multi-location manufacturing enterprise, physical verification becomes difficult when inventory and fixed assets are spread across plants, warehouses, depots, consignment locations and third-party premises. 

The risk increases when the same team that maintains the records also performs the physical count, or when differences between physical and book balances are not formally investigated.

Under CARO 2020, auditors must check if property, plant and equipment and inventory are physically verified regularly, whether the verification process is appropriate, and whether material discrepancies are properly recorded.

This is where the control usually breaks down:

Verification is performed without sufficient independence

A plant team may count its own inventory for convenience, but this weakens the control. For high-value or high-risk locations, independent reviews, surprise counts, or cycle counts provide stronger assurance.

Physical counts are not reconciled properly

Finding a difference is only the first step. Variances should be supported, investigated, approved, and documented. Unexplained adjustments should not simply be passed through the ledger. 

Third-party and consignment stock is overlooked

Inventory held by job workers, consignment agents, or other third parties should be confirmed and reconciled with company records. Otherwise, reported quantities may remain unverified.

Fixed asset records no longer reflect reality

A fixed asset register containing equipment that was scrapped, transferred or sold, without physical tagging and reconciliation, weakens both financial reporting and asset accountability.

The scale of these gaps can be understood with recent findings. Ramkrishna Forgings reported inventory overstatement of ₹220.52 crore as of March 31, 2025, following discrepancies identified during annual physical verification. Ola Electric’s FY25 auditor also identified a material weakness relating to physical verification of inventory held at stores and state distribution centres.

You may think, ‘We do a stock count every year before the audit. Isn’t that enough?’ The answer depends on what happens after the count. If your team performs the count, finds discrepancies, quietly adjusts the books, and moves on, you have not tested whether the controls actually work. You have only documented the result.

 The auditor will ask to see the reconciliation, how discrepancies were investigated, who approved the adjustments, and whether the same discrepancies appeared in prior periods. If you cannot show this, the control is not operating effectively.

For a business with several locations, perform this simple test: Check your last two physical verification cycles. Were all locations counted using the same protocol? Were all discrepancies formally investigated and documented? Were third-party confirmations obtained? If the answer to any of these is no, you have a control gap that an auditor would flag.

The goal should be to complete an annual stock count before the statutory audit. You must establish reliable evidence that the assets recorded in the financial statements actually exist, are properly accounted for, and are subject to controls that work throughout the year.

5. IT General Controls Gaps in ERP Environments

You may be using SAP, Oracle, Tally, Microsoft Dynamics, or another ERP across your plants, to enforce approvals and automate accounting, but your ERP itself needs controls

IT General Controls (ITGC) determine who can access the system, what they can do, how changes are introduced, and whether system activity can be traced.

Here are some common weaknesses we have observed: 

ERP access rights do not match the approval matrix

The ERP role structure that no longer reflects the company’s current responsibilities. A former employee still has an active account, several users share generic credentials, or an administrator has both technical and transaction processing access.

The higher risk occurs when one user can perform incompatible activities, such as creating a vendor and processing its payment. Sensitive master data changes, including vendor bank details or customer credit limits, could also be possible without independent approval.

When you have a multi location business, access needs to be reviewed across every plant and branch. A documented role based access control review should compare actual ERP permissions with the approved designation and segregation of duties matrix.

ERP changes are made without formal change management

Changing an approval workflow, tax configuration, report, master data rule or other ERP setting changes the way financial controls operate. Yet often such configuration changes are made directly in production after a verbal or informal request.

A basic change management process should record what changed, why it was required, who approved it, who implemented it, and whether it was tested before deployment. This helps create an audit trail and helps establish whether a system change unintentionally weakened an existing control.

As an enterprise with multiple locations, here’s a check you must run:

  • User access: quarterly review of active users, privileged accounts and terminated employee access.
  • Segregation of duties: testing whether ERP roles actually enforce the documented approval matrix.
  • Change management: documented approval, testing and deployment records for configuration changes.
  • Audit trails: confirmation that relevant logs are enabled, retained and periodically reviewed.

Your ERP access and configuration must at all times reflect the way the business is supposed to operate. 

For a CFO or finance head preparing for IFC testing, internal audit or statutory audit, an ITGC review can help separate a genuine system control from a control that exists only on paper.

ITGC gaps are rarely reviewed in isolation – they’re usually surfaced as part of a broader internal audit. See PKC’s internal audit services in India for how ERP access and configuration reviews fit into a full engagement.

6. Related Party Transaction Monitoring Failures

For promoter-led groups, related party transactions (RPTs) are common. This may include inter-company purchases, shared services, leases, loans or sales between group entities. 

Here, the internal control problem usually starts when finance teams don’t have the clarity on who qualifies as a related party and which transactions require approval, documentation or disclosure.

Section 188 of the Companies Act, 2013 covers specified contracts and arrangements with related parties, including purchases, sales, leases and services. It requires Board approval subject to the conditions prescribed under the law, with additional approval requirements for transactions crossing prescribed thresholds. The Act also requires relevant contracts or arrangements to be reported in the Board’s report.

Here are some common repetitive failures:

The related party register does not capture the full relationship network

Many times companies treat related party register as a year-end compliance document. A new director interest, promoter-linked entity or change in ownership can occur during the year, while purchases, payments or service arrangements continue without being flagged.

For example, a plant may start purchasing raw materials from a supplier connected to a promoter or director. If vendor onboarding is not checked against the related party register, the transaction can enter the ERP as an ordinary purchase without the required review.

Management should therefore maintain an up-to-date related party register, link it to vendor and customer onboarding, and establish a process for identifying changes in directors, promoters and connected entities throughout the year.

Recurring RPTs are approved but not monitored afterwards

Recurring management fees, leases or inter-company supplies create a different control risk. An approval obtained at the start of the financial year does not remove the need to monitor actual transactions against the applicable approval, pricing and disclosure requirements.

For companies with an Audit Committee, omnibus approvals are subject to prescribed conditions and require appropriate monitoring and review.

Your RPT control framework should therefore include:

  • A current related party master covering all locations and group entities
  • Pre-transaction checks during vendor and customer onboarding
  • Documented basis for pricing and arm’s length assessment where applicable
  • Tracking of approved versus actual transaction values
  • Periodic review of RPTs by finance, internal audit and the Audit Committee where applicable
  • Reconciliation of RPT records with the general ledger and required disclosures

For a CFO, the key question is simple: can the company identify every RPT before it occurs, prove why it was approved, and reconcile what was actually transacted with what was authorised and disclosed? If not, the weakness is not merely a documentation issue. It can become a governance, audit and financial reporting risk.

How PKC Helps Enterprises Build a Remediation Roadmap

Identifying control failures is only the first step. The real challenge is remediation.

Many businesses struggle to bridge the gap between identifying a deficiency and implementing a sustainable fix.

Why Internal Teams Struggle With Remediation

Your internal finance team may be able to address straightforward, isolated issues such as updating an approval matrix document, cleaning up a user access list, and revising an existing policy. 

But a complex issue raises a crucial question:

Can our team design, test, and deploy ERP-level control changes across multiple locations without disrupting operations and while maintaining the independence auditors require?

The answer depends on whether or not your internal teams are set up for this. And honestly, most are not. 

They are already managing daily closing, reporting, and statutory deadlines. They lack an independent perspective, which auditors specifically require when evaluating control remediation. And they rarely have the specialised ERP configuration expertise needed to embed controls into the system rather than leaving them as paper policies. 

How Does PKC Solve This Problem

We offer three specific capabilities that internal teams usually do not have:

  1.  Impartiality, auditors value independent remediation
  2. Deep ERP configuration knowledge with over 20+ ERPs
  3. A structured methodology that has been tested across 100+ implementations.

This remediation work is delivered alongside PKC’s internal audit services, so control fixes are tested and re-verified as part of the same engagement rather than handed off separately.

When we run a remediation engagement for a multi-location manufacturer, the process is designed to minimize operational disruption. Here’s what it looks like

Scope & assess (4-6 weeks)

We start with a focused pilot targeting the highest-risk area, such as inventory verification or approval matrix enforcement.

Our consultants work directly with your finance and IT teams to review current configurations, identify control gaps,  map required changes and define a remediation plan.

Parallel run (8-12 weeks)

The pilot is followed by a parallel-run cycle. We usually roll it out across 2-3 plant locations first. During this parallel run, the new control configurations operate alongside the existing manual processes. 

This allows your team to compare results, catch configuration errors, and build confidence before enterprise-wide deployment. 

Enterprise rollout

Once the parallel run produces consistent, error-free results, we proceed with deployment across all locations.

For each of the failures discussed above, the remediation approach is specific. 

Control failureRemediation
Segregation of dutiesWorkflow redesign and ERP configuration
Approval matricesPolicy updates and system enforcement
Manual journal entriesReview workflows and audit trails
Inventory verificationCount protocols and reconciliation
ITGCsAccess reviews, change management and logging
RPT monitoringPolicies, documentation and audit committee oversight

PKC’s internal controls consulting services include drafting remediation plans and SOPs, configuring systems for control execution, and providing independent evaluations to help remediate deficiencies and restore stakeholder confidence.

The remediation roadmap for a business that comes to us is built to target the specific control failures identified, the business context, and the regulatory requirements applicable to the enterprise. 

Our goal is to build a practical, achievable roadmap that addresses the most significant risks first and establishes a process for continuous improvement.

If you recognise the control failures, don’t wait for an audit or regulatory inspection to find them. Identify the risks now and address them on your terms.

At PKC we work with businesses like yours with complex operations and demanding compliance requirements. Our advisors understand what is at stake: audit opinions, regulatory compliance, financial accuracy, and operational integrity.

The first step is a conversation about your specific situation. Just a direct assessment of where your controls stand and what needs to happen next.

FAQs

Q1: What is an internal control failure in a company?

An internal control failure happens when a process meant to prevent or catch errors, fraud, or misstatement doesn’t work as designed, whether because it was never implemented, isn’t followed consistently, or has a structural gap such as one person holding conflicting duties. Unlike operational mistakes, control failures are usually silent. Financial output still looks correct until an audit, review, or fraud investigation exposes the weakness behind it.

Q2: How often should enterprises test internal controls?

Most control areas need review at least once a year, aligned with the statutory audit cycle. Higher-risk areas, such as manual journal entries, vendor master changes, and ERP user access, warrant monthly or quarterly checks. Physical verification of inventory and fixed assets should follow a defined cycle across every location, not only head office, rather than being triggered solely when an audit is approaching.

Q3: What is the difference between an internal control failure and an audit finding?

A control failure is the underlying gap itself, such as a missing approval or an unreviewed journal entry. An audit finding is what happens once an auditor identifies and formally documents that gap, through internal audit, statutory IFC testing under Section 143(3)(i), or a CARO 2020 observation. A failure can sit unnoticed for years; a finding puts it on record.

Q4: Who is responsible for internal controls when finance operations span multiple plants or branches?

The board and CFO hold overall accountability, but effective controls need an owner at each plant or branch who applies the approval matrix, segregation of duties design, and ERP access rules that head office sets centrally. Without a named owner at every location, controls that look uniform on paper often drift apart in practice once distance and local staffing pressure take over.

Q5: Can weak internal controls affect a statutory audit opinion?

Yes. Under Section 143(3)(i), the statutory auditor must give a separate opinion on whether internal financial controls are adequate and operating effectively, and CARO 2020 requires comment on the internal audit system’s adequacy. Significant weaknesses can lead to a qualified or adverse opinion on internal controls, even when the financial statements themselves are otherwise unqualified.

Q6: How does PKC assess internal control effectiveness?

At PKC we run a gap assessment against a COSO-based framework, covering segregation of duties, approval authority, journal entries, physical verification, ERP access, and related party monitoring, through documentation review, control walkthroughs, and transaction sample testing. Findings feed into a Risk and Control Matrix prioritized by actual exposure, followed by a remediation roadmap with named owners, timelines, and a re-testing step before the next audit.

Fix Control Gaps Before Your Auditor Finds Them

Segregation gaps, ERP access issues, approval bypasses - PKC finds them before they become audit findings.

Call us: +91 91761 00095

Got a question after reading?

Drop your details and one of our consultants will call you back — usually within a business day.

Want to talk? Get a call back today
+91 91761 00095

Fill out your details

Once submitted, a calendar will open to book your 30-minute meeting slot.

or call us: +91 91761 00095