TL;DR: Internal controls reduce fraud, limit misuse, and improve accountability by combining preventive, detective, and corrective measures across financial and operational processes, according to Pathlock. The same control logic now applies to NHI, human access, and delegated workflows, where standing privilege and weak review cycles turn convenience into exposure.
Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “Internal Controls to Prevent Fraud | Checklist”.
By the numbers:
- A 2022 KPMG Fraud Outlook survey of 642 senior executives and board members in the Americas found that 71% had experienced internal or external fraud in the last 12 months.
Key questions
Q: What breaks when no single person is allowed to own an entire transaction or access path?
A: When one person can initiate, approve, record, and reconcile the same process, fraud and misuse become much easier to hide.
Q: Why does weak access control increase the risk of unauthorized access and misuse?
A: Weak access control increases risk because broad permissions make it easier for stolen credentials, mistaken assignments, or insider misuse to reach sensitive systems.
Q: How do organisations know whether internal controls are actually working?
A: They work when activity, approval, and reconciliation consistently line up.
Practitioner guidance
- Map critical workflows to segregation points Identify where the same person or role can request, approve, execute, and reconcile a transaction or access change.
- Separate access creation from access certification Ensure the person who grants privilege is not the same person who later certifies it.
- Require independent reconciliation of privileged activity Compare entitlement records, actual usage, and approval evidence on a fixed cadence.
Bottom line: Internal controls are not paperwork when they prevent one person from controlling an entire process from start to finish.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Internal controls are the governance layer that turns identity from a permission problem into an accountability system. The article is written for finance and operations, but the underlying pattern applies equally to IAM, IGA, and PAM: access without review becomes an open path for misuse. In practice, controls are what make ownership, approval, and reconciliation auditable rather than assumed, and that is why identity programmes fail when control design is treated as optional.
A few things that frame the scale:
- U.S. fraud losses are projected to reach $40 billion by 2027.
A question worth separating out:
Q: What should teams do when a control failure is found in an access or approval process?
A: They should correct the process, not just record the exception. That means fixing the approval chain, limiting who can perform conflicting duties, and confirming the same failure does not reappear in later reviews. Corrective action only works when it changes the operating model, not just the paperwork.
👉 Read our full editorial: Internal controls are the missing identity governance layer