Avenlor
Home / Insights / Audit readiness
Internal Controls

Internal Controls Before an External Audit

The audits that go smoothly are the ones where the controls were already working. By the time the auditor arrives, readiness is not something you build — it is something you demonstrate. Here is how to get there.

Avenlor ConsultingGovernance & Internal Controls7 min read

Every finance team knows the feeling of the weeks before an external audit: requests pile up, reconciliations get redone, and someone spends a night reconstructing an approval that happened months ago. The stress is real, but it is a symptom. It means the control environment was not producing evidence as it went — so the team has to manufacture it under deadline.

A well-controlled organization experiences the audit differently. The evidence already exists because the controls already operate. The goal of pre-audit preparation is to move your organization from the first state to the second.

Start with the control environment, not the checklist

It is tempting to treat audit readiness as a list of documents to gather. But auditors are not only checking whether a control exists — they are assessing whether the environment around it makes the numbers trustworthy. Tone from the top, clear ownership, and a culture where exceptions are escalated rather than absorbed all shape how much reliance an auditor can place on your controls. A tidy binder cannot compensate for an environment where one person quietly does everything.

Segregation of duties: the first thing tested

The single most common finding in growing companies is a breakdown in segregation of duties. The principle is straightforward: no one person should control a transaction end to end. The person who initiates a payment should not also approve it, record it, and reconcile the account it hits.

In a small company this concentration happens naturally — there simply were not enough people. But it is precisely the condition that makes error and fraud possible, and it is where auditors look first. Where headcount genuinely prevents full separation, the answer is compensating controls: independent review, dual authorization above thresholds, and management oversight that is documented rather than assumed.

Think in three lines

A useful way to organize control responsibility is the three-lines model:

Not every company needs a large structure for each line, but every company should be able to say who plays each role. When all three collapse into one team, there is no independent check — and the external auditor has to do more work, at more cost, with less reliance on your controls.

Controls only count if they leave evidence

An auditor cannot test a control they cannot see. "We always review this" is not a control; a dated, initialled review that shows what was checked and what was found is. As you prepare, walk each key control and ask a blunt question: if someone asked me to prove this operated last quarter, could I? If the answer is no, the control is effectively invisible, regardless of how diligently it is performed.

A control that leaves no trace is, to an auditor, a control that did not happen.

The gaps we see most often

Remediation with an owner and a date

Finding a gap is the easy part. Closing it durably is the discipline. Every issue should be logged with a named control owner, a described fix, and a date — and, crucially, a sign-off confirming the remediation is in place and operating, not merely planned. A remediation plan with no owner is a wish list; the same plan with an accountable owner and evidence of closure is what turns a repeat finding into a resolved one.

Pre-audit readiness map

  • Key controls documented — what, who, how often, and the evidence produced
  • Segregation of duties reviewed, with compensating controls where separation is impractical
  • System access matched to current roles; stale access removed
  • Reconciliations performed and independently reviewed, with evidence retained
  • Manual journals supported by documented rationale and approval
  • Related-party transactions identified, priced, and approved through a clear path
  • Open findings logged with a named owner, a fix, a date, and sign-off on closure

The organizations that dread the audit are usually the ones that treat controls as paperwork produced for the auditor. The ones that barely notice it are those that built controls to run the business well — and let the audit simply confirm what was already true.

Facing an audit?

We run control-gap assessments and remediation planning aligned to recognized frameworks — with clear ownership at every step.

Discuss your mandate →

Read next

Building an Internal Control Framework with COSO → Board Readiness for a Tadawul Listing →

This article is general guidance on internal-controls practice and does not constitute legal, audit, or regulatory advice. Obtain professional advice for your specific circumstances.