Internal Controls Every CFO Should Strengthen in 2026 

 

In today’s dynamic business environment, internal controls are far more than a compliance requirement—they are the backbone of financial integrity, operational efficiency, and stakeholder confidence. For CFOs in South Africa, the past few years have been particularly challenging: economic pressures, digital transformation, and increased scrutiny from regulators have exposed weaknesses in many finance functions. 

According to the 2025 PwC Global Economic Crime and Fraud Survey, 49% of organisations in South Africa reported at least one economic crime incident in the past two years, with financial statement manipulation and procurement fraud among the top threats. Weak or ineffective internal controls were cited as a common contributing factor. 

Strengthening internal controls is no longer optional. It is a strategic imperative. Below, I outline the five critical internal control areas every CFO should focus on this year, with practical guidance on how to enhance them. 

Revenue Recognition Controls

Why it matters:
Revenue is often the most material line item in financial statements. Misstated revenue is the leading cause of restatements globally. IFRS 15 – Revenue from Contracts with Customers – requires careful assessment of contract terms, performance obligations, and timing of revenue recognition. Weak controls in this area can lead to significant compliance and reputational risk. 

How to strengthen: 

  • Implement automated contract review systems to ensure all revenue streams are captured accurately. 
  • Conduct regular cut-off testing at month-end to verify transactions are recorded in the correct period. 
  • Develop management review procedures for revenue estimates and judgments, such as discounts, returns, and variable consideration. 
  • Align accounting policies with IFRS 15 and ensure staff are trained on key judgment areas. 

Statistic: A 2023 EY study found that over 60% of material misstatements in audits were related to revenue recognition—underscoring the importance of robust controls. 

IT General Controls (ITGCs)

Why it matters:
Finance operations are increasingly digital, relying on ERP systems, cloud solutions, and automation tools. ITGCs form the foundation for reliable financial reporting and protection against cyber threats. ISA 315 (Identifying and Assessing Risks of Material Misstatement) emphasises evaluating IT controls when auditing automated financial systems. 

How to strengthen: 

  • Enforce user access management with role-based permissions and quarterly access reviews. 
  • Monitor system changes via controlled change management procedures to prevent unauthorised modifications. 
  • Conduct regular system monitoring and vulnerability assessments, especially for cloud platforms. 
  • Integrate ITGC testing into internal audit and external audit plans. 

Statistic: According to a 2024 KPMG survey, 73% of finance leaders reported at least one material control weakness stemming from IT vulnerabilities. 

 

Segregation of Duties (SoD)

Why it matters:
Segregation of duties ensures no single individual can execute conflicting functions, such as approving a payment and recording it. Weak SoD is a common source of fraud and misstatement. ISA 240 emphasises evaluating fraud risk arising from management override or collusion. 

How to strengthen: 

  • Conduct a roles and responsibilities review, mapping all finance processes to ensure proper separation. 
  • Implement system-enforced controls to prevent overlapping access in ERP systems. 
  • Introduce regular SoD conflict reports reviewed by finance leadership and internal audit. 
  • Train staff on fraud awareness and reporting procedures. 

Statistic: ACFE’s 2024 Global Fraud Study indicates that over 35% of occupational fraud cases involved a lack of SoD, emphasising its criticality. 

 

Procurement and Payment Controls

Why it matters:
Procurement and payment processes are high-risk areas for fraud, errors, and unauthorised spending. Proper controls ensure compliance with corporate governance frameworks and prevent financial leakage. 

How to strengthen: 

  • Introduce rigorous vendor onboarding processes, including validation of banking and tax details. 
  • Require dual approvals for all payments above defined thresholds. 
  • Automate invoice matching and verification to ensure that goods/services are received before payments are processed. 
  • Periodically conduct procurement audits and exception reporting to identify unusual or duplicate payments. 

Statistic: PwC’s 2025 South Africa CFO Survey found that procurement-related fraud represented 41% of reported economic crimes, highlighting the need for robust controls. 

 

Financial Close and Reporting Internal Controls

Why it matters:
The integrity of financial statements depends heavily on disciplined month-end and year-end processes. Controls here prevent misstatements, facilitate timely reporting, and improve decision-making. ISA 330 highlights the need for substantive procedures to validate account balances. 

How to strengthen: 

  • Standardise month-end close checklists with clear deadlines and responsibilities. 
  • Conduct reconciliations of key accounts, including intercompany balances, cash, and receivables. 
  • Introduce management review of financial statements prior to board submission. 
  • Leverage automation tools for reporting to reduce human error and increase efficiency. 

Statistic: Deloitte 2024 research shows that companies with structured financial close processes report a 30–40% reduction in errors and adjustments during audits. 

 

Implementing a Robust Internal Control Environment 

Strengthening these five areas is only part of the solution. CFOs should aim for an integrated control environment, aligned with COSO principles, ISA guidance, and IFRS compliance. This includes: 

  • Regular internal audits to assess effectiveness and identify gaps. 
  • Continuous monitoring and risk assessment, especially as business models and IT systems evolve. 
  • Training and awareness programs for staff at all levels, ensuring everyone understands their role in controls. 
  • Strong governance oversight, with the audit committee and board actively reviewing internal control performance. 

 

Internal controls are no longer a checkbox—they are a strategic asset. Strengthening revenue recognition, IT general controls, segregation of duties, procurement, and financial close processes not only reduces risk, but also enhances stakeholder confidence and supports sustainable growth. 

CFOs who proactively address these areas will position their organisations to navigate regulatory pressures, digital transformation, and economic challenges effectively. 

💡 Question for finance leaders:
Which internal control areas are your teams prioritising in 2026, and what strategies have proven most effective? 

 

References: 

IFRS 15 – Revenue from Contracts with Customers 

ISA 240 – The Auditor’s Responsibilities Relating to Fraud 

ISA 315 – Identifying and Assessing Risks of Material Misstatement

ISA 330 – The Auditor’s Responses to Assessed Risks

PwC Global Economic Crime and Fraud Survey, 2025 

KPMG South Africa Finance & Technology Risk Survey, 2024 

Deloitte Research – Financial Close and Reporting Best Practices, 2024 

ACFE Global Fraud Study, 2024 

COSO Internal Control – Integrated Framework, 2013 

Tshisikhawe Khangale CA (SA), RA

Leave a Reply

Your email address will not be published. Required fields are marked *

Auditors | CA RA Mpako IncHeadquarters
Develop the revolutionary, innovative Audit practice from a holistic perspective.
Corporate Identity
https://i0.wp.com/carampako.co.za/wp-content/uploads/2019/04/CaraMpako-Logo-e1556027459330.png?fit=529%2C240&ssl=1
Get in touchOur Social links
At your convenience, we reach you
CA RA Mpako Inc.Headquarters
Our audit services go beyond compliance to help you identify opportunities for growth
Get in touchCA RA Mpako Social links
Get social with us and never miss a beat!