{ "@context": "https://schema.org", "@type": "WebPage", "@id": "https://www.planaxion.com/en-ca/articles/internal-control-application-risks#webpage", "name": "Internal control and application risks: a 7-step approach for your new financial solution", "url": "https://www.planaxion.com/en-ca/articles/internal-control-application-risks", "inLanguage": "en-CA", "publisher": { "@type": "Organization", "@id": "https://www.planaxion.com/#organization", "name": "PlanAxion", "url": "https://www.planaxion.com/" } }

Internal control and application risks: a 7-step approach for your new financial solution

Internal control and application risks must be addressed together because every control costs money, and every missing control also costs money—often more, and later on. The balance between the two must be decided during the solution's configuration, not after.
•
image of an innovation lab (for an AI developer tools business)
Key takeaways
  • According to the ACFE’s 2024 Occupational Fraud report, organizations lose approximately 5% of their revenue to fraud each year, with a median loss of $145,000 USD per case.
  • The ACFE (2024) notes that the absence of internal controls is the weakness responsible for 32% of frauds, and the override of existing controls for 19% of cases.
  • The PlanAxion approach, inspired by the COSO framework (1992, revised in 2013), links processes, control objectives, risks, and existing or new controls in 7 steps.
  • Residual risk is calculated as follows: probability of occurrence × impact, taking into account the effectiveness of existing controls (PlanAxion).

Three weeks before a new financial system goes live, the controller at a Laval-based distributor asks the question no one saw coming: who is now responsible for approving changes to supplier banking information? In the old system, a manual signature was required. In the new one, overly broad access permissions allow three people to do it on their own.

This is an application risk, and it is addressed through internal controls, not by emergency fixes after deployment.

The fraud figures cited are based on public international studies and serve as benchmarks; the actual cost of a missing control depends on your specific volumes, processes, and industry.

According to the ACFE’s 2024 Occupational Fraud report, organizations lose an average of 5% of their revenue to fraud each year, based on an analysis of 1,921 real-world cases across 138 countries.

Why address internal controls and application risks together from the start of implementation?

Internal controls and application risks must be handled together because every control costs money, and every missing control also costs money—often more, and later on. The balance between the two should be decided during the solution configuration, not after.

Adding a control once in production requires modifications, revalidation, and new training. The same control, if planned during the design phase, can be configured in a few hours.

What matters is the balance between the resources allocated to controls and the risk to be mitigated. Too many controls slow down operations and end up being bypassed. Too few open the door to errors, fraud, and year-end surprises.

The reference framework remains that of the Committee of Sponsoring Organizations of the Treadway Commission (COSO), published in 1992 and revised in 2013. Our approach is inspired by this framework, integrating three pillars: processes, risks, and controls. It applies equally to cloud-based ERPs and accounts payable management solutions.

What are the 7 steps of the PlanAxion approach inspired by COSO?

The PlanAxion approach consists of 7 steps: selecting processes, setting control objectives, mapping the two, identifying gross risks, qualifying controls, calculating residual risk, and moving to continuous improvement. Each step produces a simple deliverable, often a spreadsheet shared between finance, IT, and the integrator.

  • Step 1: Determine the business processes included in the scope (purchasing, sales, payroll, treasury, financial closing).
  • Step 2: Establish the desired control objectives: availability, integrity and confidentiality of information, asset protection, and compliance with standards and regulations.
  • Step 3: Map each process to the control objectives that actually apply to it. Not all objectives are relevant to every process.
  • Step 4: Identify the risks for each process/objective pairing, without considering existing controls. This is the gross risk.
  • Step 5: Qualify the controls that are currently in place or need to be created for each risk (see the following section).
  • Step 6: Calculate the residual risk: probability of occurrence × impact, taking into account the effectiveness of the evaluated controls.
  • Step 7: Move to continuous improvement with periodic re-evaluation, at least annually, and adjustments proportional to the cost of each control.

Step 4 is the one teams want to skip. They often describe the existing control instead of the risk. Resist this: a well-defined risk without its control often reveals that the current control is protecting something other than what you thought.

How do you qualify a control and calculate residual risk?

A control is classified according to four pairs of criteria (key or secondary, manual, semi-automated or automated, detective or preventive, centralized or decentralized), and the residual risk is then calculated by multiplying the probability of occurrence by the impact, once these controls have been factored in.

This classification dictates where to invest. A key, manual, and decentralized control is fragile: it is the primary candidate for automation in the new solution.

The fire example illustrates the mechanics. A no-smoking policy reduces the probability of occurrence without reducing the scale of potential damage. Sprinklers do not change the probability, but they significantly reduce the impact. A good system combines both types, and the same applies to your financial processes.

Transposed to a financial solution: the segregation of duties between creating a vendor and approving a payment acts on the probability. Automated daily bank reconciliation acts on the impact because it detects anomalies within 24 hours rather than at the end of the month. Your How to build a test strategy for software packages? must also include a scenario for each key control; otherwise, no one will know if it actually works.

Adding a control after deployment requires modifications, revalidation, and training. That same control, when planned during the design phase, only costs a few hours of configuration.

What is the cost of lacking internal controls?

The absence of controls is costly and long-lasting: according to the ACFE’s 2024 Occupational Fraud report, a typical fraud lasts about 12 months before being detected and results in a median loss of $145,000 US. These figures only cover fraud. Data entry errors, duplicate payments, and miscoded entries are not counted, and they are much more frequent.

A few benchmarks from the same study:

  • 5% of annual revenue is lost to fraud, according to estimates by certified examiners (ACFE, 2024).
  • 32% of cases are attributable to a lack of internal controls, and 19% to the override of existing controls (ACFE, 2024).
  • 12 months is the median duration before fraud is detected (ACFE, 2024).
  • $145,000 US in median loss per case, and $1.7M US in average loss (ACFE, 2024).
  • The presence of anti-fraud controls is associated with lower losses and faster detection (ACFE, 2024).

A common reflex is to recreate every manual control from the old system in the new one through customization. This is the wrong approach, as we explain in Modifying software packages: a very costly bad habit. Modern software packages offer standard controls (approval workflows, thresholds, audit logs) that cover the majority of risks without a single line of code.

Where should you start to reduce your application risks?

Start with the two or three processes where money flows (vendor payments, payroll, receipts), define the gross risks with the controller before discussing configuration, and require that every key control has its own test scenario. The rest of the process follows naturally, and the steering committee finally has a list of quantified risks rather than just a general impression.

This question is becoming relevant again with AI agents that execute financial tasks from end to end. They shift application risks rather than eliminating them, as we describe in Agentic AI in the ERP: what changes for your financial processes in 2026. The 7-step approach applies as is: the agent simply becomes a new executor to be qualified, somewhere between manual and automated.

Frequently asked questions

What is an application risk?

An application risk is the possibility that a software solution produces, authorizes, or allows an operation that is contrary to control objectives: inaccurate, unavailable, or disclosed information, misappropriated assets, or non-compliance with rules. It stems from configuration, access profiles, and interfaces, not just fraud. A common example: a profile that allows a user to both create and pay a vendor.

What is the difference between a preventive control and a detective control?

A preventive control reduces the likelihood of an event occurring, such as segregation of duties or mandatory approval before payment. A detective control reduces the impact by identifying the anomaly quickly, such as daily bank reconciliation. A no-smoking policy prevents a fire, while sprinklers limit the damage. A robust system combines both, with a majority of automated controls.

How is residual risk calculated?

Residual risk is calculated by multiplying the probability of occurrence by the impact, after accounting for the effectiveness of the controls in place. First, the gross risk is assessed without controls, then each factor is adjusted based on the qualification of the controls (key or secondary, automated or manual). The resulting score ranks the risks and guides investment.

What is the cost of lacking internal controls according to the ACFE?

According to the ACFE’s 2024 Occupational Fraud report, organizations lose approximately 5% of their revenue to fraud each year, with a median loss of $145,000 USD per case and a median duration of 12 months before detection. The absence of internal controls is a factor in 32% of the cases studied, not including simple errors.