- According to the ACFE's Occupational Fraud 2024 report, organizations lose about 5% of revenue to fraud each year, with a median loss of US$145,000 per case.
- The ACFE (2024) found that a lack of internal controls was the weakness behind 32% of frauds, and the override of existing controls behind another 19%.
- PlanAxion's approach, inspired by the COSO framework (1992, refreshed in 2013), links processes, control objectives, risks and existing or new controls in 7 steps.
- Residual risk is scored as probability of occurrence × impact, adjusted for the effectiveness of the controls in place (PlanAxion).
Three weeks before a new financial system goes live, the controller of a Laval distributor asks the question nobody planned for: who now approves changes to supplier banking details? In the old system, a handwritten signature did it. In the new one, an overly broad access profile lets three people do it alone.
That is an application risk, and it is solved through internal control, not through an emergency fix after go-live.
The fraud figures cited come from public international studies and serve as indicative benchmarks: the real cost of a missing control depends on your volumes, your processes and your industry.
According to the ACFE's Occupational Fraud 2024 report, organizations lose an average of 5% of revenue to fraud each year, based on the analysis of 1,921 real cases across 138 countries.
Why handle internal control and application risks together from the start of implementation?
Internal control and application risks belong together because every control costs money and every missing control costs money too, usually more and later: the balance between the two is decided during configuration of the solution, not afterwards.
A control added in production requires a change, a revalidation and another round of training. The same control, planned at design time, takes a few hours of setup.
What matters is the balance between the resources assigned to controls and the risk being reduced. Too many controls slow operations and end up bypassed. Too few open the door to errors, fraud and year-end surprises.
The reference framework remains the one from the Committee of Sponsoring Organizations of the Treadway Commission (COSO), published in 1992 and refreshed in 2013. Our approach draws on it by integrating three axes: processes, risks and controls. It applies equally to a cloud ERP and to an accounts payable solution.
What are the 7 steps of PlanAxion's COSO-inspired approach?
PlanAxion's approach has 7 steps: select the processes, set the control objectives, map one to the other, name the gross risks, qualify the controls, score the residual risk, then move into continuous improvement. Each step produces a simple deliverable, usually a spreadsheet shared between finance, IT and the integrator.
- Step 1: determine the business processes included in the exercise (purchasing, sales, payroll, treasury, financial close).
- Step 2: establish the control objectives you are pursuing: availability, integrity and confidentiality of information, safeguarding of assets, compliance with standards and regulations.
- Step 3: map each process to the control objectives that genuinely apply to it. Not every objective concerns every process.
- Step 4: name the risks for each process/objective pair, without considering the controls in place. This is the gross risk.
- Step 5: qualify the controls that exist or need to be created for each risk (see the next section).
- Step 6: score the residual risk: probability of occurrence × impact, taking into account the effectiveness of the controls you assessed.
- Step 7: switch to continuous improvement with a periodic reassessment, at least yearly, and adjustments proportionate to the cost of each control.
Step 4 is the one teams want to skip. They describe the existing control right away instead of the risk. Resist: a well-named risk without its control often reveals that the control in place protects something other than what everyone assumed.
How do you qualify a control and score residual risk?
A control is qualified along four pairs of criteria (key or secondary, manual, semi-automated or automated, detective or preventive, centralized or decentralized), and residual risk is then scored by multiplying probability of occurrence by impact once those controls are taken into account.
That qualification tells you where to invest. A key control that is manual and decentralized is fragile: it is the first candidate for automation in the new solution.
The fire example shows the mechanics. A smoking ban lowers the probability of occurrence without reducing the scale of potential damage. Sprinklers do nothing to the probability, but sharply reduce the impact. A sound system combines both types, and the same holds for your financial processes.
Applied to a financial solution: segregation of duties between creating a supplier and approving a payment acts on probability. An automated daily bank reconciliation acts on impact, because it catches the anomaly within 24 hours rather than at month-end. Your ERP Testing Strategy: How to Test a Software Package Before Go-Live should include one scenario per key control, otherwise nobody will know whether it actually works.
A control added after go-live costs a change, a revalidation and a training session. The same control planned at design time costs a few hours of configuration.
How much does the absence of internal controls cost?
The absence of controls costs a lot and for a long time: according to the ACFE's Occupational Fraud 2024 report, a typical fraud lasts about 12 months before detection and causes a median loss of US$145,000. Those figures cover fraud only. Data-entry errors, duplicate payments and misposted entries are not counted, and they are far more frequent.
A few benchmarks from the same study:
- 5% of annual revenue lost to fraud, according to the estimate of Certified Fraud Examiners (ACFE, 2024).
- 32% of cases attributable to a lack of internal controls, and 19% to the override of existing controls (ACFE, 2024).
- 12 months of median duration before a fraud is detected (ACFE, 2024).
- US$145,000 median loss per case, and US$1.7 million average loss (ACFE, 2024).
- The presence of anti-fraud controls is associated with lower losses and quicker detection (ACFE, 2024).
The common reflex is to recreate every manual control from the old system in the new one, through customization. That is the wrong answer, as we explain in Changes to software packages: a very expensive bad habit. Modern packages ship with standard controls (approval workflows, thresholds, audit logs) that cover most risks without a single line of code.
Where should you start to reduce your application risks?
Start with the two or three processes where money moves (supplier payments, payroll, cash receipts), name the gross risks with your controller before talking configuration, and require a test scenario for every key control. The rest of the approach follows naturally, and the steering committee finally gets a list of scored risks instead of a general impression.
The question is back on the agenda with AI agents that execute financial tasks end to end. They shift application risks rather than remove them, as we describe in Agentic AI in ERP: What It Changes for Your Finance Processes in 2026. The 7-step approach applies as is: the agent simply becomes a new performer to qualify, somewhere between manual and automated.
Frequently asked questions
What is an application risk?
An application risk is the possibility that a software solution produces, authorizes or lets through an operation contrary to the control objectives: inaccurate, unavailable or leaked information, a misappropriated asset, a rule not followed. It stems from configuration, access profiles and interfaces, not only from fraud. A common example: a profile that can both create and pay a supplier.
What is the difference between a preventive and a detective control?
A preventive control lowers the probability that an event occurs, such as segregation of duties or mandatory approval before payment. A detective control lowers the impact by spotting the anomaly quickly, such as a daily bank reconciliation. A smoking ban prevents the fire, sprinklers limit the damage. A solid system combines both, with a majority of automated controls.
How is residual risk calculated?
Residual risk is calculated by multiplying the probability of occurrence by the impact, after accounting for the effectiveness of the controls in place. You first assess the gross risk, with no control, then adjust each factor according to how the controls are qualified (key or secondary, automated or manual). The resulting score ranks the risks and directs the investment.
How much does a lack of internal control cost according to the ACFE?
According to the ACFE's Occupational Fraud 2024 report, organizations lose about 5% of revenue to fraud each year, with a median loss of US$145,000 per case and a median duration of 12 months before detection. A lack of internal controls is the weakness behind 32% of the cases studied, and that excludes ordinary errors, which are more frequent still.
- ACFE, press release for Occupational Fraud 2024: A Report to the Nations: estimated loss of 5% of revenue, 1,921 cases analyzed across 138 countries, median duration of 12 months before detection.
- ACFE, Occupational Fraud 2024: A Report to the Nations (full report): median loss of US$145,000, average loss of US$1.7 million, lack of internal controls behind 32% of cases and override of controls behind 19%.
- COSO, Internal Control - Integrated Framework: reference framework published in 1992 and refreshed in 2013, five components of internal control including monitoring.

