Controls we design
| Type | Examples |
|---|---|
| Preventive | Approval by value, three-way match before payment, credit limit blocks, locked periods |
| Detective | Bank and ledger reconciliations, exception reports, stock counts, review of manual journals |
| Segregation of duties | Separate people create vendors, approve bills and release payments |
| System (ITGC-aware) | User roles and access, audit trail, change control on masters and configuration |
How we build them in
- Risk and control matrix. For each process we use FMEA to list and rank what could go wrong, the control that addresses it, its owner and frequency, and the evidence it leaves.
- Design in the process. Controls become steps in the future-state process and the SOP, not a separate document nobody reads.
- Configure in the system. Approval rules, user roles, mandatory fields, locked periods and audit trail in Zoho.
- Test. We walk sample transactions through to confirm each control works before go-live.
Who this is for
Companies preparing for statutory or investor audits, Indian subsidiaries whose parent applies group controls such as SOX-style frameworks, and businesses preparing for due diligence or a fundraise. ProLead’s wider governance, risk and internal audit practice is available through prolead.services.
Frequently asked questions
What are internal financial controls (IFC)?
Do controls slow the business down?
Can you help with an auditor's control observations?
General information only, not legal, tax or software licensing advice. Zoho features, editions and prices change, so confirm the current position with Zoho or with our team before you commit. See our disclaimer.