The Internal Controls for Small Business Every Owner Should Review Before Year-End

Table of Contents

The conversation almost always opens the same way. A business owner calls, and within two minutes comes a version of the same sentence: she had been with the company eleven years, and there was never any reason to question it. That sentence is the finding. Not the trust itself, which is usually well-placed, but the fact that trust had been asked to do a control’s job. 

Occupational fraud in small businesses is rarely sophisticated. It is almost never committed by an outsider. Most of the time a structural gap made it possible, and a few hours of attention could have closed it. Small business fraud prevention is less about vigilance than about structure. September is the right month to do that work. There is still a full quarter before year-end close, before 1099 season, and before the audits some organizations face. Fixing a control weakness now is planning. Fixing it in February is damage control. 

This blog is a practical review of the internal controls for small business that matter most. It covers segregation of duties on a small team, what to check in the accounting system, and what to activate at the bank. It also covers payroll oversight and one 2026 reporting change that quietly removed a layer of vendor verification. 

Why Small Businesses Absorb the Larger Losses

The Association of Certified Fraud Examiners publishes the definitive global study on occupational fraud every two years, and the newest edition was released in 2026. Occupational Fraud 2026: A Report to the Nations examined 2,402 cases across 143 countries, representing more than $3.4 billion in losses. 

Several findings deserve a small business owner’s attention: 

  • Organizations lose an estimated 5% of annual revenue to occupational fraud each year. 
  • The median loss per case was $104,000. 
  • The median scheme ran 12 months before detection. Schemes caught within six months had a median loss of $40,000. Those running past five years exceeded $1.1 million. 
  • Tips were the leading detection method at 43%, and more than half came from employees. 

The most consequential finding is this one. Organizations with fewer than 100 employees recorded a median loss of $126,000 — higher than the $123,000 median at organizations with more than 10,000 employees. 

The smaller organization absorbed the larger loss. 

That outcome is arithmetic, not character. A $126,000 loss at a 25-person company can be an existential event; at a large enterprise it is a rounding error. Small organizations also have fewer barriers between an opportunity and a decision. The same report found that while 85% of large organizations maintain an established reporting mechanism, only about 25% of small businesses do. 

Weak controls rarely appear on their own. They usually sit alongside other financial warning signs, and our guide on the 8 Financial Red Flags Small Business Owners Should Never Ignore walks through the full set.

Control #1: Segregation of Duties When the Team is Only Three People

The textbook principle is to separate the person who authorizes a transaction, the person who records it, and the person who holds the asset. In a 400-person company that is an org chart exercise. In a six-person company, owners routinely describe it as impossible. 

It is not impossible. It means the third party has to be the owner. A second bookkeeper is not required. Removing a single link from the chain is. 

  • The bookkeeper can enter bills but cannot create a new vendor. Vendor setup requires owner approval and a completed W-9 on file. This change alone eliminates the most common billing scheme. 
  • The bookkeeper prepares checks and ACH batches but does not hold release authority above a defined threshold. The threshold should be meaningful relative to revenue, not symbolic. 
  • Bank statements arrive somewhere the bookkeeper cannot intercept. Reviewing the statement before the person who wrote the checks has reconciled it is among the highest-value fifteen minutes in an owner’s month. 
  • Someone other than the payroll processor approves new hires and pay-rate changes. Ghost employees require the ability to both create a person and pay them. 

None of this requires additional headcount. It requires the owner to occupy one seat in the process rather than delegating it entirely.

Control #2: The Bookkeeper With Full System Access

Nearly every business DWG CPA onboards presents the same finding. One person holds administrator rights in the accounting system, is an authorized user on the bank account, carries the corporate card, and receives the bank statements. 

That person is usually very good at the job. The issue is that the structure has no mechanism for telling anyone if that ever stops being true. 

  • Audit user permissions in the accounting software:  
    The questions are who can void a transaction after it has been recorded and who can edit a closed period. Both can be restricted in QuickBooks Online and comparable platforms, and the audit log can be enabled so changes leave a trail.  

If a bookkeeper can void a check and rebuild the register, the reconciliation proves very little.

  • Reconcile bank and card access against the current staff roster: 
    Former employees with live credentials appear more often than most owners expect. The ACFE study also found that roughly 84% of perpetrators displayed observable warning signs before detection. Living beyond apparent means and unusually close vendor relationships lead the list. 
     
    Refusing to take vacation is another, which is why mandatory time off functions as a genuine control rather than an HR courtesy. Most concealment schemes require ongoing maintenance, and two consecutive weeks away tends to break them. 

Control #3: Bank Protections That Are Available But Rarely Activated

This is the least visible item on the list and likely the highest return on time invested. A single call to a business banker covers all of it. 

  • Positive pay: 
    The business transmits its issued-check file and the bank rejects anything that does not match on payee, amount, and check number. Check tampering remains a common asset misappropriation scheme, and positive pay largely ends it. 
  • ACH debit blocks and filters:  
    Most business accounts will honor an ACH debit from anyone holding the routing and account number. A filter restricts debits to a pre-approved list. 
  • Dual authorization on wires and ACH batches: 
    Business email compromise, where a spoofed message appearing to come from the owner instructs a staff member to release funds, is defeated almost entirely by a second approver and a callback to a known number. 
  • Real-time alerts: 
    Set them for any transaction above a defined amount, any new payee, and any change to account settings. 

Most of these are free. They go unused because no one set aside the time to turn them on.

Control #4: Payroll Oversight When the Function is Outsourced

Where payroll is outsourced, the liability picture is worth understanding precisely. The IRS position is unambiguous: the employer remains the responsible party for the deposit and payment of federal tax liabilities, even when funds have already been forwarded to the provider. If the provider fails to deposit, penalties and interest are assessed against the employer, and an owner can be held personally liable for certain unpaid federal taxes. 

The IRS recommends two steps that carry no cost: 

  • Enroll separately in EFTPS:  
    It is available free from the Treasury at eftps.gov, so deposits made under the business EIN can be independently verified. A quarterly login takes about five minutes. 
  • Keep the address of record in your own name: 
    If notices are redirected to the provider, they arrive somewhere the owner never sees them. 

The New $2,000 1099 Threshold: What It Means for Your Vendor List

One development this year has received almost no attention from a controls standpoint. Among the many provisions in what the One Big Beautiful Bill Act actually means for small business owners, one change quietly altered how much a business knows about the people it pays. 

The reporting threshold for Forms 1099-NEC and 1099-MISC rose from $600 to $2,000 for payments made in 2026, with inflation indexing beginning in 2027. For most businesses that means meaningfully fewer forms to prepare. 

But consider what the old threshold was quietly accomplishing. Every vendor paid more than $600 generated a form, which required a W-9, which required a legitimate taxpayer identification number attached to a real entity. That compliance obligation also functioned as a light annual verification of the vendor list.

In 2026, a fictitious vendor invoiced at $1,750 generates no form at all.

This is not an argument against the new threshold. It is an argument for replacing the verification it used to supply. A W-9 should still be collected from every vendor before the first payment, regardless of the amount anticipated. Vendor setup should remain owner-approved, and the vendor list deserves an annual review that compares addresses against employee addresses and flags entities with no web presence, no phone number, or a P.O. box paired with a generic name. y. It is the result of decisions and actions taken in the months before December 31, not in the weeks after. 

Reconcile monthly through November: A year-end that follows 11 months of clean reconciliations is orderly. A year-end that follows 6 months of deferred reconciliations is a crisis. The goal is to arrive at December with only one month left to close, not three or four. 

Resolve outstanding receivables: Aging receivables that aren’t going to be collected need to be identified and potentially written off before year-end. Bad debt write-offs require documentation — a record of the debt, evidence of collection attempts, and a business decision that the amount is uncollectable. 

Conduct an inventory count if applicable: For product-based businesses, a year-end physical inventory count is often required for accurate financial reporting and tax purposes. This takes time to organize and should be planned in advance. 

Document everything: Deductions require documentation. Vehicle mileage logs, receipts for meals and entertainment, home office calculations, contractor payments for 1099 purposes, all of these need to be current and organized before the filing season begins. 

For a comprehensive year-end bookkeeping checklist, DWG’s earlier post Year-End Bookkeeping Checklist for Small Businesses provides a detailed step-by-step guide.

Owner Override: The Control Failure That Gets Left Off Every List

Most discussions of internal controls for small business end with segregation of duties and bank protections. Few address the failure mode that shows up clearly in the data. The ACFE found that owners and executives accounted for 16% of cases in 2026, up from 12% in 1996, with losses rising sharply alongside the perpetrator’s position.  

Owner override is usually not theft. It is the owner telling the bookkeeper to skip the approval this once because the deal is time-sensitive. It is a personal expense run through the business because it is simpler. It is a closed period reopened to improve a number before it goes to the bank.  

Any single instance may be harmless. The cumulative effect is not. Every override signals that the control is optional and sets precedent for the next person who wants to bypass one. It also makes staff reluctant to question a transaction — the exact moment a business loses the tip that ACFE data identifies as its best detection method.  

Controls are respected when leadership is visibly bound by them. That is the part of small business fraud prevention that costs nothing, and the part most often skipped. 

How DWG CPA Strengthens Internal Controls for Small Business Owners

Internal controls are not an expression of suspicion toward the people who work in the business. They are how a company stops depending on any single person’s continued good judgment, including the owner’s. 

Darrell Groves holds the Certified Fraud Examiner (CFE) designation alongside his CPA and CGMA credentials, and control design is an area DWG CPA addresses directly with clients across construction, healthcare, professional services, and nonprofit organizations. An internal controls review documents where the weaknesses sit, tests whether existing controls work as designed, and produces a prioritized list the business can act on. 

Most control gaps are straightforward to close once identified. What makes small business fraud prevention costly is the assumption that nothing has gone wrong because nothing has been noticed.  

To review where your controls currently stand, schedule a discovery call.