The 5 Internal Controls Auditors Flag First in Small Company Closes
After fifteen years of running closes and sitting on both sides of the audit table, I've learned that auditors don't fish randomly. They walk in with a mental checklist of the control weaknesses that show up in almost every small company, and they test those first because that's where they find findings fastest. If you know what they're going to look at, you can close the gaps before fieldwork instead of scrambling during it.
Here are the five controls that draw the most scrutiny in SMB closes, and how to design each one so it holds up.
1. Review Evidence That Doesn't Exist
The most common finding I see isn't a bad reconciliation. It's a reconciliation nobody can prove was reviewed. Your senior prepares the bank rec, the controller "reviews" it, and there's no signature, no timestamp, no annotation. When the auditor asks for evidence of review, you get a shrug and a "we definitely looked at it."
That's a control deficiency, full stop. A control that leaves no trace didn't happen as far as the audit is concerned.
How to close it
Every review needs three things: who reviewed it, when, and what they actually checked. A reviewer who signs off on a $2.3M AR aging in four seconds isn't reviewing anything, and the metadata will expose that. I tell my teams the review note should include at least one specific observation, for example, "Tied AR subledger to GL, $18,400 variance is the unapplied cash batch clearing 4/2."
In Excel this falls apart because there's no reliable way to capture review timing. A signature cell gets typed in whenever someone remembers. A close platform stamps the reviewer and time automatically when the item is signed off, and the reviewer can't approve until the preparer marks it ready. That sequencing is the whole point of a review control, and a spreadsheet can't enforce it.
2. Manual Journal Entries With No Trail
Manual JEs are where auditors expect to find both errors and, occasionally, something worse. A top-side entry that moves $40,000 out of expense and into a prepaid with a memo that just says "reclass" is a red flag every time.
The problems auditors flag:
- Entries posted with no supporting documentation attached
- The same person preparing and posting with no independent approval
- Vague descriptions that don't explain the business reason
- Entries booked after the close was supposedly finalized
How to close it
Set a dollar threshold that triggers mandatory second-person approval. For a company doing $30M in revenue, I'd require review on any manual entry over $5,000, and any top-side entry regardless of amount. Each entry needs backup attached before it posts, not after.
Log every manual JE in one place with preparer, approver, amount, account, and reason. When you track this in a shared spreadsheet, entries get missed, the log and the ERP drift apart, and by the time the auditor cross-checks them you're explaining discrepancies. A structured close tool keeps the JE log tied to the task and the approval in a single record, so the population the auditor samples from is complete by design.
3. Segregation of Duties in a Five-Person Department
Every SMB controller has heard "you don't have adequate segregation of duties" and wanted to respond, "I have three people." Auditors know your team is small. What they want to see is that you've acknowledged the risk and built compensating controls.
The classic exposure: the person who enters vendors also cuts the checks and reconciles the bank account. That's the exact path a fictitious-vendor scheme runs through.
How to close it
You can't hire your way out of a five-person department, so document the compensating control instead. If the AP clerk sets up vendors, have the controller run a monthly new-vendor report and review every addition against supporting documentation. Have someone outside AP review the bank reconciliation. The key is that the compensating control is evidenced the same way as any other review.
Map who does what across your close tasks so the conflicts are visible. In Excel that map is a stale tab someone updated eighteen months ago. When your close workflow assigns preparers and reviewers per task, the segregation is baked into the process and you can show an auditor exactly who touched what.
4. Cutoff Errors Nobody Catches
Cutoff is where accrual accounting quietly breaks. A $60,000 invoice for December services that hits in January, an unrecorded liability for goods received but not invoiced, revenue booked before delivery. Auditors love cutoff testing because errors here are common and material.
How to close it
Build a cutoff checklist that runs every period, not just year-end:
- Review all invoices received in the first ten days after period end and confirm the expense lands in the right month
- Check the receiving log against recorded payables for goods received not invoiced
- Match revenue recognition to delivery or completion dates, not invoice dates
The reason a platform beats a spreadsheet here is recurrence. The cutoff checklist needs to appear automatically every month with owners and due dates, so it never gets skipped in a busy close. A checklist tab in Excel gets copied forward, edited inconsistently, and eventually abandoned. A close system regenerates the task list each period so the control runs on schedule whether or not anyone remembers it.
5. Reconciliations That Aren't Actually Reconciled
There's a difference between a schedule that agrees to the GL and a reconciliation that explains what's in the account. Auditors flag "reconciliations" that are really just a printout of the GL balance with a checkmark. The tell is an aged reconciling item that's been sitting there for eight months with no resolution.
How to close it
A real reconciliation lists every reconciling item, its age, and a plan to clear it. If you have a $12,000 unidentified difference in a suspense account, the auditor will ask what it is. "We're not sure" on a recurring item is a control problem, because it means the account isn't being managed.
Set an aging policy: any reconciling item over 60 days gets escalated and documented. Track the aging so nothing lingers unnoticed. This is the single hardest thing to do in Excel across dozens of accounts, because the aging lives in your head. A close platform that carries reconciling items forward with their original date makes the stale ones impossible to hide, which is exactly the discipline the auditor is testing for.
The Shift Worth Making
Every one of these findings comes from treating controls as documentation you produce after the fact rather than steps you build into how the close runs. When review sign-offs, JE approvals, cutoff checks, and reconciliation aging are enforced by the workflow itself, the audit evidence is a byproduct of doing the work, not a separate scramble the week before fieldwork.
Before your next close, pick the one control on this list that's weakest for you and redesign it now. Auditors flag these first because they're easy to break. They're also the easiest to fix once you stop relying on memory and start relying on process.
Ready to streamline your month-end close?
ComplyBar helps accounting teams close faster with less stress.
Start Free Trial