Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Document and evidence governance

Internal control system (ICS)

Also known as: Internal controls

German: Internes Kontrollsystem (IKS)

In corporate governance, an internal control system (ICS) is the set of policies, processes and controls an organization uses to make its operations reliable, its reporting accurate and its conduct compliant with laws, standards and internal rules. Frameworks and regulations such as the Sarbanes-Oxley Act (SOX), ISO/IEC 27001 and the German MaRisk expect it to include segregation of duties.

  • Compliance

In one sentence

An internal control system is the set of policies, processes and controls that keeps operations reliable, reporting accurate and conduct compliant.

Example

As part of its internal control system, a machine builder listed in the US documents which roles may create, approve and pay purchase orders, and tests every year that the separation still holds.

How it applies

  • SOX (USA): Section 404 of the Sarbanes-Oxley Act requires listed companies to assess and report on their internal control over financial reporting; auditors routinely test segregation of duties as part of it.
  • ISO/IEC 27001: Annex A control 5.3 requires conflicting duties and areas of responsibility to be segregated within the information security management system.
  • MaRisk (Germany): The minimum requirements for risk management that BaFin sets for banks require a clear separation of incompatible activities (Funktionstrennung) in the internal control system.
  • Documentation: Control descriptions, role matrices and test records are controlled documents; keeping them current is part of audit readiness.

Internal control system vs. compliance

An internal control system is a means, not a result: having one does not by itself show that an organization meets SOX, ISO/IEC 27001, MaRisk or any other requirement. The controls must be designed for the actual risks, applied and tested.

By knowledge.aitechdoc.world · Published September 29, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on the COSO Internal Control — Integrated Framework (2013), Sarbanes-Oxley Act of 2002, Section 404, ISO/IEC 27001:2022 and BaFin MaRisk (AT 4.3.1)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!