Glossary · Document and evidence governance
Internal control system (ICS)
Also known as: Internal controls
German: Internes Kontrollsystem (IKS)
In corporate governance, an internal control system (ICS) is the set of policies, processes and controls an organization uses to make its operations reliable, its reporting accurate and its conduct compliant with laws, standards and internal rules. Frameworks and regulations such as the Sarbanes-Oxley Act (SOX), ISO/IEC 27001 and the German MaRisk expect it to include segregation of duties.
- Compliance
In one sentence
An internal control system is the set of policies, processes and controls that keeps operations reliable, reporting accurate and conduct compliant.
Example
As part of its internal control system, a machine builder listed in the US documents which roles may create, approve and pay purchase orders, and tests every year that the separation still holds.
How it applies
- SOX (USA): Section 404 of the Sarbanes-Oxley Act requires listed companies to assess and report on their internal control over financial reporting; auditors routinely test segregation of duties as part of it.
- ISO/IEC 27001: Annex A control 5.3 requires conflicting duties and areas of responsibility to be segregated within the information security management system.
- MaRisk (Germany): The minimum requirements for risk management that BaFin sets for banks require a clear separation of incompatible activities (Funktionstrennung) in the internal control system.
- Documentation: Control descriptions, role matrices and test records are controlled documents; keeping them current is part of audit readiness.
Internal control system vs. compliance
An internal control system is a means, not a result: having one does not by itself show that an organization meets SOX, ISO/IEC 27001, MaRisk or any other requirement. The controls must be designed for the actual risks, applied and tested.