Internal Controls for Small Business When You Only Have Three People

👉 Curious what graded permissions and a change log look like? Launch an instant live demo — no signup needed →

Quick answer: What do internal controls for small business look like in practice?

They are short, repeatable habits, not corporate paperwork: the owner sees the bank statement before anyone else, spending above an agreed figure needs a second yes, every person has their own login limited to their job, accounts are matched to statements monthly, manual journal entries need approval, finished months get locked, and the change log is read once a month. Nearly all of it is free and takes an afternoon to switch on.

Ask any accountant about small business theft and you'll hear a version of the same story: the long-serving, entirely trusted employee who handled everything. That detail is never the surprise in the story — it's the explanation. In a small company, work gets handed to whoever is willing, and over a few years one capable person quietly ends up with the bank login, the supplier list, the bookkeeping, and the mail. No one chose that arrangement. It assembled itself.

Internal controls are how you take it apart again, and they're much smaller and duller than the phrase implies. A control is just a step that prevents something going wrong unseen — a signature, a monthly comparison, a permission setting, a report someone reads. Enterprises hire teams for this. A company of three needs roughly nine habits, most costing nothing, and this piece works through them in the order we'd switch them on.

Theft is the dramatic case, not the common one. The bulk of what controls actually catch is ordinary error: a bill paid twice, an invoice keyed in again, a cost landing in the wrong quarter. Fraud prevention sells the idea. Books you can plan against are what you'll feel every month.

What an Internal Control Actually Is

A control is any procedure that safeguards assets, keeps the records honest, and makes sure the rules you set are followed. They come in three flavors, and you want some of each:

Read that list and you'll recognize several things you already sort-of do. The gap between "we usually check that" and a real control is definition, ownership, and timing: everyone knows precisely what the step is, a named person performs it, and it happens on a date rather than when it occurs to somebody.

What are the five components auditors look for?

Formal frameworks — the COSO model auditors use for listed companies — break it into five parts: the control environment (does the boss actually care), risk assessment (where can we realistically get hurt), control activities (the approvals, permissions, and reconciliations themselves), information and communication (does everyone know the rules and receive the numbers), and monitoring (does anyone verify the controls still function). Scaled to a five-person company: you care, you know where the cash is exposed, the rules exist, you've told people, and you re-read the page once a year.

Why the Smallest Companies Carry the Most Risk

Fraud researchers keep finding the same thing: relative to their size, the smallest organizations lose the most. It isn't a comment on small-company staff. It's arithmetic — fewer people to divide tasks among, no internal audit function, and an owner whose day is spent on customers rather than the ledger.

Investigators describe three conditions behind most cases: pressure (a private financial squeeze), rationalization ("it's a loan," "I'm owed this"), and opportunity. The first two happen inside someone's life and you'll never see them coming. The third is entirely yours to remove, and removing it is sufficient.

The question was never whether you trust your bookkeeper. It's whether a single distracted month — yours or theirs — should be able to cost you $40,000 before anyone notices.

The Control That Matters Most: Splitting the Chain

If you adopt one thing from this article, adopt this. Segregation of duties means one person never owns a transaction end to end. Three jobs are meant to sit with different hands:

Hand all three to one person and they can invent a supplier, pay it, and book it to consumables — and the accounts will still balance to the penny, because double-entry bookkeeping only demonstrates that an entry is internally consistent, never that it describes something real. "But it balances" has never been evidence of anything.

How do you split duties when there are only three of you?

You can't cleanly divide three roles among three people who are also selling and delivering, and the answer isn't a new hire. The answer is that the owner takes one position in every chain. Not the bookkeeping — just an unavoidable seat somewhere along the route any pound travels. Three habits do it:

  1. Statements land where only you can open them — paper to you, or an email address nobody else holds — and you look before anyone else does.
  2. You approve spending over a line you've drawn (say anything above $500, plus every brand-new supplier regardless of size).
  3. You are the one who signs or releases, even when someone else did all the preparation.

Call it a quarter of an hour a week. It severs the one-person loop at exactly the points that matter.

Nine Controls You Could Switch On This Week

Ordered roughly by protection gained per minute spent.

1. One login per person, with the narrowest rights that still work

Shared accounts silently void every other control you set. When three people sign in as "admin," your change log reports that admin edited the entry, which tells you precisely nothing. Everyone gets their own user, scoped to their role: someone doing data entry has no business deleting transactions or altering company settings, and a person who only ever pulls reports should be read-only. This is a settings screen, not an initiative.

2. The person who approves isn't the person who pays

Whoever keyed the bill shouldn't also be the one letting the money go. If your bank offers dual authorization on transfers, enable it. Where it doesn't, the owner releases. Then write down the figure above which your sign-off is compulsory — a threshold that lives only in your head is not a control.

3. You open the bank statement first

Four minutes a month, and nothing else on this list beats it for value. Before the statement reaches whoever reconciles, you scan: names you don't know, tidy round transfers, payments made out to an individual rather than a company, amounts sitting suspiciously just below your approval line. You'll usually find nothing. The point is that the team knows you look.

4. Match every account to its statement, monthly

Reconciliation sets your records against the bank's authoritative version, item by item. It's the detective control that simultaneously catches duplicated entries, missing deposits, unbooked charges, and misappropriation — and where it's skipped, nothing else in the accounts can be relied on. Everything issuing a statement qualifies: current accounts, savings, each card, PayPal, Stripe, credit lines. Our walkthrough on how to reconcile a bank statement covers the mechanics and the won't-balance scenarios. Slot it into your monthly close routine on a fixed day.

5. Paperwork before payment, every time

No document, no money. For anything physical arriving, apply three-way matching: the order (what we asked for), the delivery record (what turned up), and the supplier's invoice (what we're charged) all have to agree before approval. That one rule shuts down invented-supplier schemes and intercepts quantity and pricing errors that would otherwise be paid on trust. Our accounts payable walkthrough shows where matching sits in the wider payment route.

6. Make manual journal entries pass through someone

Everyday transactions leave a trail behind them. Manual journals don't — they're the tool by which a shortfall gets tucked into sundry expenses or a stubborn balance gets nudged until a reconciliation agrees. Requiring that a manual entry be reviewed by a more senior user before it posts is a single toggle, and it takes away the most-used concealment device in bookkeeping.

7. Lock a month once it's finished

When you've reviewed and signed off a period, seal it. Leave it open and an old transaction can be quietly amended — rewriting figures you already circulated, upsetting the opening balance on your next reconciliation, and undermining every comparison you draw afterwards. The lock is the thing that converts a review into a genuine close, and it pairs naturally with your year-end closing entries.

8. Read the supplier and customer lists once a quarter

Four times a year, a quarter of an hour each. Sort suppliers by newest and by recently amended. Watch for entries with a P.O. box and no phone number, addresses matching a staff member's, near-twins (Acme Supply against Acme Supplies), and bank details altered lately. Redirecting a genuine supplier's payment details is among the most common frauds going right now, and it stays invisible unless somebody reviews the list.

9. Open the change log

Decent accounting software records who created, amended, or removed every record, with a timestamp. Owning that log isn't the control — reading it is. Monthly, filter to deletions, voided items, and edits touching closed periods, then ask about anything unfamiliar. Ten minutes. As with the bank statement, most of its force comes from people knowing it gets opened.

Where Small Companies Actually Lose Money

Each asset leaks differently. The usual loss routes, and the control that shuts each one:

Exposure How it shows up The control that catches it
Invented suppliers Payments to a company that doesn't exist, or padded invoices from one that does Owner approves every new supplier; three-way match; quarterly list review
Payment tampering Altered payees, transfers nobody approved, changed supplier bank details Owner opens statements; dual authorization; bank-side payment verification
Skimming Cash or a customer payment taken before it ever reaches the books Tie deposits to the sales record; review AR ageing; send customer statements
Expense claims Personal spending or repeat receipts submitted as business cost Receipts mandatory; reviewed by someone other than the claimant; spot-checks
Payroll Employees who don't exist, padded hours, rate changes nobody authorized Owner signs off every hire and rate change; read the payroll register
Stock Goods leaving quietly and being written down as shrinkage Counts performed by someone with no control over the records

Look down that final column and one shape repeats: either the owner occupies one of two required seats, or an independent person compares two records that ought to agree.

Put It on Paper — a Page, Not a Policy Binder

Controls stored only in your memory evaporate the week you take a vacation or the bookkeeper moves on. Skip the manual; write one page answering five questions:

That page outlives staff changes, ends "I assumed you'd approved it" disputes, and is the first document a lender, insurer, or incoming accountant will request. If you're heading towards a credit facility or outside investment, it earns its keep several times over.

What Your Software Should Be Doing Unprompted

Roughly half the list above is policy you have to uphold personally. The rest ought to be enforced by the system so a hectic Thursday can't quietly bypass it — and this is where plenty of small business accounting tools fall down, because access is all-or-nothing and the change log is thin or missing entirely.

Kantivo was built with these in place rather than added later. It runs GAAP-compliant double-entry bookkeeping on your own machine, with five graded permission levels — admin, manager, accountant, bookkeeper, viewer — assigned per company, so someone can administer one entity while holding read-only rights on another. Journal entry approval can be made compulsory, with a minimum approver level you choose. A change log captures who created, edited, or deleted each record and when. Completed periods can be locked. Reconciliation, receivables and payables ageing, and budget-versus-actual handle the detective half. And because it's desktop software holding your data on your own computer, access control begins with who can sit at the keyboard.

Safeguards That Come With the Software

Kantivo includes per-company user roles, journal entry approvals, a full change log, period locking, and bank reconciliation — the controls on this list, enforced for you, at one flat annual price with no monthly bill creeping upward every year.

Start Free 30-Day Trial Try Live Demo

The Takeaway

Internal controls for small business have nothing to do with suspecting your people. They exist so that nobody — you on a scattered Tuesday very much included — can shift money or rewrite a record without a second set of eyes somewhere along the line. Almost every control here is free, and most take minutes to establish.

If this week only has room for three: issue individual logins with minimal rights, start opening the bank statement before anyone else does, and fix reconciliation to a calendar date. Those three cover the realistic risk in a company this size. Add the others as you go, write the page, and reread it once a year.

Frequently Asked Questions

What counts as an internal control in a small company?

Any routine step that makes it hard for money or data to move without a second pair of eyes. In a very small company that usually means approval limits on spending, individual logins with limited rights, a monthly match of books to bank statement, review before a manual journal entry posts, a locked period once the month is finished, and someone actually reading the change log.

Are there different categories of internal control?

Three. Preventive controls block the problem up front - permissions, spending limits, locked periods. Detective controls surface it afterwards - reconciliations, change-log reviews, budget-versus-actual comparisons. Corrective controls repair the damage and tighten whatever let it through. Leaning on only one category leaves an obvious gap.

How can two or three people separate duties?

You cannot split authorizing, holding, and recording three ways with three people who also run the business. Instead the owner claims one position in every money chain: the statements arrive where only you can see them, spending past an agreed figure needs your yes, and you are the one who releases payment even when someone else prepared it. That alone breaks the single-person loop.

What actually stops an employee from stealing?

Closing off the opening. Theft in tiny companies almost always traces back to one trusted person holding both the money and the records unobserved. Individual accounts with narrow rights, paperwork required before payment, owner sign-off on any new supplier, a monthly reconciliation, and a change log that is visibly reviewed remove nearly all of that room.

Should a very small business document its controls?

Write them down, but keep it to a page. Note who signs off on what and at which amount, who reconciles which accounts and by when, what paperwork a payment requires, and when the period closes. That page keeps working when staff change, ends arguments about who approved something, and is exactly what a bank or accountant will ask you for.

Can accounting software do any of this for me?

The controls worth automating are the ones a busy day would otherwise skip. Graded user permissions decide what each person can reach, journal entry approval holds a manual entry until a senior user signs it, a change log captures who touched which record and when, and locking a finished period blocks retroactive edits. Kantivo ships with all four.

Related Articles