Controls we review
Many subsidiaries have group policies on paper, while the warehouse runs on habits, shared logins and signatures added after the event. We look at both the design of the controls and whether they actually operate.
- Roles and responsibilities: who receives, stores, issues and records stock
- Physical access: keys, gates, restricted zones, visitors and contractors
- System access: user rights in 1C, ERP or WMS, shared accounts, leavers still active
- Approvals: write-offs, adjustments, returns, transfers and price or cost changes
- Segregation of duties: whether one person can move stock and also change its record
- Paper versus system: whether documents and system entries agree and in what order they are made
How we test whether controls work
We start with walkthroughs, asking staff to show us each step rather than describe it. Then we test a sample of transactions per control: for example, whether each write-off in the sample had an approved document before it was posted, or whether adjustments were made by users who also handle stock.
System access is reviewed from a user rights extract, compared with the organisation chart and the list of current employees. Physical controls are checked on site, at different times of day where possible, because controls that hold during the morning shift may weaken at night or at weekends.
Gaps and fixes that fit a real warehouse
A small site cannot always separate every duty, so we focus on compensating controls that are realistic: a regular review of adjustments by finance, a short monthly exception report, or a spot check by someone outside the warehouse. Each gap in the report is rated by risk and paired with a specific fix, an owner and a suggested order of work.
Where a control depends on local accounting or tax requirements, we note it and recommend confirming the detail with your local accountant or auditor.
Why controls drift in subsidiaries
Controls in a foreign subsidiary rarely fail all at once. They drift. A storekeeper covers for a colleague on leave and keeps the extra system rights afterwards. A manager signs approvals in bulk at the end of the month because the paper process is slow. A temporary workaround during a system change becomes permanent. Each step seems reasonable on its own, but together they leave the warehouse with controls that exist only in the policy manual.
A periodic internal controls review catches this drift before it shows up as losses or audit findings. It also gives the local team a fair chance to explain why a control does not fit the way the warehouse works, which often leads to a simpler and stronger control rather than a stricter rule that nobody follows.
What you receive
- D1Control map of roles, access and approvals in the warehouse
- D2Test results for each key control, with evidence
- D3Segregation of duties conflicts from the user rights review
- D4Rated list of gaps with specific fixes and owners
- D5Report in English, with a local-language version on request
Common questions
Q1Do we need written procedures before the review?
No. If procedures are missing, the review documents how the warehouse works today, which is a useful starting point for writing them.
Q2Can you review user rights in 1C?
Yes, from an export of users and their rights. We do not need administrator access to your system.
Q3Will you help implement the fixes?
The report is designed so your team can implement it. We can return later to check that the changes work in practice.