Home/ Volume 11/ Chapter 1
Show menu button
The Golden Rule

A business can't control pressure or rationalization, but it can remove opportunity entirely.

Fraud requires all three legs of the triangle at once. Remove one, and fraud becomes far less likely.

OpportunityThe one leg internal controls actually remove.
PressureLives in someone's private life, outside the business's reach.
RationalizationOnly indirectly shaped, through fair pay and culture.

Not an insult to trusted staff

Controls protect honest employees at least as much as the business.

Build it before, not after

The cheapest time for a control is before it's ever tested.

Scales down, doesn't disappear

Even a two-person business has one relationship to check.

No single point of control

The one rule every chapter in this volume applies differently.

1

Definition

Imagine a business introduces a rule that no single payment above a set amount can go out without a second person's sign-off. The employee whose sole authority just got reduced feels, at first, mildly distrusted. Months later, that same rule catches a fraudulent payment request before it can be sent. The employee wasn't the one being protected from suspicion, she was the one the rule protected from ever being wrongly suspected, because the record now shows two people reviewed it, not one person acting alone.

Internal controls

are the rules that decide who can count cash, approve an expense, sign a payment, or access a company account, designed so that no single person ever has complete, unchecked power over money or goods, however trusted they are.

In One Sentence

Internal controls aren't built because employees are assumed dishonest, they're built because trust alone is not a control. This volume is the specific mechanism behind Chapter 3's fraud "risk of presence" and the "Loose Cannon" quadrant from Volume 06, Chapter 1. Unchecked authority, held long enough, eventually costs a business money, regardless of how honest any individual person is.

2

The Fraud Triangle

The fraud triangle: opportunity, pressure, and rationalization must all be present for fraud to occur, and internal controls remove opportunity

A well-established idea in risk management: fraud requires three things at once. Remove any one, and fraud becomes far less likely.

Opportunity

Unchecked access, no second reviewer, no checking against records. Yes, this is what internal controls remove.

Pressure

Personal financial strain pushing someone toward temptation. No, this lives in someone's private life.

Rationalization

The internal story that makes it feel acceptable. Only indirectly, through fair pay and culture.

Vol 28
LegWhat It MeansCan the Business Control It?
OpportunityUnchecked access, no second reviewer, no checking against recordsYes, this is what internal controls remove
PressurePersonal financial strain pushing someone toward temptationNo, this lives in someone's private life
RationalizationThe internal story that makes it feel acceptable ("I'm underpaid," "I'll pay it back")Only indirectly, through fair pay and culture (Volume 28)

This chapter's whole argument in one line: a business cannot control pressure or rationalization, but it can remove opportunity entirely, and that's exactly what every chapter in this volume does.

Memory Trick

Controls don't assume dishonesty, they remove temptation. The most protective thing a business can do for an honest employee is make sure they're never placed in a position where a bad month and one moment of weakness could cost them everything.

3

The Core Principle: No Single Point of Control

Every chapter in this volume is one application of the same rule:

ChapterThe Rule, Applied
Chapter 2: Segregation of DutiesNo one person handles an entire transaction alone
Chapter 3: Cash ControlsNo one person counts, banks, and reconciles cash alone
Chapter 4: Approval AuthorityNo one person approves unlimited spending alone
Chapter 5: Access ControlsNo one person holds every password and access credential alone
4

Example Story: The Control That Was Never About Distrust

Here's the full version of the second-signature story from the start of this chapter.

When MANIAC MINDZ introduced a second-signature rule for payments above a set amount (Volume 10, Chapter 5's phishing story), the staff member whose sole authority was reduced initially felt mildly distrusted. Months later, that same rule caught a fraudulent payment request before it could be sent, protecting not just the business's money, but that same employee from ever being wrongly suspected, since the record now clearly showed two people reviewed every large payment, not one person acting alone.

5

Across Industries

City Kitchen

Opportunity to closeOne person both taking cash and recording the till total

Rapid Auto Works

Opportunity to closeOne person both ordering parts and approving the supplier invoice

Nimbus Labs

Opportunity to closeOne developer holding sole access to the live customer database
BusinessAn "Opportunity" Worth Closing
City KitchenOne person both taking cash and recording the till total
Rapid Auto WorksOne person both ordering parts and approving the supplier invoice
Nimbus LabsOne developer holding sole access to the live customer database
6

Common Mistakes

Common Mistake #1: Treating Controls as an Insult to Trusted Staff

As the example story shows, controls protect honest employees at least as much as they protect the business.

Common Mistake #2: Only Adding Controls After a Loss

The cheapest time to build a control is before it's ever tested, see Volume 10's whole risk-response philosophy.

Common Mistake #3: Assuming Small Teams Don't Need Controls

A two-person business still has exactly one relationship where "no single point of control" can be tested. Controls scale down, they don't disappear.

7

Quiz Yourself

Quiz 1
Name the three legs of the fraud triangle, and which one internal controls actually target.
Opportunity, pressure, and rationalization, internal controls remove opportunity, the only leg the business can directly control.
Quiz 2
What is the one core principle behind every chapter in this volume?
No single person should have complete, unchecked control over an entire transaction, cash process, spending decision, or set of access credentials.
8

Practice Exercise

List every point in your business where one person currently holds complete, unchecked control over money, goods, or access. For each, note which chapter of this volume (2–5) closes that specific gap.

9

Quick Summary

Quick Summary

  • Internal controls exist because trust alone is not a control, not because employees are assumed dishonest.
  • The fraud triangle (opportunity, pressure, rationalization) shows why: controls remove the one leg a business can actually control.
  • The core principle repeated across this volume: no single person controls an entire transaction, cash process, approval, or access point alone.
  • Controls protect honest employees as much as they protect the business.