Skip to main content
All guides
9 min read·Last updated: 2026-07-08

Financial internal controls for SMEs: preventing errors and fraud without bureaucracy

A practical framework to protect liquidity, accounting data, and compliance in the Swiss regulatory context

Why internal controls matter for Swiss SMEs

In Swiss small and medium-sized enterprises, financial internal controls are not a luxury reserved for large listed companies. They are the mechanism that separates a typing error from a balance-sheet loss, or an attempted fraud from contained damage that is quickly detected. When a single employee handles invoices, payments, and bank reconciliation, operational risk grows exponentially — regardless of the good faith of those working in the company.

In Switzerland, the obligation to keep orderly accounts (Art. 957 et seq. CO) and to prepare reliable financial statements (Art. 958 CO) also requires companies limited by shares to organize financial control by the governing bodies (Art. 716a CO for AGs; Art. 810 para. 2 CO for GmbHs). There is no single mandatory catalogue for SMEs, but the absence of minimum controls can have concrete consequences: tax disputes, findings by the statutory auditor (if appointed), liability of the governing bodies and, in extreme cases, criminal proceedings for misappropriation or false accounting (Art. 251bis SCC).

The good news: an effective internal control system for an SME does not require bulky manuals or dedicated committees. It requires clarity on critical processes, simple and verifiable rules, and tools that make cash flows visible. This guide proposes a graduated approach suited to business owners, finance managers, and fiduciary firms supporting clients with 2–50 employees.

The three pillars of financial internal controls

Before listing individual measures, it is worth establishing the principles that make them effective. Every internal control should answer one of these fundamental questions:

Segregation of duties

No one person should control the entire cycle of a transaction alone: from order to payment, from accounting entry to bank reconciliation. Even in small teams, segregation can be partial — for example, entrusting payment approval to the owner while an employee prepares payment instructions.

Authorization and limits

Every cash outflow, significant discount, or change to supplier and customer master data should follow approval thresholds defined in writing. CHF 5,000 for a craft business and CHF 50,000 for an industrial SME may require the same relative level of control, but with different amounts.

Traceability and verification

Every financial transaction must leave a verifiable trail: supporting document, accounting entry, system log. Periodic checks — monthly bank reconciliation, supplier aging review, VAT balance comparison — turn accounting from a passive archive into a management tool.

Essential controls matrix by company size

Not all SMEs need the same level of formalization. The table below indicates which controls are priorities based on operational complexity, not revenue alone:

Control Micro (1–3 people) Small SME (4–10 FTE) Structured SME (11+ FTE)
Dual signature / payment approval Owner approves every payment > threshold Two people for payments > CHF 10,000 Formal workflow with written delegations
Bank reconciliation Monthly, verified by owner Monthly, separate from person entering payments Monthly + quarterly review by CFO/auditor
Supplier / IBAN verification Phone confirmation for new suppliers Dual check on master data changes Approved supplier list + sample audit
Inventory and warehouse Annual count Semi-annual count + adjustment entries Perpetual inventory + sampling
Accounts receivable (invoicing) Sequential numbering, no gaps Match orders / deliveries / invoices Flag anomalous discounts and credit notes
Cash and petty cash Daily cash register Cash closing with responsible signature Cash limit + frequent deposits
Accounting software access Individual passwords Profiles with differentiated permissions Access logs + periodic profile review
Documentation Centralized digital archive Rule: «no entry without supporting document» Written policy + 10-year retention (Art. 958f CO)

Controls by process area

Financial risks concentrate in a few recurring flows. Here is how to protect them with concrete measures compatible with day-to-day SME management:

Accounts payable: purchasing and payments

The most frequent frauds in SMEs involve forged invoices, duplicate payments, or fraudulent changes to the IBAN of legitimate suppliers — a technique known as CEO fraud or business email compromise. To counter them:

  • Match every invoice with the purchase order and delivery confirmation before approval.
  • Never change a supplier's bank details based on a single email: always verify with a known contact, preferably by phone.
  • Use a bank payment file (pain.001) generated by accounting software, not manually compiled in Excel spreadsheets.
  • Schedule recurring payments only after initial verification of the IBAN and mandate.

Accounts receivable: invoicing and collections

Invoicing errors and collection delays silently erode margin. Key controls include:

  • Weekly monitoring of customer aging and outstanding invoices beyond contractual terms.
  • Verify that every credit note is linked to an original invoice and approved by a manager.
  • Monthly comparison between recorded revenue, bank receipts, and VAT position due.
  • Automatic flagging of discounts above a predefined threshold (e.g. > 10% of order value).

Payroll and expense reports

Entertainment expenses, mileage reimbursements, and expense reports are sensitive areas, especially when documentation is incomplete:

  • Clear policy on maximum amounts, eligible categories, and mandatory documentation (receipt with VAT, business purpose stated).
  • Expense report approval by a supervisor other than the person who incurred the expense.
  • Timely recording in accounting — delays exceeding 30 days increase the risk of omissions and duplicate reimbursements.
  • For allowances and social contributions (OASI/AI/IC, occupational pension), verify that payroll amounts match the bases declared in filings.

Monthly close and reporting

A disciplined monthly close is the most undervalued internal control. It allows anomalies to be detected before they become annual problems:

  • Reconcile all bank and electronic payment accounts by the fifth business day of the following month.
  • Verify that clearing accounts (VAT, withholding tax, prepayments) show balances consistent with tax deadlines.
  • Analyze the month's accounting adjustments: a high volume of reversals may indicate systemic errors or attempts at concealment.
  • Compare the provisional income statement with the budget or prior year, flagging variances > 15% on major line items.

Warning signs and fraud prevention

SMEs are particularly exposed to internal and external fraud because formal controls and a speak-up culture are often missing. Watch for these indicators:

Operational red flags

  • Employee who refuses extended leave or job rotation with colleagues.
  • Suppliers whose address or IBAN matches those of an employee.
  • Invoices with irregular numbering or repeatedly «round» amounts.
  • Expenses frequently reclassified between cost centers.
  • Access to accounting software at unusual hours or from non-company IP addresses.
  • Customer complaints about payments already recorded as collected.

Effective preventive measures

  • Confidential reporting channel (even informal) for suspected irregularities.
  • Periodic rotation of accounting duties, at least for reconciliation activities.
  • Surprise review of sample transactions on a quarterly basis.
  • Fidelity insurance for staff for significant amounts.
  • Brief annual training (30 minutes) on fraud and financial phishing risks.
  • Reference and background checks for those handling money or sensitive data.

In case of concrete suspicion, document the facts, preserve digital evidence, and promptly consult a lawyer and the statutory auditor. Reporting to the authorities (cantonal police, fedpol for federal offences) should be assessed case by case, but inaction often prolongs the extent of the damage.

Internal controls and legal obligations in Switzerland

The Code of Obligations requires the governing bodies of companies limited by shares to ensure adequate accounting and financial control (Art. 716a CO for AGs; Art. 810 para. 2 CO for GmbHs). For companies subject to ordinary audit, the audit firm verifies the existence of an internal control system (Art. 728a CO). Liability is personal: directors and managers may be held liable for damage caused by an insufficient control system, even in the absence of fraud (Art. 754 CO).

Swiss accounting standards (Swiss GAAP FER or, for larger companies, IFRS/US GAAP) require that applied accounting principles ensure a true and understandable representation of the financial position. Solid internal control directly supports this objective: complete documentation, timely entries, verifiable closing procedures.

For companies limited by shares with no more than 10 full-time equivalents (annual average), waiving limited audit (opting-out, Art. 727a CO) is possible if all partners or shareholders consent and the declaration is entered in the commercial register before the start of the financial year concerned (from 2025, retroactive effect is no longer permitted). This does not eliminate the obligation to keep orderly accounts, but makes an internal self-control system even more important — the auditor will no longer be the «external control» that compensates for procedural gaps.

Obligation / reference Implication for internal controls
Art. 957–958f CO — Accounting Regular bookkeeping, 10-year document retention (Art. 958f CO), traceability of every transaction
Art. 716a / 810 CO — Financial control Non-delegable obligation of governing bodies; system proportionate to size and sector
VAT — Registration and filing Periodic reconciliation between revenue, VAT account, and quarterly or semi-annual return
Withholding tax (Quellensteuer) Verify calculations and remittances on salaries; deadlines according to cantonal model (monthly or quarterly)
Audit (Art. 727–728a CO) Auditor verifies adequacy of internal control; gaps may result in qualifications
Data protection (nFADP) Access to accounting software and financial data subject to necessity principle

Gradual implementation: four weeks to get started

A concrete action plan avoids perfectionism paralysis. Here is a realistic path for an SME starting from zero:

1

Week 1 — Risk mapping

Identify the three processes with the greatest cash movement (usually: supplier payments, customer collections, payroll). For each, note who does what today and where a second control is missing. A one-page document, not a manual.

2

Week 2 — Rules and thresholds

Define approval thresholds, expense report policy, and procedure for new suppliers in writing. Communicate them to the team in a 20-minute meeting. Add the rules as reminders in the accounting software.

3

Week 3 — Pilot monthly close

Perform the first full monthly close: bank reconciliation, aging review, VAT and clearing account checks. Note problems found and correct procedures, not just individual entries.

4

Week 4 — Review and improvement

Assess the adequacy of the system introduced with your fiduciary adviser or auditor. Plan a quarterly sample review (5–10 transactions per area) and an annual update of the rules.

Digitalization: controls integrated in accounting software

Modern accounting software such as Accountex does not replace governance decisions, but makes internal controls easier to apply and verify. Automation eliminates repetitive manual checks and creates digital trails that facilitate audits and reviews.

Features particularly useful for strengthening internal controls in a Swiss SME:

  • User profiles and granular permissions — separate those who enter invoices, those who approve payments, and those who close the accounting period.
  • Approval workflows — block payments or entries exceeding predefined thresholds until authorized by the responsible manager.
  • Automatic bank reconciliation — import transactions and match them with open invoices, with flagging of unreconciled items.
  • Numbering and audit trail — logs of changes to entries, master data, and tax parameters (VAT rates, default accounts).
  • Control reports — customer/supplier aging, variance analysis, real-time VAT position to detect anomalies before filing.
  • E-banking integration — generate pain.001 files from accounting data, reducing transcription errors and manual manipulation fraud.

Practical tip: even with comprehensive software, the most effective control remains the awareness of the owner or finance manager. Set aside 30 minutes per month to review the summary report — revenue, collections, major outflows, bank balance — and compare it with expectations. An anomaly detected in time is worth more than ten formal controls applied too late.

Quick checklist: 10 controls for your SME

Use this list for an immediate self-assessment. Each item not applied represents a risk area to address as a priority:

# Control Frequency
1 Reconciliation of all bank accounts Monthly
2 Dual approval for payments above threshold Every payment
3 Verification of new or changed supplier IBANs Every change
4 Invoice numbering check (sales and purchase) Monthly
5 Customer aging analysis and reminders Weekly
6 Review of expense reports and supporting documents Monthly
7 VAT balance comparison with return Quarterly / semi-annual
8 Software access and permissions review Semi-annual
9 Physical vs. book inventory Annual (or semi-annual)
10 Sample review of critical transactions Quarterly

Financial internal controls should not turn an SME into a bureaucratic office. They should create a light but effective safety net that protects company assets, strengthens the trust of banks and business partners, and simplifies the work of the fiduciary adviser and auditor. Starting with a few well-applied controls is always preferable to an elaborate system that no one actually follows.

Simplify your Swiss accounting

AccountEX handles VAT, QR-invoices and bookings with AI. Start for free.