Goldenthal & Suss

Audit & Assurance

Internal Control Assessments

A clean audit opinion says the numbers are right. It does not say the controls that produced them are any good.

Goldenthal & Suss Consulting P.C. performs internal control assessments for businesses, nonprofits, and government entities. An assessment examines how transactions are authorized, recorded, and reviewed — segregation of duties, cash handling, payroll, procurement, revenue, financial close, and IT access — and reports specific weaknesses and practical improvements, using the COSO Internal Control–Integrated Framework or, for organizations with federal awards, the GAO's Green Book as the benchmark. It is a separate engagement from a financial statement audit, which evaluates controls only as far as needed to plan the audit.

Frameworks
COSO 2013 · GAO Green Book
Areas
Cash, payroll, procurement, revenue, close, IT access
Clients
Businesses, nonprofits, government entities
Output
Prioritized findings and recommendations
01

Why owners and boards commission one

The usual triggers are a change that outgrew the existing controls — rapid growth, a new finance team, a new system, a first federal grant — or an event that exposed them, such as a fraud, a bounced payroll, or a significant audit finding. Owners of closely held businesses frequently commission an assessment when they step back from day-to-day operations and need to know the business can be trusted to run without them watching every check.

Organizations with federal awards have a specific obligation: the Uniform Guidance requires them to maintain effective internal control over those awards, and the auditor will test it.

02

Realistic recommendations

Small organizations rarely have enough people to achieve textbook segregation of duties. Recommending two more hires is easy and useless. The better answer is usually compensating controls — owner or board review of bank statements and payroll registers, dual authorization in the banking platform, restricted system permissions, and a documented monthly close — that close the real gaps with the staff that exists.

What this engagement covers

  • Walkthroughs and documentation of key processes
  • Segregation of duties analysis
  • Cash, disbursement, and payroll controls
  • Procurement and federal award compliance controls
  • Financial close and reporting controls
  • User access and system permission review
  • Fraud risk assessment

Frequently asked

Does our annual audit already cover internal control?

Only partially. A financial statement audit considers internal control as needed to plan and perform the audit, and auditors communicate significant deficiencies they find, but the audit is not designed to evaluate your controls comprehensively. A dedicated assessment is.

What framework do you assess against?

Usually the COSO Internal Control–Integrated Framework (2013), the standard reference for businesses and nonprofits. For organizations with federal awards we also refer to the GAO's Standards for Internal Control in the Federal Government (the Green Book), which the Uniform Guidance names alongside COSO.

Can our auditor also perform the assessment?

With limits. An audit firm can generally assess and recommend, but cannot design and implement the controls or take on management's responsibility for them without impairing independence — and the restrictions are stricter under Government Auditing Standards. We set the scope accordingly when we are also the auditor.

Sources & review
Internal control requirement for federal awards at 2 CFR 200.303 (COSO / GAO Green Book). Reviewed 2026-10-01. Thresholds and deadlines change — confirm current requirements before relying on them.

Request a proposal.

Tell us about your organization and the deadline you are working toward. We will tell you what the engagement involves and what it costs.

Request a Proposal

Staten Island, NY · Freehold, NJ
(718) 227-6035