+7 925 966 4690, 9am6pm (GMT+3), Monday – Friday
ИД «Финансы и кредит»

JOURNALS

  

FOR AUTHORS

  

SUBSCRIBE

    
Finance and Credit
 

A model for improving the company's financial risk management system in the context of internal financial control deficiencies: Diagnostics, responsibility framework, and control KPIs

ISSUE 6, JUNE 2026

PDF  Article PDF Version

Received: 9 February 2026

Accepted: 25 February 2026

Available online: 30 June 2026

Subject Heading: Financial control

JEL Classification: G32, G34, M42

Pages: 228-240

https://doi.org/10.24891/ybatxp

Mikhail G. MAZMANOV OOO TK Miratorg, Domodedovo, Moscow Oblast, Russian Federation
mi_mazmanov@mail.ru

ORCID id: not available

Subject. The impact of deficiencies in internal financial control (IFC) on the growth of key financial risks for a company — from cash flow gaps and reporting distortions to abuses and asset stripping.
Objectives. The study aims to develop an applied model for improving financial risk management under conditions of control gaps. The model is designed to identify weak points at the level of processes and data, establish accountability, and ensure controllability of control quality.
Methods. The research draws on the principles of risk?based management (ISO?31000), the component?based approach to internal control (COSO), the Three Lines Model by the IIA, and the requirements of Russian regulations for organizing internal control. It also applies methods of control maturity assessment, process mapping, and transactional analytics.
Results. The paper proposes a maturity matrix for internal financial control rated on a scale from 0 to 4, a risk map of financial risks, a RACI framework defining accountability across control points, and a KPI dashboard for monitoring control that integrates both leading and lagging indicators. Furthermore, the study includes examples of analytical tests aimed at detecting anomalies, identifying instances of approval procedure circumvention, and recognizing signs of asset stripping.
Conclusions. Transitioning from sporadic spot checks to continuous, data?driven monitoring and KPI?based management significantly enhances the system’s sensitivity to potential incidents, reduces its dependence on the human factor, and allows for treating the quality of internal financial control as a quantifiable and measurable management function.

Keywords: financial risks, internal financial control, three lines model, responsibility, KPI

References:

  1. Doyle J.T., Ge W., McVay S. Accruals Quality and Internal Control over Financial Reporting. The Accounting Review, 2007, vol. 82, pp. 1141–1170. DOI: 10.2308/accr.2007.82.5.1141
  2. Ashbaugh-Skaife H., Collins D.W., Kinney W.R., LaFond R. The Effect of SOX Internal Control Deficiencies on Firm Risk and Cost of Equity. Journal of Accounting Research, 2009, vol. 47, iss. 1, pp. 1–43. DOI: 10.1111/j.1475-679X.2008.00315.x
  3. Hammersley J.S., Myers L.A., Shakespeare C. Market Reactions to the Disclosure of Internal Control Weaknesses and to the Characteristics of Those Weaknesses under Section 302 of the Sarbanes-Oxley Act of 2002. Review of Accounting Studies, 2007, vol. 13, pp. 141–165. DOI: 10.1007/s11142-007-9046-z EDN: OVWLTQ
  4. Bromiley P., McShane M., Nair A., Rustambekov E. Enterprise Risk Management: Review, Critique, and Research Directions. Long Range Planning, 2015, vol. 48, iss. 4, pp. 265–276. DOI: 10.1016/j.lrp.2014.07.005
  5. Scandizzo S. Risk Mapping and Key Risk Indicators in Operational Risk Management. Economic Notes, 2005, vol. 34, iss. 2, pp. 231–256. DOI: 10.1111/j.0391-5026.2005.00150.x
  6. Alles M., Brennan G., Kogan A., Vasarhelyi M.A. Continuous Monitoring of Business Process Controls: A Pilot Implementation of a Continuous Auditing System at Siemens. International Journal of Accounting Information Systems, 2006, vol. 7, iss. 2, pp. 137–161. DOI: 10.1016/j.accinf.2005.10.004
  7. Vasarhelyi M.A., Alles M.G., Kogan A. Principles of Analytic Monitoring for Continuous Assurance. Journal of Emerging Technologies in Accounting, 2004, vol. 1, iss. 1, pp. 1–21. DOI: 10.2308/jeta.2004.1.1.1
  8. Alles M.G., Kogan A., Vasarhelyi M.A. Putting Continuous Auditing Theory into Practice: Lessons from Two Pilot Implementations. Journal of Information Systems, 2008, vol. 22, iss. 2, pp. 195–214. DOI: 10.2308/jis.2008.22.2.195
  9. Arena M., Arnaboldi M., Azzone G. The Organizational Dynamics of Enterprise Risk Management. Accounting, Organizations and Society, 2010, vol. 35, iss. 7, pp. 659–675. DOI: 10.1016/j.aos.2010.07.003
  10. van der Aalst W. Process Mining: Data Science in Action. 2nd ed. Berlin, Heidelberg, Springer-Verlag, 2016, 467 p. DOI: 10.1007/978-3-662-49851-4 EDN: ULBQLE

View all articles of issue

 

ISSN 2311-8709 (Online)
ISSN 2071-4688 (Print)

Journal current issue

ISSUE 6
JUNE 2026

Archive

Видите ошибку в отчестве? Отключите перевод, это английская версия сайта!