Internal Control for SMEs in Morocco: Key Controls by Cycle

Abdelhakim SoudiInass Barakat

Abdelhakim Soudi, Inass Barakat

Upsilon Consulting

Share
Internal Control for SMEs in Morocco: Key Controls by Cycle

In brief: Internal control refers to the processes, rules and procedures designed by management to ensure the reliability of financial information (SME Auditing Standards Manual, § 3.3.1). General company law does not impose it as a whole on every business, but Law 9-88 imposes some of its building blocks: supporting documents (Art. 1), an accounting organisation manual above MAD 10,000,000 of annual turnover (Art. 4), an annual inventory (Art. 5) and ten-year retention (Art. 22). The auditor assesses your controls in every engagement; their quality determines the extent of the audit work.

You have received comments from your statutory auditor or your group on your procedures. Here is how the auditor reads them, what the law actually requires, the key controls by cycle and a method for dealing with the weaknesses raised. The overall role of the statutory auditor (commissaire aux comptes, CAC) is described in our guide to statutory audit in Morocco.

What auditing standards mean by internal control

The SME Auditing Standards Manual published by the Ordre des experts-comptables (October 2019) gives an operational definition. Internal control “refers to processes, rules and procedures designed by management to ensure the reliability of financial information and the preparation of financial statements, in accordance with the applicable financial reporting framework” (§ 3.3.1).

The manual breaks it down into five components: the control environment, risk assessment, control activities, information and communication, and monitoring. This is the framework the auditor applies to your company.

Two ideas in the manual matter for a CFO:

  • Internal control always exists. “Whatever the size of the entity, there is always some form of internal control, such as the competence of the owner-manager” (§ 3.3.1). It may be informal; it is still internal control.
  • Only controls relevant to the audit concern the auditor. The auditor assesses the controls that mitigate the risks of material misstatement in the financial statements (états de synthèse), whether due to fraud or error. Other controls may be excluded from the scope (§ 3.3.1).

Why the auditor assesses your controls and what difference it makes

A requirement in every engagement

According to the manual, the auditor must obtain an understanding of internal control “for all audit engagements”, including when choosing an entirely substantive approach (§ 3.3.1). This understanding is used to assess the residual risk of material misstatement and to design further audit procedures. The nature, timing and extent of these procedures depend on the assessed risks (§ 3.4).

Inherent risk (business, fraud) is reduced by your controls; what remains is residual risk. The less your controls mitigate the risk, the more the auditor has to cover it through their own testing.

The four steps of the assessment

The manual describes four steps (§ 3.3.2): identify the risks to be mitigated; check that the controls as designed can prevent, or detect and correct, a material misstatement; check that they operate; document how they operate (who performs the control, where, how often, and what document it produces).

Two sentences from the manual deserve to be posted in the accounting department. Inquiries of management “on their own are not sufficient”. And “a documented description of controls that are not implemented (even if they are good), or that are not operating, has no value for the audit” (§ 3.3.2).

What the auditor does when controls are lacking

Where few controls exist, the auditor considers whether the assertions can be addressed through substantive procedures, or whether the absence of controls makes it impossible to obtain sufficient appropriate audit evidence. Concerns about the reliability of the records may lead the auditor to modify the report, or even to withdraw (§ 3.3.1). The errors that lead to a qualification are described in our article on accounting errors that trigger statutory auditor qualifications.

What the law actually requires

Neither Law 9-88 on accounting obligations nor Laws 17-95 and 5-96 on companies require all businesses to have an internal control system in the broad sense. Regulated sectors (banking, insurance, listed companies) are also subject to their own rules. Several legal obligations nonetheless form its foundation.

ObligationTextScope
Each entry states the origin, content and allocation of the transaction and the reference of its supporting documentArt. 1, Law 9-88All traders
Manual describing the accounting organisationArt. 4, Law 9-88Annual turnover above MAD 10,000,000
Inventory of assets and liabilities at least once per financial year, at its endArt. 5, Law 9-88All traders
Inventory book (balance sheet and income statement)Art. 6, Law 9-88All traders
General journal and inventory book numbered and initialled by the court clerkArt. 8, Law 9-88Except natural persons referred to in Art. 1
Retention of accounting documents and supporting documents for ten years; documents kept without blanks or alterationsArt. 22, Law 9-88All traders
Audit committee responsible for monitoring the effectiveness of the internal control, internal audit and, where applicable, risk management systemsArt. 106 bis, Law 17-95SA (public limited company) whose shares are listed on the stock exchange

The content and updating of the Article 4 manual are covered in our article on the accounting procedures manual.

The statutory auditor performs the engagement “to the exclusion of any interference in management” (Art. 166, Law 17-95): the auditor does not design your controls but assesses them, and brings the irregularities and inaccuracies discovered to the attention of the board (Art. 169-3°).

The practical components of internal control

The control activities of an SME fall into five families:

  1. Segregation of duties. Whoever authorises does not execute, does not record and does not hold the asset.
  2. Authorisations. Written signing thresholds and an up-to-date list of bank signatories.
  3. Reconciliations. An accounting balance is reconciled with an independent source, and any difference is explained.
  4. Safeguarding of assets. Restricted physical and IT access, inventories.
  5. Documentation. Each control leaves a record: sign-off, date, name, discrepancies dealt with.

Before choosing the controls, identify the risks by cycle. The method is detailed in our article on risk mapping.

Key controls by cycle

For each cycle: the main risk, the key control and the evidence the auditor will ask for. Adapt to your business.

CycleRiskKey controlEvidence to keep
PurchasesInvoice paid without an order or receipt, fictitious supplierMatching of purchase order / goods received note / invoice before payment; suppliers created by someone who does not make paymentsFile for each invoice with the three signed-off documents; log of creations and changes to supplier master records, in particular bank details
SalesDelivery not invoiced, unjustified credit note, doubtful receivable not followed upMatching of delivery notes / invoices; credit notes authorised by a manager other than the salesperson; monthly review of the aged balanceInvoice and delivery note sequences with no gaps; signed credit notes; annotated aged balance
TreasuryUnauthorised payment, misappropriation, unexplained bank differenceDual signature above a threshold; monthly bank reconciliation prepared by someone who does not make payments and reviewed by another personBank reconciliation statement signed and dated for each account; list of signatories; checked cash statements
PayrollFictitious employee, pay changed without a decisionNew hires, leavers and salary changes approved in writing; review of month-on-month payroll variancesContracts and amendments; signed-off statement of changes; reconciliation of payroll / accounts / social security returns
InventoriesDifference between physical and book inventory, theft, obsolete stockYear-end physical count (Art. 5, Law 9-88) with independent counting; restricted access to storesCount instructions; signed count sheets; statement of differences and how they were dealt with; list of written-down items
Fixed assetsAsset sold or scrapped still on the balance sheet, expense capitalisedAuthorisation of capital expenditure; fixed asset register reconciled with the general ledger; periodic physical countInvestment decisions; reconciled register; count report; disposal documents
ClosingUnsupported manual entry, omitted provision, incorrect cut-offSecond-level review of manual entries and year-end entries; closing checklistClosing entries with supporting document and sign-off; schedule of provisions; balance supported account by account

For fixed assets, see our guide to the physical count of fixed assets; for closing, our annual accounting closing checklist. For treasury and purchases, the manual lists the lack of adequate internal control procedures among the factors creating opportunities for fraud; see our article on fraud audits in Morocco.

Key points:

  • An inventory of assets and liabilities at least once per financial year is a legal obligation (Art. 5, Law 9-88).
  • Supporting documents are kept for ten years (Art. 22, Law 9-88).

Small entities where segregation of duties is impossible

The manual acknowledges this: in small entities, the low number of employees may limit segregation of duties and written documentation. Internal control there “often derives from the control environment” (§ 3.3.1).

The manual adds that “the active involvement of the owner-manager may mitigate certain risks arising from a lack of segregation of duties in a small entity; however, this may increase other risks, such as the risk of management override of controls” (§ 5.3).

In practice, with two or three people in the finance department, build compensating controls:

  • The manager signs, the accountant prepares. No payment without the signature of someone who did not enter the transaction.
  • The manager reviews what they do not prepare. Bank statements received directly by the manager, reconciliations signed off each month, list of transfers compared with invoices.
  • Discrepancies are recorded. A review with no written record is not evidence for the auditor.
  • The manager’s own controls are visible. Because the risk of override increases, transactions the manager initiates personally (advances, expenses, related-party transactions) go through a documented approval, by a partner or by the board depending on your organisation.

For a chief financial officer joining an entity of this kind, these four points come before drafting procedures.

How to deal with weaknesses raised by the auditor

What the auditor communicates to you

According to the manual (§ 4.1), deficiencies may come to light at any point in the engagement. If a deficiency is assessed as significant, the auditor must first discuss it with management, then communicate it in writing to those charged with governance, on a timely basis. Significance is assessed using professional judgement, based on the likelihood of a misstatement occurring and its potential magnitude; if the misstatement has occurred, based on its impact.

If the deficiency concerns the conduct or competence of the owner-manager personally, there is no recipient at an appropriate level within the entity: the auditor must then reconsider whether the engagement can continue (§ 4.1).

What the auditor will look at the following year

In its section on recommendations, the manual provides that the auditor may take into account the measures taken by management in respect of the deficiencies raised, and in particular consider “whether and how these measures have been implemented”, and whether they have been assessed by the internal audit function (§ 5.3). Your response to the deficiency letter will therefore be read again.

For each point, respond in writing: finding, measure adopted, owner, date. If you reject a recommendation, give your reasons and state the compensating control.

90-day action plan: a method

The method below is a suggested way of organising the work, not a requirement of the standards.

PeriodActionsDeliverable
Days 1 to 15Classify the comments by cycle and by severity; one owner per pointDeficiency tracking schedule
Days 16 to 30For each cycle: risk, key control, expected evidence; check the threshold in Art. 4 of Law 9-88Risk and control matrix
Days 31 to 60Put the missing controls in place (signing thresholds, reconciliations, review of third parties, closing checklist)Short procedures, sign-off templates
Days 61 to 75Perform the controls over a full monthEvidence file for the test month
Days 76 to 90Review by a person independent of the cycle; written responseDated, point-by-point response

Prepare your evidence in the format of step 4 of the manual: who, where, how often, what document (§ 3.3.2). The engagement timetable and the documents requested are detailed in our article on preparing for the statutory auditor’s engagement. The course of a statutory or contractual engagement is presented on the audit and statutory audit page.

Points to watch

  1. A procedure is not a control. Without a record of performance, the control has no value for the audit (§ 3.3.2 of the manual).
  2. Threshold in Art. 4 of Law 9-88. Above MAD 10,000,000 of annual turnover, the accounting organisation manual is mandatory.
  3. Management override. The manager’s supervision compensates for the lack of segregation of duties but increases this risk (§ 5.3).
  4. Listed companies. The audit committee reports regularly to the board on the performance of its duties (Art. 106 bis, Law 17-95).

Frequently asked questions

Does any law require all Moroccan companies to have an internal control system?

No: neither Law 9-88 nor Laws 17-95 and 5-96 on companies require all companies to have a comprehensive system. Law 9-88 imposes obligations that form part of one (supporting documents, annual inventory, ten-year retention, accounting organisation manual above MAD 10,000,000 of turnover, Art. 4). Law 17-95 entrusts the audit committee of listed companies with monitoring the effectiveness of internal control (Art. 106 bis).

Why does the statutory auditor assess our internal control?

Under the SME auditing standards (§ 3.3.1), the auditor must understand it in every engagement in order to assess the risk of material misstatement and design further audit procedures. If the controls are reliable, the auditor can test them; otherwise, the auditor relies more heavily on substantive procedures.

How can duties be segregated with two people in the accounting department?

At a minimum, separate the authorisation of payments from their execution and recording, and have the manager review the reconciliations and payment lists. The manual notes that the active involvement of the owner-manager can mitigate the lack of segregation of duties, while increasing the risk of management override of controls (§ 5.3).

Is a written procedure enough for the auditor?

No. According to the manual (§ 3.3.2), a documented description of controls that are not implemented or not operating has no value for the audit, and inquiries of management are not sufficient. There must be a record of the control performed: sign-off, date, discrepancy dealt with.

What should we do about a significant deficiency raised by the auditor?

The auditor must first discuss it with management, then communicate it in writing to those charged with governance (§ 4.1). Respond point by point with an owner, a measure and a date; the auditor may examine whether and how these measures were implemented during the following engagement (§ 5.3).


READ ALSO:

Frequently asked questions

Does any law require all Moroccan companies to have an internal control system?
No: neither Law 9-88 nor Laws 17-95 and 5-96 on companies require all companies to have a comprehensive system. Law 9-88 imposes obligations that form part of one (supporting documents, annual inventory, ten-year retention, accounting organisation manual above MAD 10,000,000 of turnover, Art. 4). Law 17-95 entrusts the audit committee of listed companies with monitoring the effectiveness of internal control (Art. 106 bis).
Why does the statutory auditor assess our internal control?
Under the SME auditing standards (§ 3.3.1), the auditor must understand it in every engagement in order to assess the risk of material misstatement and design further audit procedures. If the controls are reliable, the auditor can test them; otherwise, the auditor relies more heavily on substantive procedures.
How can duties be segregated with two people in the accounting department?
At a minimum, separate the authorisation of payments from their execution and recording, and have the manager review the reconciliations and payment lists. The manual notes that the active involvement of the owner-manager can mitigate the lack of segregation of duties, while increasing the risk of management override of controls (§ 5.3).
Is a written procedure enough for the auditor?
No. According to the manual (§ 3.3.2), a documented description of controls that are not implemented or not operating has no value for the audit, and inquiries of management are not sufficient. There must be a record of the control performed: sign-off, date, discrepancy dealt with.
What should we do about a significant deficiency raised by the auditor?
The auditor must first discuss it with management, then communicate it in writing to those charged with governance (§ 4.1). Respond point by point with an owner, a measure and a date; the auditor may examine whether and how these measures were implemented during the following engagement (§ 5.3).

Upsilon

Consulting

An independent firm, hands-on expertise

Upsilon Consulting is a chartered accounting, audit and tax advisory firm, statutory auditor registered with the Moroccan Institute of Chartered Accountants. Our team of 40+ professionals has been supporting Moroccan and multinational companies for over 15 years. Our multidisciplinary approach and client proximity allow us to support you with rigour and responsiveness.

OEC Members Technical expertise Multidisciplinary approach Client proximity

Let's talk about your project

Contact us for a free consultation. Our experts respond within 24h.

Newsletter

Stay ahead of tax & regulatory changes

Get our expert analyses, practical guides and regulatory alerts delivered to your inbox. Join 500+ professionals who trust us.

No spam. Unsubscribe in one click.

They trust us

PfizerAlstomDrägerCFAO MotorsCDG CapitalBourse de Casablanca