In brief: Internal control refers to the processes, rules and procedures designed by management to ensure the reliability of financial information (SME Auditing Standards Manual, § 3.3.1). General company law does not impose it as a whole on every business, but Law 9-88 imposes some of its building blocks: supporting documents (Art. 1), an accounting organisation manual above MAD 10,000,000 of annual turnover (Art. 4), an annual inventory (Art. 5) and ten-year retention (Art. 22). The auditor assesses your controls in every engagement; their quality determines the extent of the audit work.
You have received comments from your statutory auditor or your group on your procedures. Here is how the auditor reads them, what the law actually requires, the key controls by cycle and a method for dealing with the weaknesses raised. The overall role of the statutory auditor (commissaire aux comptes, CAC) is described in our guide to statutory audit in Morocco.
What auditing standards mean by internal control
The SME Auditing Standards Manual published by the Ordre des experts-comptables (October 2019) gives an operational definition. Internal control “refers to processes, rules and procedures designed by management to ensure the reliability of financial information and the preparation of financial statements, in accordance with the applicable financial reporting framework” (§ 3.3.1).
The manual breaks it down into five components: the control environment, risk assessment, control activities, information and communication, and monitoring. This is the framework the auditor applies to your company.
Two ideas in the manual matter for a CFO:
- Internal control always exists. “Whatever the size of the entity, there is always some form of internal control, such as the competence of the owner-manager” (§ 3.3.1). It may be informal; it is still internal control.
- Only controls relevant to the audit concern the auditor. The auditor assesses the controls that mitigate the risks of material misstatement in the financial statements (états de synthèse), whether due to fraud or error. Other controls may be excluded from the scope (§ 3.3.1).
Why the auditor assesses your controls and what difference it makes
A requirement in every engagement
According to the manual, the auditor must obtain an understanding of internal control “for all audit engagements”, including when choosing an entirely substantive approach (§ 3.3.1). This understanding is used to assess the residual risk of material misstatement and to design further audit procedures. The nature, timing and extent of these procedures depend on the assessed risks (§ 3.4).
Inherent risk (business, fraud) is reduced by your controls; what remains is residual risk. The less your controls mitigate the risk, the more the auditor has to cover it through their own testing.
The four steps of the assessment
The manual describes four steps (§ 3.3.2): identify the risks to be mitigated; check that the controls as designed can prevent, or detect and correct, a material misstatement; check that they operate; document how they operate (who performs the control, where, how often, and what document it produces).
Two sentences from the manual deserve to be posted in the accounting department. Inquiries of management “on their own are not sufficient”. And “a documented description of controls that are not implemented (even if they are good), or that are not operating, has no value for the audit” (§ 3.3.2).
What the auditor does when controls are lacking
Where few controls exist, the auditor considers whether the assertions can be addressed through substantive procedures, or whether the absence of controls makes it impossible to obtain sufficient appropriate audit evidence. Concerns about the reliability of the records may lead the auditor to modify the report, or even to withdraw (§ 3.3.1). The errors that lead to a qualification are described in our article on accounting errors that trigger statutory auditor qualifications.
What the law actually requires
Neither Law 9-88 on accounting obligations nor Laws 17-95 and 5-96 on companies require all businesses to have an internal control system in the broad sense. Regulated sectors (banking, insurance, listed companies) are also subject to their own rules. Several legal obligations nonetheless form its foundation.
| Obligation | Text | Scope |
|---|---|---|
| Each entry states the origin, content and allocation of the transaction and the reference of its supporting document | Art. 1, Law 9-88 | All traders |
| Manual describing the accounting organisation | Art. 4, Law 9-88 | Annual turnover above MAD 10,000,000 |
| Inventory of assets and liabilities at least once per financial year, at its end | Art. 5, Law 9-88 | All traders |
| Inventory book (balance sheet and income statement) | Art. 6, Law 9-88 | All traders |
| General journal and inventory book numbered and initialled by the court clerk | Art. 8, Law 9-88 | Except natural persons referred to in Art. 1 |
| Retention of accounting documents and supporting documents for ten years; documents kept without blanks or alterations | Art. 22, Law 9-88 | All traders |
| Audit committee responsible for monitoring the effectiveness of the internal control, internal audit and, where applicable, risk management systems | Art. 106 bis, Law 17-95 | SA (public limited company) whose shares are listed on the stock exchange |
The content and updating of the Article 4 manual are covered in our article on the accounting procedures manual.
The statutory auditor performs the engagement “to the exclusion of any interference in management” (Art. 166, Law 17-95): the auditor does not design your controls but assesses them, and brings the irregularities and inaccuracies discovered to the attention of the board (Art. 169-3°).
The practical components of internal control
The control activities of an SME fall into five families:
- Segregation of duties. Whoever authorises does not execute, does not record and does not hold the asset.
- Authorisations. Written signing thresholds and an up-to-date list of bank signatories.
- Reconciliations. An accounting balance is reconciled with an independent source, and any difference is explained.
- Safeguarding of assets. Restricted physical and IT access, inventories.
- Documentation. Each control leaves a record: sign-off, date, name, discrepancies dealt with.
Before choosing the controls, identify the risks by cycle. The method is detailed in our article on risk mapping.
Key controls by cycle
For each cycle: the main risk, the key control and the evidence the auditor will ask for. Adapt to your business.
| Cycle | Risk | Key control | Evidence to keep |
|---|---|---|---|
| Purchases | Invoice paid without an order or receipt, fictitious supplier | Matching of purchase order / goods received note / invoice before payment; suppliers created by someone who does not make payments | File for each invoice with the three signed-off documents; log of creations and changes to supplier master records, in particular bank details |
| Sales | Delivery not invoiced, unjustified credit note, doubtful receivable not followed up | Matching of delivery notes / invoices; credit notes authorised by a manager other than the salesperson; monthly review of the aged balance | Invoice and delivery note sequences with no gaps; signed credit notes; annotated aged balance |
| Treasury | Unauthorised payment, misappropriation, unexplained bank difference | Dual signature above a threshold; monthly bank reconciliation prepared by someone who does not make payments and reviewed by another person | Bank reconciliation statement signed and dated for each account; list of signatories; checked cash statements |
| Payroll | Fictitious employee, pay changed without a decision | New hires, leavers and salary changes approved in writing; review of month-on-month payroll variances | Contracts and amendments; signed-off statement of changes; reconciliation of payroll / accounts / social security returns |
| Inventories | Difference between physical and book inventory, theft, obsolete stock | Year-end physical count (Art. 5, Law 9-88) with independent counting; restricted access to stores | Count instructions; signed count sheets; statement of differences and how they were dealt with; list of written-down items |
| Fixed assets | Asset sold or scrapped still on the balance sheet, expense capitalised | Authorisation of capital expenditure; fixed asset register reconciled with the general ledger; periodic physical count | Investment decisions; reconciled register; count report; disposal documents |
| Closing | Unsupported manual entry, omitted provision, incorrect cut-off | Second-level review of manual entries and year-end entries; closing checklist | Closing entries with supporting document and sign-off; schedule of provisions; balance supported account by account |
For fixed assets, see our guide to the physical count of fixed assets; for closing, our annual accounting closing checklist. For treasury and purchases, the manual lists the lack of adequate internal control procedures among the factors creating opportunities for fraud; see our article on fraud audits in Morocco.
Key points:
- An inventory of assets and liabilities at least once per financial year is a legal obligation (Art. 5, Law 9-88).
- Supporting documents are kept for ten years (Art. 22, Law 9-88).
Small entities where segregation of duties is impossible
The manual acknowledges this: in small entities, the low number of employees may limit segregation of duties and written documentation. Internal control there “often derives from the control environment” (§ 3.3.1).
The manual adds that “the active involvement of the owner-manager may mitigate certain risks arising from a lack of segregation of duties in a small entity; however, this may increase other risks, such as the risk of management override of controls” (§ 5.3).
In practice, with two or three people in the finance department, build compensating controls:
- The manager signs, the accountant prepares. No payment without the signature of someone who did not enter the transaction.
- The manager reviews what they do not prepare. Bank statements received directly by the manager, reconciliations signed off each month, list of transfers compared with invoices.
- Discrepancies are recorded. A review with no written record is not evidence for the auditor.
- The manager’s own controls are visible. Because the risk of override increases, transactions the manager initiates personally (advances, expenses, related-party transactions) go through a documented approval, by a partner or by the board depending on your organisation.
For a chief financial officer joining an entity of this kind, these four points come before drafting procedures.
How to deal with weaknesses raised by the auditor
What the auditor communicates to you
According to the manual (§ 4.1), deficiencies may come to light at any point in the engagement. If a deficiency is assessed as significant, the auditor must first discuss it with management, then communicate it in writing to those charged with governance, on a timely basis. Significance is assessed using professional judgement, based on the likelihood of a misstatement occurring and its potential magnitude; if the misstatement has occurred, based on its impact.
If the deficiency concerns the conduct or competence of the owner-manager personally, there is no recipient at an appropriate level within the entity: the auditor must then reconsider whether the engagement can continue (§ 4.1).
What the auditor will look at the following year
In its section on recommendations, the manual provides that the auditor may take into account the measures taken by management in respect of the deficiencies raised, and in particular consider “whether and how these measures have been implemented”, and whether they have been assessed by the internal audit function (§ 5.3). Your response to the deficiency letter will therefore be read again.
For each point, respond in writing: finding, measure adopted, owner, date. If you reject a recommendation, give your reasons and state the compensating control.
90-day action plan: a method
The method below is a suggested way of organising the work, not a requirement of the standards.
| Period | Actions | Deliverable |
|---|---|---|
| Days 1 to 15 | Classify the comments by cycle and by severity; one owner per point | Deficiency tracking schedule |
| Days 16 to 30 | For each cycle: risk, key control, expected evidence; check the threshold in Art. 4 of Law 9-88 | Risk and control matrix |
| Days 31 to 60 | Put the missing controls in place (signing thresholds, reconciliations, review of third parties, closing checklist) | Short procedures, sign-off templates |
| Days 61 to 75 | Perform the controls over a full month | Evidence file for the test month |
| Days 76 to 90 | Review by a person independent of the cycle; written response | Dated, point-by-point response |
Prepare your evidence in the format of step 4 of the manual: who, where, how often, what document (§ 3.3.2). The engagement timetable and the documents requested are detailed in our article on preparing for the statutory auditor’s engagement. The course of a statutory or contractual engagement is presented on the audit and statutory audit page.
Points to watch
- A procedure is not a control. Without a record of performance, the control has no value for the audit (§ 3.3.2 of the manual).
- Threshold in Art. 4 of Law 9-88. Above MAD 10,000,000 of annual turnover, the accounting organisation manual is mandatory.
- Management override. The manager’s supervision compensates for the lack of segregation of duties but increases this risk (§ 5.3).
- Listed companies. The audit committee reports regularly to the board on the performance of its duties (Art. 106 bis, Law 17-95).
Frequently asked questions
Does any law require all Moroccan companies to have an internal control system?
No: neither Law 9-88 nor Laws 17-95 and 5-96 on companies require all companies to have a comprehensive system. Law 9-88 imposes obligations that form part of one (supporting documents, annual inventory, ten-year retention, accounting organisation manual above MAD 10,000,000 of turnover, Art. 4). Law 17-95 entrusts the audit committee of listed companies with monitoring the effectiveness of internal control (Art. 106 bis).
Why does the statutory auditor assess our internal control?
Under the SME auditing standards (§ 3.3.1), the auditor must understand it in every engagement in order to assess the risk of material misstatement and design further audit procedures. If the controls are reliable, the auditor can test them; otherwise, the auditor relies more heavily on substantive procedures.
How can duties be segregated with two people in the accounting department?
At a minimum, separate the authorisation of payments from their execution and recording, and have the manager review the reconciliations and payment lists. The manual notes that the active involvement of the owner-manager can mitigate the lack of segregation of duties, while increasing the risk of management override of controls (§ 5.3).
Is a written procedure enough for the auditor?
No. According to the manual (§ 3.3.2), a documented description of controls that are not implemented or not operating has no value for the audit, and inquiries of management are not sufficient. There must be a record of the control performed: sign-off, date, discrepancy dealt with.
What should we do about a significant deficiency raised by the auditor?
The auditor must first discuss it with management, then communicate it in writing to those charged with governance (§ 4.1). Respond point by point with an owner, a measure and a date; the auditor may examine whether and how these measures were implemented during the following engagement (§ 5.3).
READ ALSO:
- Accounting procedures manual
- Risk mapping: what you need to know
- 5 accounting errors that trigger statutory auditor qualifications