Mastering internal controls is key to startup success

Head of Strategic Finance, Mercury.
For startups, proper financial management is essential for survival and growth. One element that often gets overlooked? Internal controls.
As head of strategic finance at Mercury, I've witnessed firsthand the role that internal controls play in a startup's trajectory. While product development and customer acquisition are often top of mind for founders, ignoring financial operations and governance can hinder the long-term success of your business.
Here are some tangible strategies to integrate internal controls into your startup, and how Mercury can help automate these processes.
What are internal controls?
Internal controls are the policies and procedures implemented within an organization to protect a company’s financial and accounting data. Internal controls are the organization’s own set of checks and balances to prevent fraud, errors, and misuse of funds while promoting operational efficiency and regulatory compliance.
Types of internal controls
- Internal controls are typically broken down into three types—detective, preventive, and corrective—depending on when they're used.
- Detective controls are monitoring activities that identify problems as they arise. This could involve processes comparing transaction data to account summaries or scheduled audits and physical inspections.
- Preventive controls are proactive measures designed to stop issues before they occur. Examples include spending approval workflows and background checks during the hiring process, along with technological solutions that ensure only authorized individuals can access company systems.
- Corrective controls are actions taken to restore compliance after the fact. This includes mechanisms like reporting hotlines for escalating identified issues and discipline procedures for policy violations.
Companies should employ all three of these measures, though I recommend tailoring the usage of each of them to their unique risk exposure.
Why internal controls matter
Internal controls aim to minimize the risk of harmful events, allowing you to focus on what’s most important — growing your company.
For startups, internal controls that enforce proper spending are essential for maximizing your runway. Inaccuracies in financial reporting, whether accidental or intentional, can destroy your credibility with investors, customers, and partners. Accounting controls ensure your books are audit-ready at all times.
While no founder likes to think about fraud, the reality is that startups can be targets. In a recent survey by Alloy of 450+ financial services companies, 25% of respondents lost over $1M from fraud in the last 12 months. While these companies have a unique risk of fraud given their roles in the banking & payments ecosystem, even non-financial services companies have material fraud risks. Vectors of fraud can include vendors, customers, and bad actors entirely outside of the day to day purview of their business. Weak or nonexistent oversight leaves your hard-earned capital unnecessarily exposed to both internal and external threats.
As your startup scales, so does the complexity of your financial operations. Proper internal controls allow you to maintain order amidst increasing complications, preventing chaos as you expand.
Whether you're raising your next round, getting acquired, or taking the company public, investors and regulators may scrutinize your internal controls and financial governance. Gaps or deficiencies send up red flags that can jeopardize funding and decrease your company’s credibility. It is also crucial that you set up proper controls if you want to sell your product to large enterprises; their compliance teams, as they seek to protect their own company, will often vet the management of your company!
The cost of neglecting internal controls
Every startup founder understands the importance of fiscal responsibility in theory. But when you're operating in hustle mode, spinning up formal internal controls can feel like a costly distraction from product development, sales, and other growth priorities.
I get it – implementing and enforcing internal processes requires time, effort, and investment. But avoiding internal controls comes with risk and the potential for big consequences.
Without budgetary oversight, cash burn can balloon out of control from overspending. When there's a lack of clarity around spending and financial data, it breeds a culture of mistrust between founders and employees. A misaligned team is a fractured team.
Comprehensive IT controls, such as firewalls, intrusion detection systems, and regular security audits, identify vulnerabilities and prevent unauthorized access, protecting systems from takeovers and ransomware. Safeguarding customer data is equally crucial; data encryption, secure storage, and regular backups prevent leaks that could damage reputations and cause financial losses.
Establishing strong internal controls early on is not just about ensuring current security – down the line, weak internal controls may bottleneck initiatives like commercial sales, global expansion, mergers and acquisitions, and taking the company public. You'll be forced to hit the brakes and spend precious time remediating. Proactively investing in internal controls not only mitigates current risks but also smooths the path for future growth and opportunities.
Tailoring internal controls to your growth stage
While the size or stage of a startup might impact the controls that need to be in place, it’s important to acknowledge the specific processes required as your startup matures through various stages of growth.
Smaller startups might have simple control systems due to fewer transactions, fewer employees, and less complexity. When a startup is in its earliest stages, the focus is often primarily on the spending side of the financial statements—typically on product development, marketing, or other operational costs. At this stage, internal controls tend to focus on expense approvals, vendor diligence, AP processes, and ensuring funds are being used appropriately.
As a startup grows and generates more revenue, however, the need for more sophisticated internal controls becomes evident. Startups need to manage both income and expenses, increasing the complexity of financial management and the potential for errors or fraud. This drives the need for stronger internal controls that cover the greater risks and a bigger management layer being built to run the company.
As the company acquires more customers, they also inherit the responsibility of protecting customer data, adding another layer to their internal control system. While the company scales and more management layers are introduced, the founding team will find themselves with less time to review expenses or invoices in detail, underlining the importance of having strong, automated internal controls in place.
As startups grow and become more successful, they face increased scrutiny from various stakeholders. Investors, auditors, and regulatory bodies will expect robust financial management and governance, including solid internal controls across the org, from accounting to IT to HR. They will also expect that companies have operated with these controls in place for a period of time and have built a culture of compliance around them. If a company has grown internationally, it must navigate and comply with unique sets of regulations across different regions.
Therefore, startups should aim to put the right tools, systems, and processes in place early on rather than waiting as they grow. Doing so will help instill a culture of sound financial management and control, preparing the company for future growth and scrutiny. This approach can make the company's financials more resilient, ultimately contributing to its long-term success.
Building your internal control framework
For internal controls to be effective, they need to be designed and implemented with care. Here are a few best practices:
Start with controls you can implement this week
A comprehensive control framework can take a while to put together, but there are certain low-lift policies you can start following immediately. Rolling out a few of these to your team can help everyone build muscle memory before expanding your internal controls program.
Each of the controls below can be implemented fairly easily, and each one comes with a clear owner, a cadence, and the evidence you should retain so an auditor, an investor, or your future finance hire has a paper trail to follow.
Control | Owner | Frequency | Evidence to retain |
|---|---|---|---|
Vendor onboarding against an approved vendor list | Founder or finance lead | At every new vendor onboarding | W-9, verified banking details, approval record |
Bill approval before payment | Founder or department lead | Per bill | PDF or in-app log of each approval |
Card spend limits and merchant locks on employee cards | Founder | Set once and review monthly | Card policy document and bank dashboard settings |
Dual approval for payments above a set threshold | Founder or department lead plus one approver | Per payment | Two approval records per payment |
Bank reconciliation | Bookkeeper | Monthly | Bank rec workbook tied to statements |
Payroll review before each run | Founder | Per pay cycle | Signed-off payroll register |
Duplicate bill check | Bookkeeper | Per bill | Log of flagged duplicates and resolutions |
Receipt policy for all card spend | Every cardholder | Per transaction | Receipts matched to transactions in your system |
Access review of banking and accounting systems | Operations or founder | Quarterly | Access list with additions and removals noted |
Budget variance review | Founder with department leads | Monthly | Variance report with written explanations |
Conduct a comprehensive risk assessment
Before designing any internal controls, you need to understand where your specific vulnerabilities lie. Assess and identify potential risks or areas of concern within your organization. This could involve financial risks, operational risks, or risks related to fraud. Also think about what the company will look like if (when!) you hit your goals in the next 12-24 months; what will be your risks at that point? Will you be adding new geographies, materially growing your tech infrastructure, scaling your customer base, etc? If so, you should start planning now for how you will support that larger risk footprint.
Here are the top risks startups face and the different controls that can be implemented to reduce them. Consider this a starting point for you to build on.
Risk | Primary controls | Control type |
|---|---|---|
Payment fraud (fake vendors, tampered banking details) | Approved vendor list, verification of banking details at onboarding, dual approval on large payments | Preventive |
Duplicate bills | Automated duplicate detection in your bill inbox, per-bill review by bookkeeper | Detective |
Unauthorized spend | Card limits, merchant locks, approval workflows above thresholds | Preventive |
Stale receivables | Weekly AR aging review, automated invoice reminders | Detective |
Payroll errors | Pre-run payroll review, separation between whoever prepares and whoever approves the run | Preventive |
Unused subscription services | Monthly bank reconciliation, quarterly subscription audit | Detective |
Revenue cut-off errors (booking revenue in the wrong period) | Month-end close checklist, revenue recognition review with your bookkeeper | Detective and corrective |
Platform access being misused | Role-based permissions, quarterly access reviews, prompt offboarding | Preventive |
Document policies and communicate
Policies and procedures should be clearly communicated to all employees in a dedicated manual or internal wiki, including all preventive and detective control activities and protocols. But documentation alone isn't enough — you should evangelize these policies through thorough training and continuous communication. And you, as a leader at the company, need to practice what you preach and be a role model for effective compliance.
Among your documented controls, one of the most frequently used processes you’ll encounter is your spend approval workflow. Use the following sample language to help guide your spend approval policy.
Spend amount | Sample policy language |
|---|---|
$0–$499 | “Purchases under $500 may be made on an issued company card within its preset limits. No pre-approval is required. A receipt and memo must be attached within 3 business days.” |
$500–$4,999 | “Purchases of $500 to $4,999 require written approval from the relevant department lead before the purchase is made. Approval records are retained in our expense system.” |
$5,000+ | “Purchases of $5,000 or more require CEO approval, and payments of $5,000 or more require a second approver before funds are released. New vendors at this level also require a signed agreement and completed vendor onboarding.” |
Exceptions | “Emergency spend needed to protect the business (for example, incident response) may proceed on verbal approval from the CEO. The spend must be documented within 24 hours and ratified at the next weekly review. Any other exception requires advance CEO sign-off, logged with a reason.” |
Set measurable guardrails, and check them monthly
Now, you’ve identified a set of controls to prioritize and drafted policy language for your team to follow. How can you tell that your controls are working and being followed?
The guardrails tell you whether your overall financial picture is drifting or staying on target. As a founder or finance lead, there are a number of metrics worth tracking to assess your financial health. Here are four worth tracking because of their relevance and potential impact from the financial controls you’ve implemented above:
- Cash runway. Use the formula: cash balance ÷ average monthly net burn. With $900,000 in the bank and $75,000 of monthly net burn, you have 12 months of runway. Many founders set an internal flag at 12 months to begin fundraising conversations, since fundraises can take two or three quarters.
- Days cash on hand. Use the formula: cash balance ÷ average daily operating outflow. The same $900,000 against $3,600 of average daily outflow gives you 250 days. This is the guardrail enterprise buyers and lenders tend to ask about, so it's worth keeping a regular pulse on it.
- Forecast accuracy. Use the formula: 1 − (|actual − forecast| ÷ forecast). If you forecast $100,000 of burn and spend $108,000, accuracy is 92%. Missed forecasts above or below 10% warrant a further investigation, because repeated big misses mean your forecasts are unreliable, making it more difficult to plan around.
- Monthly budget variance. Use the formula: (actual − budget) ÷ budget, per line item. It’s worth flagging any line item beyond 10% variance, and hold payroll to 5% since it's your highest and most predictable cost. A $60,000 marketing line that comes in at $71,000 is an 18% variance, which should warrant a review before next month's spend takes place.
Adopt the right financial automation tools
Technology can play a significant role in implementing effective internal controls. For instance, vendor management automation can streamline processes, reducing the chance of human error. At Mercury, we offer a feature in which the company avoids sending payments to fraudulent vendors – it requires legitimate vendors to be added to an approved list before payments can be made, adding an extra layer of security.
Improve constantly
Internal controls should be dynamic and evolve with changes in the business environment and company size. The executive team and the board should also review internal controls regularly to ensure they are still effective and relevant. This includes testing controls for any loopholes that might lead to financial misstatement.
Foster a culture of integrity
Ultimately, the effectiveness of internal controls depends on the company's culture. Encouraging a culture of financial integrity and accountability can go a long way in ensuring the effectiveness of internal controls, especially as the company matures. This starts at the top and flows through to the finance and accounting teams that are ultimately responsible for financial oversight.
Your first 90 days: A realistic rollout plan
Rolling out too many new internal controls at once can make it difficult for your team to follow. Instead, try this 90-day phased implementation approach, and consider the deliverables that should exist at the end of each phase:
Phase | Days | Deliverables |
|---|---|---|
Assess | 1–30 | Risk assessment (start from the matrix above); inventory of who can currently move money and access which systems; list of the five controls that address your biggest risks |
Design | 31–60 | Approval matrix with thresholds; written spend and receipt policy; month-end close checklist; variance review cadence on the calendar |
Pilot | 61–75 | One full month-end close run against the new checklist; approval workflows live in one department; a short list of workflows to fix |
Rollout | 76–90 | Company-wide policy launch and training; controls documented in your wiki; monthly guardrail report shared with leadership and, where relevant, your board |
How budgeting and controls work together
While founders sometimes treat the budget and the control system as separate projects, they're actually one system working together before, during, and after the spending takes place.
Consider this example of, say, a $3,000 annual analytics subscription:
Stage | What happens | The $3,000 subscription |
|---|---|---|
Pre-spend (policy and budget) | Budgets set per department; thresholds and policies documented; vendors onboarded to the approved list | Marketing's budget includes a software line; the $3,000 purchase falls in the $500–$4,999 band, so the buyer knows lead approval is required before signup |
At-spend (approvals and limits) | Approval workflows run; card limits and merchant locks constrain what can actually be charged | The department lead approves in writing; the charge goes on a card with a limit that fits the tooling budget, locked to that merchant |
Post-spend (reconciliation and review) | Transactions reconciled and categorized; variance reviewed against budget; audit trail retained | The bookkeeper matches the receipt and maps the charge to the right GL code; the monthly variance review confirms the tooling line is still within 10% of plan |
How Mercury can help
Of course, implementing internal controls is easier said than done – particularly for companies just starting out. That's where Mercury comes in – we offer a suite of tools for streamlining and automating your core internal control activities. Through accounting and accounts payable automations built right into your bank account, you can speed up month-end close and enhance financial precision. This includes:
Automated approval flows
Budgetary overruns are a common pitfall for many startups. With our multi-layered approval flows, you gain control over your expenses, providing an added layer of security that could save your startup from unnecessary expenditures and potential financial pitfalls. You can even approve bills effortlessly right inside Slack or Mercury’s mobile app.
Expense management
Mercury's expense management integrates company cards and reimbursements into the same system as your banking, which is where most of the controls in this article live day to day. You can issue physical or virtual cards to your team for free, set custom limits and expiration dates, and lock cards to specific merchants or categories.
With our spend policies, you can set rules requiring receipts and notes, set submission timeframes, and automatically match emailed receipts to the right transactions. Employees submit reimbursable expenses in seconds with data auto-scanned from receipts, admins reimburse in two clicks, and a single view shows you any spend that's out of your stated policy.
Accounting automations
Mercury's accounting automations speed up month-end close by syncing all your bills, cards, and bank transactions from your Mercury account. Using your real-time financial data, categorize your bills and expenses within Mercury and sync to QuickBooks, NetSuite, or Xero, helping maintain accuracy and transparency in your financial data. Create custom rules to map merchants to your GL codes and apply them automatically — saving your employees the effort and potential for error. With up-to-date and accurate reports, confidently present your financial reports to investors, stakeholders, and regulatory bodies.
Bill management
As soon as a bill arrives in your bill inbox, its details will automatically populate – allowing you to easily cross-check info and eliminate manual errors. Mercury then automatically detects duplicate bills, giving you an extra set of eyes and preventing you from overpaying. By paying bills more accurately with software built into your bank account, your hard-earned money flows where it's supposed to.
At Mercury, we know that startups must adopt sound financial discipline and accountability to position themselves for long-term, sustainable success.
That’s why we’re always innovating our product with an eye toward enhancing financial oversight and governance.
The startups that prioritize internal controls and leverage the right technology to facilitate them will be the ones that avoid financial pitfalls – and reach their full potential.
About the author
Stuart Goldberg is the Head of Strategic Finance at Mercury. Previously, he worked in Strategic Finance at Block and at SoFi, helping those companies navigate their scaling journeys, including cross border M&A activities, public offerings, and bank charter applications.
Share article
Related reads

Leveraging payment automation to optimize your startup’s AP processes

Strategies for streamlining subscription management and optimizing spend

Timing your first finance hire and finding the right person for the job
