At Risk Oversight, we have spent more than twenty years helping organizations design, run, and improve internal control programs across energy, financial services, post-secondary, and the public sector. Over that time, one belief has shaped everything we do: an internal control program should make an organization stronger, not just prove that it is compliant.

That sounds simple. In practice, it is the difference between a program people tolerate and one leadership relies on.

Too many programs have drifted into expensive routine. Controls are documented, tested, and rolled forward year after year, and the question of whether any of it is improving the business rarely gets asked. We believe it should be the first question, not the last.

This article sets out the philosophy behind our work: seven principles for running internal control programs that are value-added, action-oriented, and built for how organizations operate today. Whether you are a controller, VP Finance, CFO, or internal auditor, we hope it prompts an honest look at your own program.

Compliance is the floor, not the ceiling

SOX, and its Canadian counterpart CSOX, have now been in place for more than two decades. The original mandate was to restore trust in financial reporting through transparency, accountability, and reliable processes. That mandate hasn’t changed. The world it operates in has.

Internal controls have never been better resourced, or more expensive. Costs for SOX programs are up 44%. Hours spent on compliance are up 32%. The number of controls being tracked is up 18% in just two years.

Most programs were built to answer one question: Are we compliant? That was the right question in 2002. It is not enough now. Compliance is the baseline every organization must meet, but it is not the measure of a good program. The better question is:

Is our control environment making this organization stronger?

Why This Actually Matters More Now, Not Less

Here’s the part that gets me out of bed in the morning. The pressure on organizations right now is unlike anything we’ve seen in a generation. Leaner headcounts. ERP systems being replaced wholesale, this time built for a post-internet world. AI tools landing on people’s desks faster than anyone can govern them. Leadership teams asked to do more with less, permanently.

That combination changes the stakes for internal controls entirely. When processes are shifting, systems are changing, and teams are stretched, the control environment either holds the organization together or quietly lets it come apart.

Most organizations will respond to this pressure in one of two equally ineffective ways.

  • The first is paralysis: “We’ve always done it this way” becomes the default while everything around it changes.
  • The second is a sweeping transformation initiative that promises to fix everything at once.  McKinsey puts the failure rate for major transformations at 70%. Bain’s 2024 data puts it at 88%. The “AI transformation” now being sold as the next solution carries the same bet– and the same risk.

The answer is neither autopilot nor upheaval. It’s something quieter and considerably more durable: active, continuous improvement through honest assessment of how your controls and processes are actually designed.

Not a one-time overhaul. Not the same program rolled forward for the twenty-third year running.

The organizations that get this right will have a real competitive advantage. The ones still running the 2002 playbook will keep spending $2.3 million a year* and wondering why nothing improves. [*KPMG, The 2025 SOX Survey, FY24 average program cost — up from $1.6M in FY22]

Our 7 Favorite Principles to Modernize Internal Controls

Here’s what we believe at Risk Oversight, built from years of working with organizations across energy, financial services, post-secondary, and beyond.

  1. Focus on continuous improvement, not pass/fail.

Stop framing everything as a deficiency waiting to be documented. Reframe the program around how controls and processes are maturing over time and tell that story to your stakeholders. Progress over perfection.

  1. Design is the cake. Testing is the icing.

You can survive with minimal icing. You cannot survive without the cake. Many programs pour the bulk of their hours into testing while shortchanging design, and the results show it. At Risk Oversight, we think roughly 50% of program effort should go to design evaluation. Assuming last year’s design review still holds is one of the most common and costly mistakes in the business.

  1. Think good habits, not grand theory.

An internal control program is not an academic exercise. It’s a collection of habits: reviews, approvals, reconciliations, access management. The companies that get controls right don’t have the fanciest frameworks. They have the most consistent habits. Think of it like going to the gym. Showing up three times a week beats reading every fitness book ever written.

  1. Be an accountability partner, not a cop.

Picture someone following a manager around with a clipboard marking down everything they did wrong. That’s exactly how internal controls feel to a lot of people. The best programs feel like support, not surveillance. Think personal trainer, not hall monitor.

  1. Keep it interesting, silly (KIIS).

Roll-forward is meant to preserve institutional knowledge. It is not a license for intellectual autopilot. Rotate the people. Change the questions. Attack different areas of focus each year. Fresh eyes catch things familiar eyes miss, which is precisely why 31% of material weakness disclosures are repeat offenders. Same program, same blind spots, same result.

  1. Be a problem-solver, not a box-checker.

Box-checking programs aren’t just useless. They’re dangerous. They create a false sense of security that lulls everyone into thinking the organization is safer than it is. Here’s a useful test: If a third of your current program activities disappeared tomorrow and nobody noticed, that’s a signal worth taking seriously.

  1. Use AI as a lever, not a crutch.

Teams are using AI to brainstorm control designs, draft risk assessments, and analyze full data populations instead of samples. That’s genuinely great. But AI cannot hold a point of view. It hedges. It presents multiple perspectives and carefully avoids strong claims. The internal control professional who uses their expertise to shape decisions, persuade stakeholders, and cut through ambiguity becomes more valuable in this environment, not less. The one who just runs everything through a chatbot and calls it done is competing with free software.

The Bottom Line

The tools are better than they’ve ever been. The data is richer. The business case for modernizing internal controls has never been stronger. The profession has been making that argument for twenty years without meaningfully changing how programs are designed.

This is the year to actually do it.

Free Download: Your 2026 Internal Controls Checkup Starts Here

If you want a quick way to review your internal control program, this checklist walks you through the 7 Principles and the actions you can take to improve. It’s a great starting point for 2026 planning. Download it, use it, and let us know what you think. What resonated? What needs work? We’re actively refining it and your input matters.

Grab the checklist at the following link:

7 Principles and Tools to Assess and Modernize Your Internal Controls