Article
Updated:
August 14, 2026

Improve Organizational Performance through People, Process and Technology

No items found.
Two business people converse over laptops in a white-washed brick room.

Table of Contents

Share with network

Edit: Originally published on August 8, 2023. Updated to reflect current internal controls best practices.

A day at any business may differ from company to company based on the services or products it offers, but all businesses have perform similar operational activities, including meetings, contracts, approvals, reporting, and execution. These tasks introduce risks, such as missing or inappropriate approvals, incomplete or inaccurate data, fraud, inconsistent execution, inefficient handoffs, and reputational damage, among others. Without a defined structure to govern how work gets done, these risks compound over time, creating control failures, inefficiencies, and exposure that can impact financial reporting, decision-making, and the organization’s ability to scale.

This is where internal controls play an important role. When thoughtfully designed and well executed, internal controls bring structure and accountability to routine activities, reducing the likelihood and impact of operational, financial, and compliance risks. Having good internal controls in place is the key for any business to thrive. When questions arise about the effectiveness of existing controls, it is often a signal for leadership to reassess, reorganize, and, when appropriate, seek additional perspective.

Strengthening internal controls does not always require a significant new investment. Many times, all that is needed is a recalibration of what is already in place. Reassessing current processes, ownership, and system use can reduce risk while improving efficiency and consistency.

What Internal Controls Are and How They Reduce Operational Risk

Internal controls are deliberate activities carried out or governed by people, embedded in processes, and enabled by technology to reduce risk and strengthen how an organization operates. They establish clear expectations around who is responsible, how work should be performed, and where oversight occurs. Without this structure, variability in execution increases, making it harder to identify issues, enforce accountability, or support well-informed decision-making.

Internal controls operate across three interconnected components: people, process, and technology. When aligned, they create a coordinated control environment that drives greater efficiency, enhances risk mitigation, and enables scalable, sustainable growth.

  • People (the “who”) People are accountable for the consistent execution of control activities and for responding when something deviates from expectations. When roles are unclear, overloaded, or misaligned, control activities are more likely to break down, increasing the risk of errors, missed deadlines, or ineffective oversight.
  • Process (the “how”) Processes define the specific steps required to perform a control effectively and mitigate associated risks. They translate accountability into action by defining what must occur, when it must occur, and how consistency is maintained with control processes aligned to the organization’s structure, objectives, and risk profile.
  • Technology (the “what”) Technology includes the tools that support or perform control activities, including automated controls. When configured and implemented based on clearly defined processes, technology supports consistent and reliable execution of control activities.

Bringing It Together

Internal controls designed through an integrated people, process, and technology lens help organizations manage risk in line with their risk appetite, drive productivity and efficiency, create value, and support the achievement of strategic goals.

This article is the first in a series that explores each area—people, process, and technology—why they are important, and how to evaluate where risk may be building and where improvements can have the greatest impact.

We Can Help

Strong governance frameworks reinforce transparency, accountability, and sustained performance. Effective organizations rely on disciplined controls and well-defined processes to support sound decision-making, manage risk, and remain audit-ready.

At Elliott Davis, our team helps organizations identify and implement practical improvements across governance, processes, and reporting, including the ability to:

  • Evaluate the current internal controls framework to understand how well it addresses operational and reporting risk
  • Identify gaps in risk assessment, control activities, and monitoring that could lead to adverse events and risk realization.
  • Enhance reporting processes to improve transparency and uncover inefficiencies, manual workarounds, or areas of increased risk
  • Align oversight mechanisms with business goals and regulatory expectations to improve accountability and visibility
  • Support leadership decision-making with clear insights into risk exposure, control effectiveness, and operational consistency

Contact us today to get started and explore other articles in the series:

The information provided in this communication is of a general nature and should not be considered professional advice. You should not act upon the information provided without obtaining specific professional advice. The information above is subject to change.

download the white paper

contact our team

No items found.

contact our team

contact our team.