UAE E Invoicing 100

Is Your ICFR Framework Built to Withstand Scrutiny?

Naveed Akhter Sep 29, 2026

Most financial reporting issues are not caused by accounting errors alone.

They often arise from weaknesses in the underlying processes and controls, an ineffective review, inadequate segregation of duties, unreliable system-generated information, or simply a control that has not operated as intended.

This is why Internal Controls over Financial Reporting (ICFR) are receiving increasing attention in the UAE, particularly following regulatory developments affecting Public Joint Stock Companies. While regulation is an important driver, the underlying objective of ICFR is straightforward, to provide reasonable assurance over the reliability of financial reporting.

Understanding ICFR and Why It Matters

ICFR comprises the policies, processes and controls established by an organisation to provide assurance over the reliability of financial reporting and the preparation of financial statements.

Although ICFR is often associated with the finance function, effective financial reporting depends on activities across the organisation. Revenue may originate in operational systems, payroll in HR, purchasing in procurement, while valuations may depend on management assumptions, models and specialist inputs.

An ICFR framework therefore cannot simply be built around the year-end financial reporting process. It needs to consider the processes, people, systems and information on which the financial statements ultimately depend.

For management and boards, the benefit is straightforward: greater confidence that material financial reporting risks have been identified and appropriately addressed.

The UAE Regulatory Landscape

The UAE's regulatory environment continues to place greater emphasis on governance, accountability and internal controls. The precise requirements differ according to the nature of the organisation, including whether it is listed, regulated or operating within a particular financial free zone.

For listed companies, developments introduced by the Securities and Commodities Authority have increased the focus on internal control and risk management, including ICFR. This places greater emphasis not simply on whether controls have been documented, but whether they are appropriately designed, implemented and operating effectively.

This distinction is fundamental.

A well-prepared risk and control matrix may describe an appropriate control environment, but it does not establish that those controls actually operate in practice.

Boards and management should therefore understand the specific requirements applicable to their organisation and ensure that responsibility for ICFR is clearly established.

COSO as the Foundation for ICFR

The COSO Internal Control - Integrated Framework remains one of the most widely recognised frameworks for designing, implementing and evaluating internal control.

It is based on five integrated components, Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.

The framework provides a useful foundation, but implementing COSO should not become an exercise in documenting controls against five headings.

The important part is applying those principles to the organisation's own business model, systems, processes and financial reporting risks. A diversified group operating across jurisdictions and multiple systems will require a different approach from a single-entity business operating through one ERP platform.

The framework should therefore be proportionate to the organisation and focused on the risks relevant to its financial reporting.

Implementing an Effective ICFR Framework

One of the most common mistakes in ICFR implementation is to start by documenting every control already performed within the organisation.

A better starting point is the financial statements.

Management should first consider which areas could reasonably give rise to a material misstatement and then understand the processes supporting those areas. The key question is:

What could go wrong that could result in a material misstatement in the financial statements?

Only then should management determine which controls address those risks.

This leads to an important point, more controls do not necessarily mean better controls.

An organisation may perform hundreds of approvals, reconciliations and reviews while still having gaps in areas that present significant financial reporting risk. Equally, an overly extensive control framework can become difficult to operate, test and maintain.

The objective should be to identify the controls that matter, establish clear ownership and ensure that those controls address the relevant risks at an appropriate level of precision.

Technology also needs to be considered from the outset. Financial reporting increasingly depends on ERP systems, interfaces, automated calculations, spreadsheets and system-generated reports. A review control may be appropriately designed but still be ineffective if the information on which it relies is incomplete or inaccurate.

Assessing and Testing ICFR

Once controls have been identified, management needs to consider three separate questions: are they appropriately designed, have they been implemented, and have they operated effectively during the relevant period?

A control can be well designed but not consistently performed. Similarly, a control may be performed but leave insufficient evidence to demonstrate what was reviewed, what exceptions were identified and how those exceptions were resolved.

Management review controls are a good example.

Evidence that a CFO reviewed a monthly financial report confirms that a review took place. It does not necessarily demonstrate the depth or precision of that review.

An effective review should be capable of identifying an error of sufficient magnitude to matter. The evidence should therefore demonstrate what was reviewed, how unusual items or variances were investigated and how matters identified were resolved.

The existence of evidence is not, on its own, evidence that a control was effective.

Common ICFR Implementation Challenges

Several issues arise repeatedly during implementation.

  • Too many controls. Organisations can spend considerable time documenting and testing controls that do not address significant financial reporting risks. Starting with risk rather than existing processes usually produces a more focused framework.
  • Unclear ownership. ICFR can become viewed as a finance, internal audit or compliance project. In practice, responsibility for individual controls should sit with those responsible for the underlying processes, supported by appropriate oversight.
  • Confusing activities with controls. Statements such as "management reviews the report" or "invoices are checked" may describe an activity, but do not necessarily explain who performs the control, what is reviewed, how frequently it operates, the precision applied or how exceptions are resolved.
  • Insufficient evidence. A control may have operated, but without appropriate evidence it can be difficult to demonstrate its effectiveness. This is particularly relevant for reviews, approvals and follow-up performed through informal discussions or email.
  • Underestimating technology dependencies. Controls often rely on system-generated information, automated calculations or spreadsheets. The reliability of that underlying information needs to form part of the control assessment.
  • Late remediation. Identifying deficiencies close to the reporting date can leave insufficient time to redesign a control, implement the change and demonstrate that the revised control has operated effectively.

These issues are rarely solved by adding more documentation.

They generally require better risk assessment, clearer ownership and greater discipline in how controls are performed and evidenced.

Maintaining an Effective ICFR Framework

ICFR is not a one-off implementation exercise.

Businesses acquire companies, change systems, automate processes, restructure teams and introduce new products. Accounting and regulatory requirements also evolve. Each change can affect the organisation's financial reporting risks and the controls designed to address them.

Management should therefore periodically reassess the scope of ICFR, consider significant business and system changes, update controls where necessary and monitor deficiencies through to remediation.

Control owners also need to understand why their controls exist, rather than simply how to perform them. This makes it easier to recognise when a change in the business affects the risk that the control was intended to address.

For boards and Audit Committees, reporting should remain focused. Visibility over significant deficiencies, remediation, overdue actions and material changes to the control environment is generally more useful than extensive control-level reporting.

Questions Management and Boards Should Be Asking

Management and boards can often assess the maturity of an ICFR framework through a small number of fundamental questions:

  • Have we identified the financial reporting risks that could result in a material misstatement?
  • Can our key controls be traced to those risks?
  • Are we focusing on the controls that matter, or simply documenting everything we do?
  • Do our management review controls operate with sufficient precision?
  • Can we demonstrate that key controls have operated effectively?
  • Which controls rely on systems, reports or spreadsheets, and have those dependencies been considered?
  • When a control fails, do we understand the cause and wider implications, or do we simply correct the individual exception?
  • Does our ICFR framework change when the business changes?

If these questions are difficult to answer, the solution may not be more controls. It may be a more focused framework.

Final words

Effective ICFR should not be measured by the number of controls documented, the size of the risk and control matrix or the volume of testing completed.

The more relevant question is whether the organisation understands its financial reporting risks, has designed appropriate controls to address them and can demonstrate that those controls operate effectively in practice.

As ICFR and wider corporate governance requirements continue to develop in the UAE, boards and management should consider whether their frameworks remain proportionate to the organisation, appropriately focused on financial reporting risk and capable of operating effectively in practice.

At Baker Tilly UAE, we support organisations with the design, implementation and assessment of ICFR frameworks, including scoping and risk assessment, control design and documentation, testing, remediation and readiness for independent assurance. Our approach is focused on the organisation's financial reporting risks and the practical operation of the controls established to address them.

Related content

Article Audit & Assurance
Muhammad Adnan Jul 31, 2026
Article Audit & Assurance
Saad Maniar Jun 29, 2026
External Publications Audit & Assurance
Gulf News Saad Maniar Jun 1, 2026
External Publications Audit of Financial Statements
Saad Maniar Apr 8, 2026
External Publications Audit & Assurance
Gulf News Saad Maniar Mar 12, 2026
External Publications Audit & Assurance
Gulf News Saad Maniar Feb 26, 2026
External Publications Audit & Assurance
Accounting and Business magazine Saad Maniar Nov 1, 2025
Audit & Assurance
Saad Maniar Oct 17, 2025
Article Audit & Assurance
Armen Biberian Aug 1, 2025
Join our newsletter
Receive our insights direct to your inbox.
Sign up