[Yoon Manho’s Financial Focus] Internal Control Is a Company’s "Brand" and "Culture"
If Internal Controls Fail, Companies Can Collapse Overnight
The Future Core of Internal Control: Prevention and Education Leveraging AI
Advancing Internal Controls Should Be Seen as a Strategic Investment
If an internal control system fails to function, even a company once deemed highly successful can face a sudden catastrophe overnight.
This was something I experienced while working in New York. Not long after the September 11 attacks in 2001, a major accounting fraud scandal erupted at Enron, a leading U.S. energy company. Enron, once hailed as "America's most innovative company" and one of the "Top 100 companies to work for," was discovered to have manipulated its accounting records—a shocking incident. As a result, the giant conglomerate Enron collapsed into bankruptcy and its executives were arrested. That same year, WorldCom, the second-largest telecom company in the U.S., also declared bankruptcy following its own accounting scandal. WorldCom had reclassified operating costs as capital expenditures, amortizing them over the long term to inflate its net income. Arthur Andersen, one of the global Big Five accounting firms and the external auditor for both Enron and WorldCom, was also forced to shut down.
In response, the U.S. Congress moved quickly to restore confidence in the American capital market by enacting the Sarbanes-Oxley Act in 2002, which strengthened the requirements for final signatures and responsibilities of CEOs and CFOs on financial statements, mandated annual internal control system assessments by external auditors, and enhanced the independence of external auditors, among other measures.
In Korea, over the past six years (from 2020 to April 2026), the number and scale of financial accidents at domestic financial firms have reached 609 cases, amounting to 1.2429 trillion won, with incidents on the rise each year. Despite ongoing company-wide efforts for internal control, why do such incidents not decrease but instead keep rising? What kind of system can help proactively prevent or quickly detect recurrent types of fraud, embezzlement, breach of trust, and other financial crimes? Why do accidents repeatedly occur in the same places?
Recently, each domestic financial institution has been introducing responsibility structure systems to clarify and strengthen accountability related to internal controls. As we enter the era of artificial intelligence (AI), it is time to recall the words of Warren Buffett, who once remarked that the failure of internal controls is far more devastating to a company's credibility and reputation than financial losses: "It takes 20 years to build a reputation and five minutes to ruin it."
How to Operate Internal Control Systems Effectively
Undoubtedly, internal controls are vital to a company's survival. This issue must be managed across the entire governance structure—from shareholder meetings, to boards of directors, to board subcommittees, to CEOs and top executives—by establishing internal control standards and strategies, monitoring and evaluating their implementation, and applying responsibility structure systems as appropriate. Regulatory authorities are also formalizing these requirements.
With the advent of the AI era, AI support has become indispensable for effective internal control operations, especially regarding changes in responsibility structures, amendments to regulations, ongoing checks such as KYC (Know Your Customer) and AML (Anti-Money Laundering), and matters that must be observed for financial consumer protection. There is a trend to use AI agents to automatically check whether work assignments are appropriate, and whether key issues such as approvals, reconciliations, and access controls are being properly executed.
I would like to introduce several internal control systems that have proven effective during my long organizational career.
The first is the whistleblower system. The mere presence of internal monitors reduces the number of incidents. The sooner incidents are detected, the easier the recovery and the lower the losses for the organization. If detection is delayed, the scale of the problem can grow exponentially and major breaches in the control network can occur. To successfully operate a whistleblower system, companies must ensure complete protection of the whistleblower's identity and offer appropriate rewards. It is also crucial to instill awareness and provide education so that the company culture does not devolve into simple surveillance and anonymous reporting, but creates a foundation for ethical management.
The second is the thorough implementation of mandatory leave policies and operation of work backup systems. When the U.S. Federal Reserve visits a bank for inspection, these are the first two items it requests. Mandatory leave is a system for risk management, requiring employees to be away from their work for a set period. If an employee has not taken this leave and continues working, the reasons and potential risks are scrutinized. Mandatory leave allows backup personnel to assume the role with minimal disruption and also review the predecessor’s work for any problems. To see effective internal control, any company should start by strictly enforcing the whistleblower system, mandatory leave, and work backup operations.
The Core of Internal Control: Prevention and Education Using AI
The future core of corporate internal control lies first in establishing automated work and verification systems using AI agents. Second is the formation of an ethical organizational culture through repeated education. Recently, AI has started to support legal validation of work performed by business departments and internal control departments. AI-based technology is being used to detect and alert signs of anomalies in advance, thereby helping prevent financial crimes. Many companies are adopting AI-based continuous surveillance and automatic checks, evolving internal control systems into processes focused on prevention, prediction, and automation. AI is now identifying and integrating items that humans previously failed to detect or manage. Whereas internal controls in the past focused mainly on financial accounting, modern issues faced by companies now include failures in ERP system access management and massive data breaches due to ransomware or hacking—critical digital IT issues that can lead to astronomical damages. Controlling such risks requires ongoing investment in IT security and AI automated monitoring systems.
Another core aspect of internal control is continuous, practical education. Regardless of how well an AI-based internal control system is established, if management does not lead by example and employees do not fulfill their responsibilities as users, the system is nothing more than an empty shell and incidents will continue. Employees and management alike must recognize that internal control is a key element in brand reputation and future corporate value, and must participate in ongoing education to foster an accident-free organizational culture.
Microsoft (MS) in the United States is frequently cited as a successful case in establishing and complying with key internal control systems. Its internal control employs four levels of overlapping measures: an independent internal auditor plays the primary role, with the board of directors and audit committee receiving regular reports and performing a strong supervisory function as the second level; periodic compliance reviews by external third parties serve as the third level; and, finally, an intensive whistleblower system operates as the fourth level. While responding effectively after an incident is important, as in the case of MS, it is far better to build a culture of internal control through thorough prevention and proactive supervision.
Advancing Internal Control Systems Is a Strategic Investment
Advancing the internal control system is like putting a safety belt on a company—it may seem unnecessary until an accident occurs, but it becomes a matter of life and death when the worst happens. Therefore, investments in internal control systems should not be regarded as mere costs, but as strategic investments that strengthen competitiveness and enhance brand value.
The COSO Framework, a coalition for internal control in the United States, upholds as an unwritten rule the maxim "Controls are not a cost, they are insurance." Accordingly, global financial companies are developing their internal control processes by organizing teams of AI experts, security experts, and internal control professionals based on data analysis. We, too, need to recognize this trend and proactively invest in internal control systems.
As shown by the cases of Enron and WorldCom, internal control succeeds not just through documentation, regulatory systems, or advanced monitoring, but only when leadership and employees set positive examples to create a living organizational culture. Ultimately, advanced internal control systems constitute infrastructure for a company's sustainable growth and are the key determinant of distinguished brands and organizational cultures.
Hot Picks Today
"If You Give 100,000 Won, You’ll Be Criticized"... Wedding Gift Amounts: 130,000 Won for Singles vs. 290,000 Won for Married Couples
- 14,000-Dollar Cashmere Coat Without a Logo... The Price of "Quiet Luxury" Chosen by the Truly Wealthy
- "107% Return in Just Half a Year"... National Pension Service Scores Major Gains in Domestic Stocks
- President Lee to Personally 'Unbox' Next Year's Youth Budget... Covering Jobs, Housing, and Finance
- "Such a Beauty in Korea" "Looks Like a Movie Star"... Which Volleyball Player is Making Japan Buzz?
Yoon Manho, Financial Columnist (Former President, KDB Financial Group)
© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.