How Rolls-Royce Power Systems made its Internal Control System manageable and audit-ready

Why many Internal Control Systems fail to deliver in practice

An effective Internal Control System (ICS) requires more than defined controls and documented responsibilities. It needs standardised processes, clear ownership, and documentation that makes tests, deviations, and measures traceable at any time. Only when these elements are applied consistently, reviewed regularly, and documented uniformly does the system become truly audit-ready.

In many organisations, the reality looks different. Comprehensive guidelines and defined responsibilities often exist on paper, yet day-to-day implementation remains fragmented. Controls are tracked manually, test results are documented inconsistently, and audits require significant preparation. The result is a system that exists formally but has limited impact in practice and fails to meet audit requirements. This creates a significant need for coordination between departments, unclear operational responsibilities, inconsistent implementation across sites, and reporting that provides only limited insight into the control system’s actual status.

For an ICS to deliver real value, risks, controls, responsibilities, and evidence must be consolidated and managed centrally. Only then does it provide a coherent framework that not only meets regulatory and internal requirements but also offers orientation, reliability, and transparency in daily operations.


What effective ICS implementation looks like in complex organisations

The more complex an organisation is, the more demanding ICS implementation becomes. Controls must be defined, tested, and documented consistently across sites, business units, and operating entities, while still taking local processes into account.

Rolls-Royce Power Systems illustrates how these requirements can be met even in a highly complex, international environment. Its Internal Control System comprises more than 90 global controls, over 1,000 local control instances, around 80 Control Owners, and approximately 300 tests per year. The organisational scope extends across the headquarters, six production sites, fifteen sales companies, and additional entities worldwide.

Many companies reach their limits when dealing with structures of this scale. If group-wide standards and local processes are not properly aligned, evidence becomes inconsistent, testing involves significant manual effort, and controls are difficult to manage transparently.

Addressing this complexity requires more than a list of documented procedures. An effective ICS needs a clear hierarchy, unambiguous responsibilities, and a central platform that connects the relevant components of the control environment. For Rolls-Royce Power Systems, the challenge was to create this structure without losing the flexibility required locally. Global controls and requirements had to be defined consistently, while information from individual entities still needed to be maintained at the appropriate organisational level. To make this model transparent and manageable, test results, evidence, measures, and reporting also had to be brought together in one place, giving employees, management, and auditors access to a shared source of information.

How BIC Internal Control creates structure and clarity

BIC Internal Control provides a framework for defining controls centrally and structuring them in a consistent way. At the same time, local controls can be clearly assigned to the relevant organisational units and Control Owners, while their implementation remains traceable and transparent. Tests, reporting, and the handling of deviations all take place within a single structure. The result is not a rigid register of controls, but a living Internal Control System that connects requirements, execution, and evidence.

The GBTEC ICS tool has everything we need – fully automated. What mattered most to us was having a standardised control system that we could still adapt flexibly to our business requirements.” – Andrés Caminos, Internal Controls Manager, Rolls-Royce Power Systems

This combination of standardisation and flexibility is particularly important for a large-scale Internal Control System. A clear ICS control hierarchy helps translate global controls into local practice without losing transparency. BIC Internal Control supports configurable workflows, centralised and audit-proof documentation, and flexible reporting for regular and ad hoc analyses. This simplifies not only operational management but also the preparation and execution of ICS testing procedures. Test results, exceptions, ICS responsibilities, and measures remain traceable within a consistent structure. As a result, ICS auditability is strengthened since audit requirements can be met on an ongoing basis.

In many cases, close integration with process management adds further value. When the ICS is linked to process management – for example through BIC Process Design – controls can be embedded directly in actual workflows.

 

Three principles for a resilient Internal Control System

The example of Rolls-Royce Power Systems shows that an effective ICS in complex organisations rests on three closely connected principles. These go beyond formal structures and determine whether the system actually works in daily operations.

Clear responsibilities instead of vague ownership 

Responsibilities must be assigned to named individuals rather than abstract organisational units. When every control has a designated Control Owner, coordination effort decreases and reliable execution is easier to ensure. Vague ownership is one of the most common reasons why controls remain theoretical rather than being applied reliably.

Connecting global requirements with local implementation 

In large organisations, simply issuing global standards is rarely enough. The real challenge is to translate them into local practice without compromising their binding nature or overall consistency. Without this balance, central requirements risk remaining detached from operational reality, while local adaptations may gradually weaken a common control approach. A clear control hierarchy creates clarity without restricting local flexibility.

Audit readiness as a result of daily operations 

Many organisations only focus on audit readiness once an audit is already on the horizon. Rolls-Royce Power Systems demonstrates that genuine transparency depends on controls, test results, and measures being documented continuously and in a structured way. Once this continuity is established, much of the extensive preparation usually required before audits is no longer necessary. Evidence is available at all times, allowing internal teams, management, and auditors to access the information whenever needed.

When responsibilities are clear, standards are implemented in a practical way, and information remains continuously available, compliance moves beyond documentation and becomes genuinely manageable. The Internal Control System then gains strategic relevance: it supports better decision-making, provides guidance for risk management, and strengthens the reliability of governance.

Conclusion

Rolls-Royce Power Systems shows how an effective Internal Control System can remain manageable even in a complex organisation. What matters is not the number of controls, but the ability to bring global standards, clear ICS responsibilities, systematic testing, and evidence of execution together within a consistent structure. Only then does an ICS become traceable, manageable in day-to-day operations, and continuously audit-ready.

BIC Internal Control provides the basis for this by consolidating controls, tests, evidence, measures, and reporting on a single platform. In this way, a formally documented control system becomes an ICS that is actively embedded in the organisation and can be operated reliably. Companies looking to implement their ICS or strengthen long-term audit readiness will find a proven solution in BIC Internal Control.


Frequently asked questions

What is an Internal Control System (ICS)?

An Internal Control System (ICS) is an internal framework that brings together controls, defined responsibilities, processes, and documentation to manage organisational risks. It is designed to mitigate identified risks through appropriate control mechanisms and to ensure compliance with legal, regulatory, and internal requirements. It also helps safeguard assets, support the reliability of information, and ensure that business processes are carried out properly. An effective Internal Control System is characterised by controls that are not merely defined on paper, but clearly assigned, embedded in operational processes, and regularly tested for effectiveness.

What makes an Internal Control System (ICS) audit-ready?

An Internal Control System (ICS) becomes audit-ready when controls, test results, deviations, and corrective actions are documented continuously and in a structured way. Real audit readiness is not achieved through intensive preparation shortly before an audit, but as a result of daily operations. This requires clear responsibilities, standardised workflows, audit-proof evidence, and reporting that provides transparency on the current status of the control system at any time. Only when these elements work together consistently can internal teams, management, and external auditors reliably verify that the ICS is functioning effectively.

How can global and local controls be managed in an Internal Control System (ICS)?

Global and local controls can be managed through a clear control hierarchy. Group-wide controls are defined centrally, while local requirements are mapped to this overarching framework. This ensures that compliance with common standards remains traceable. At the same time, local units can adapt existing controls or add specific ones to address site-specific risks and requirements. This keeps global standards binding without limiting the flexibility needed locally.

How can ICS tests be documented effectively?

ICS tests should be documented in a central, consistent structure that records test activities, results, responsibilities, evidence, deviations, and follow-up measures. When this information is linked to the relevant controls, it becomes clear which controls were tested, what the outcome was, who was responsible, and how any exceptions were addressed. This creates the transparency needed for operational management, internal reviews, and audits.

How can ICS complexity be managed in global organisations?

ICS complexity in global organisations can be managed by creating a governance model that makes the system scalable. This means defining a clear scope, assigning ownership at the right levels, setting consistent rules for documentation and testing, and establishing escalation paths for exceptions. A structured reporting model is also essential, as it allows management to understand where risks, gaps, and remediation activities require attention. In this way, the Internal Control System remains manageable even as organisational structures, regulatory requirements, and business processes become more complex.