The Wirecard case: how companies can prevent control gaps in their Internal Control System

Wirecard: a fraud that stayed hidden for too long

Wirecard was long regarded as Germany’s flagship fintech company, despite repeated criticism over irregularities in its financial reporting and questionable business structures. In April 2020, a special KPMG audit concluded that Wirecard had failed to provide sufficient documentation to clear these allegations. EY refused to sign off the annual accounts on 18 June 2020 after €1.9 billion in escrow funds could not be verified. A few days later, Wirecard admitted that the money probably never existed. The company filed for insolvency on 25 June of the same year.

The German Bundestag later ranked the case among the largest economic scandals in post-war history. Its final report also stated that Wirecard had deliberately kept its Internal Control System ineffective. This is precisely why the scandal remains relevant for companies today. The case was far more than an instance of balance-sheet fraud; it exposed what can happen when an ICS fails to flag critical developments early enough.


Why internal controls fail

An Internal Control System (ICS) is a company’s organisational framework to identify risks, embed controls in processes, and document their execution in a traceable way. The system only works when risks, processes, responsibilities, and evidence stay closely connected and controls are actually applied in day-to-day operations.

In many organisations, the problem is that formal control structures do not match operational reality. Controls are often defined as requirements, but not reflected in the routines, responsibilities, and systems that govern operational processes. As a result, controls may be documented, but there is no reliable proof that they are actually performed as intended. Such an ICS may look complete but offers only limited protection.

An ineffective Internal Control System usually shows these weaknesses:

  • Controls have been defined but never linked to specific process steps
  • Process changes create new risks without anyone updating the controls
  • Responsibilities stay unclear
  • Evidence is missing or cannot be gathered quickly for audits
  • Manual, error-prone processes block strategic management
  • Risks, measures, and controls are managed in separate systems

These gaps undermine the ICS’s reliability. Their consequences often become apparent only when evidence is missing, control execution proves inconsistent, or weaknesses in the control framework can no longer be overlooked.

How control gaps emerge in an Internal Control System

Most control gaps arise where process management and control management are not sufficiently aligned. Processes continue to evolve, while risks, controls, and measures are maintained separately. Without a common foundation, the Internal Control System can quickly lose touch with the processes it is meant to safeguard.

Whenever processes change, responsibilities shift, or new risks emerge, the related controls need to be reviewed and adjusted in a structured way. This requires ICS processes to be modelled precisely and controls to be linked directly to the relevant process steps. Only then can companies assess how changes affect the control environment, identify new risks, and determine where additional or different controls may be needed. This way, the Internal Control System remains consistent and up-to-date, even as the process landscape evolves.

As long as risks, controls, and processes are managed separately, the impact of process changes often goes unnoticed until the control environment has already been affected. Maintaining the effectiveness of the Internal Control System then becomes more difficult and requires considerable manual effort.

The risks of an ineffective Internal Control System

A weak Internal Control System reduces a company’s ability to manage risks and detect critical developments. This can trigger operational, regulatory, and organisational problems.

The negative effects include:

  • Higher exposure to errors and fraud
  • Poor transparency over critical ICS processes
  • Heavy workload during audits, reviews, and inspections
  • Uncertainty about whether controls actually work
  • Inability to meet regulatory requirements

As a result, the Internal Control System loses much of its reliability and its value as a management tool. If controls are ineffective or evidence is missing, audits become more time-consuming, uncertainty increases, and serious issues are more likely to be detected too late.

Digitisation as a key success factor

KPMG’s study¹ on the digitisation of Internal Control Systems highlights paper-based controls, manual document storage, and varying levels of maturity as the main hurdles companies face when they try to improve their ICS.

Digitisation helps overcome these hurdles by making control management more structured, consistent, and measurable. Standardised workflows, automated reminders, clear escalation paths, version histories, and audit trails make it easier to monitor control execution and provide reliable evidence when needed. When these elements are managed in one digital system, companies can analyse control performance more effectively, identify recurring weaknesses, and refine the ICS where it matters most.

¹Source: https://hub.kpmg.de/digitalisierung-des-iks

The benefits of BIC Internal Control

BIC Internal Control helps companies manage their Internal Control System transparently and with audit requirements in mind. The tool enables organisations to organise all controls in one place, assign clear responsibilities, and systematically document and track measures. It also reduces manual handovers and fragmented documentation, creating reliable structures for day-to-day ICS operations.

As part of BIC GRC, BIC Internal Control integrates seamlessly into the wider GRC landscape. A shared foundation makes risks, controls, measures, and responsibilities available across departments, helping to avoid redundancies and reduce coordination effort.

BIC Internal Control can also be linked with BIC Process Design. This enables a continuous exchange of information between process models and the Internal Control System.

Conclusion

The Wirecard case makes one thing clear: documented rules alone do not make an Internal Control System effective. Controls need to be embedded in everyday operations, and process changes need to be reflected in the control environment as they occur. Otherwise, gaps can go unnoticed for years. This can lead to serious financial, regulatory, and reputational consequences.

At the same time, companies face growing demands for transparency, traceability, and reliable governance. An Internal Control System that operates separately from business processes will quickly reach its limits. Effective ICS management, therefore, requires processes, risks, and controls to be managed in integrated systems so companies can see how changes affect existing controls and where adjustments are needed.

Handled in this way, the Internal Control System becomes more than a mechanism for meeting compliance requirements. Companies can intervene earlier, focus improvement efforts where they have the greatest impact, and manage risks with greater confidence.


Frequently asked questions

What is an Internal Control System, and how does it work?

An Internal Control System provides the organisational framework companies need to address risks, embed controls in business processes, and document whether those controls have been carried out. It works effectively when risks, processes, and evidence of control execution are closely connected.

Why do internal controls fail in companies?

Internal controls usually fail when they are documented but not properly embedded in day-to-day business processes. A lack of transparency, unclear responsibilities, and process changes that are not reflected in the control environment can cause companies to overlook risks and identify weaknesses too late.

What causes control gaps in an Internal Control System?

Control gaps typically arise when processes change, but the related risks and controls are not reviewed. Unclear responsibilities and separate systems for managing processes and controls can also make such gaps more likely.

Which risks can an ineffective ICS create?

An ineffective ICS can allow errors, manipulation, and compliance breaches to go undetected. It also makes it harder to document controls transparently and demonstrate that they are effective, increasing the effort required for audits and weakening strategic business management.

What are the warning signs of weaknesses in an ICS?

Common signs of weaknesses include controls that are not linked to specific process steps or lack sufficient evidence of execution. Weaknesses can also arise when process changes are not reflected in the control framework. Manual workflows and unclear responsibilities may further delay risk detection and increase the likelihood of control gaps.

Why must controls be linked to processes?

Controls are only effective when they are closely linked to the underlying business processes. This ensures transparency regarding where the controls are applied, who is responsible for them, and how their execution can be evidenced. Linking controls to processes is also essential for identifying control gaps at an early stage and managing risks effectively.