
Webinar Recap: Expanding your internal control framework
Internal control frameworks are never really finished. Something shifts, whether that's a transformation program, an acquisition, a new reporting requirement or an audit finding, and the framework that made sense last year has gaps in it. That part is uncontroversial. The harder questions are the ones underneath: what actually counts as a trigger, how much you expand in response, and how you avoid ending up with hundreds of controls nobody can quite explain.
Recent headlines give plenty of reasons to ask. For example in the UK, Provision 29 is raising the bar for board accountability and pushing teams to look harder at their material controls. In Germany, the discussion around ending penalty-free voluntary disclosure for TCMS is doing something similar. None of it arrives on a convenient schedule.
This Compliance. Curated. [Online] session brought together two practitioners who have handled this from very different vantage points. Meera Vora leads the Finance Controls Excellence pillar at Unilever, and was previously Head of Financial Governance and Compliance at ITV, giving her experience of a large SOX-regulated global group on one side and a UK broadcaster mid-transformation on the other. Christoph Becker spent 15 years in a Big 4 environment designing, building and auditing GRC functions, tools and processes, and joined Impero in July as Compliance Solutions Director. Jasmine Hansen de Guzman, Marketing Director at Impero, moderated. The full session is available on demand here.
Where the audience is today
The session opened by asking attendees which phase they're in: building, expanding, or simplifying.
A clear majority, 57%, said expanding. Another 38% put themselves in the simplifying phase, and 5% are still building. The split is telling, because expanding and simplifying turned out to overlap heavily. Almost everything the panel said about expanding a framework came back to first understanding, and often reducing, what's already in it.
What triggers an expansion, and why it matters which one
For Meera, transformation is the dominant trigger. A lot of organizations are in the middle of one, and at minimum that forces a review of the existing framework. Sometimes it forces a complete rebuild. Acquisitions are a close second, along with regulatory change and, underlying all of it, shifts in the risk picture itself. Her real point was that these rarely arrive one at a time. Most teams are now contending with two or three simultaneously, with leaner teams than they had five or six years ago. That makes prioritization a monthly exercise rather than an annual one.
Christoph added two triggers that come from outside the organization entirely. The first is the external auditor asking for more entities, processes, systems or controls in scope, which starts a familiar negotiation between what the auditor wants and what actually serves the business. The second is control failure. When an audit finding shows a process isn't working as designed, he noted, the framework expands quickly and budget appears just as quickly. His summary was blunt: most triggers are external, and most expansion is reactive. Companies don't wake up wanting a bigger framework. The expand to solve a problem right in front of them.
Which trigger you're responding to should change how you respond. A deficiency comes with a remediation plan, often with extra resources and moves fast. An auditor request needs proportionality: before adding ten controls, understand what upstream and downstream controls already address the risk. As Meera put it, "it is really key to be proportionate, and that is the dance that you have to dance with the auditors."
Acquisitions may not need core framework changes at all. At ITV, with a run of acquisitions on the studios side, her team built a minimum control framework instead. That gave new entities enough to address their key financial risks quickly, ahead of onboarding onto the core ERP. New reporting requirements start with an impact assessment. For something like IFRS 18, you may already have controls over disclosures, and where you don't, transition controls can be carved out and then retired once the requirement moves into business-as-usual. Transformation is the outlier, bringing different processes, multiple teams and a new operating model underneath, and it often does justify a full refresh.
Christoph's addition was change management. An acquisition is largely the acquiring company setting the terms. Expanding scope entity by entity across markets works differently, and local cultural differences matter more than most frameworks account for.
Expanding doesn't mean adding
This was the line the whole session kept returning to. "Expanding a control framework doesn't mean just adding more controls," Meera said, "because that in itself becomes unsustainable." The starting point is the framework you already have. Where are the risks already covered, and where are the genuine gaps? The goal of expansion is improving management's confidence and sharpening accountability across the business, and a bigger inventory rarely delivers either on its own.
Christoph's version was structural. Hold a generic control description at parent level, allow local adaptations beneath it, and make sure the same questions are answered the same way everywhere. And before any of that: walk through the process. Review it before you touch it, then decide whether to add controls or adjust the methodology behind them.
One methodology, several formats
As controls extend beyond finance into IT, HR and operations, consistency becomes harder and more important. The panel drew a useful line between what has to stay consistent and what doesn't.
What stays fixed is the substance: risk objective, control objective, activity, control owner, evidence -how you document it can move. Meera's example from ITV was a room full of media and creative professionals who were never going to engage with a traditional risk contro matrix (RCM). Her team mapped process flows and overlaid control points so people could see where the risks sat, and reformatted the RCM into simple Word guidelines matching the other guidance those teams already used. Same components, different presentation, and noticeably better adoption. "People are more receptive to something presented in a slightly different way," she said, adding that many of us are "very allergic" to an Excel framework.
Christoph made the case for the layer above it. Several organizations he's worked with recently have set up a governance office sitting across internal controls, enterprise risk management and compliance in the second line. Without a common methodology for how risks are scoped, identified and rated, that office can't aggregate anything meaningful, and aggregation is where the reporting value comes from.
Delete before you add
Asked what they'd do if handed a framework with hundreds of controls tomorrow, both panellists went the same way: start removing.
Christoph would question every control critically, agree the deletions, and only then redesign what's left. Part of his reasoning was change management related as much as technical. Processes and controls travel across departments, so you need everyone on board, and acceptance is far higher when you arrive offering to clean up rather than to add work.
Meera agreed, with a caveat worth remembering. Before deleting a control, understand why it was put there. She's seen controls removed as redundant that were in fact compensating for an upstream control that wasn't operating as effectively as assumed. Assess the end-to-end process first.
Technology, AI, and the pace question
Technology can absolutely reduce the administrative burden. Workflows, continuous control operation and data analytics all drive coverage, insight and timeliness. The caution is the obvious one, and it applies double to AI: understand the underlying process before automating it. Good data, clear accountability, operators who know what changed. "Making sure you're not just bolting on a tool on top of a very broken process," as Meera put it. AI adds a governance question of its own. How do you keep human review in the loop and confirm the tool continues to operate as intended?
On the final question, whether the bigger risk is expanding too slowly or too quickly, both said too quickly. Christoph's reasoning was that regulatory change can usually be seen coming, so speed is rarely the constraint it appears to be. Meera's concern was poorly designed controls and change management that can't keep up. But she didn't let the slow route off the hook either. Expanding too slowly leaves control gaps. The answer is a phased approach, and it's worth revisiting how often you republish the framework at all.
From the Q&A
Where does complexity and scope creep come from? Christoph pointed to silos. Within one company, internal control functions in IT, accounting and tax often run on different tools, collect evidence differently and evaluate it differently, while attaching to the same processes. The complexity shows up when you try to bring it together. Alignment across departments is the fix.
When simplifying a mature framework, do you start with the control inventory or reassess the underlying risks? Meera starts with the inventory: number of controls per process, coverage of that process, then mapping to risks to find duplicates addressing the same risk. Only after that does she work back through the risks to confirm coverage. It's slow work across a full framework, but it produces a framework that has been deliberately controlled instead of one that has simply accumulated over time.
Key takeaways
- Know which trigger you're responding to. A deficiency, an auditor request, an acquisition and a transformation all call for different responses, and different amounts of framework.
- Assess before you add. Look hard at what you already have first. More controls often means less control.
- Clean up first. Deleting redundant controls before designing new ones improves both the framework and the reception it gets, as long as you understand why each control was there.
- Fix the methodology, flex the format. Keep risk and control components consistent across the business, and shape the documentation to the audience actually performing the control.
- Slow down. Both panellists thought expanding too quickly was the bigger risk. Phase it, prioritize by risk, and revisit the framework on a deliberate cycle.
Keep the conversation going
This session was part of Compliance. Curated., Impero's ongoing series for finance, tax and compliance professionals. You can watch previous sessions in the full playlist on YouTube, including our last one on whether continuous controls are the new baseline.
We run these sessions regularly, and if you'd like an invite to the next one, sign up for our newsletter.
And if you're working through an expansion of your own, get in touch with the Impero team for a walkthrough of how the platform can help.
Get the latest from Impero in your inbox.
Stay informed on all things Impero — webinar & event invites, exclusive content, product launches, and more! Or let us show you why Impero is the right choice for your risk and compliance needs.
You might also like...
Explore insights, product updates, and practical guidance to navigate the world of risk & internal controls.


