ICFR DOCUMENTATION PACKS
Introduction
The Internal Control over Financial Reporting (ICFR) Documentation Pack is the collection of documents that an entity prepares to support its assessment of the effectiveness of its internal control over financial reporting. In Nigeria, ICFR is no longer a matter of best practice; it is a statutory requirement. The Financial Reporting Council of Nigeria (FRC) and the Securities and Exchange Commission (SEC) have both issued guidance requiring Public Interest Entities (PIEs) and Public Companies to assess and report on the effectiveness of their ICFR.
The documentation pack is the evidentiary foundation for management’s assessment. It provides the basis for management’s conclusion about the effectiveness of controls and supports the external auditor’s attestation report. Without a well-structured documentation pack, management cannot demonstrate that it has reasonable support for its assessment, and the external auditor cannot form an opinion on the effectiveness of ICFR.
This comprehensive guide examines the ICFR Documentation Pack, covering its purpose, components, the COSO framework, documentation requirements, and how Qeeva Advisory helps organisations build robust ICFR documentation.

The Pain Points: Why ICFR Documentation Matters Now More Than Ever
The Regulatory Mandate
In Nigeria, ICFR has shifted from practice to legal requirement. The amended Investments and Securities Act (ISA) requires that public companies establish a system of internal controls over financial reporting and security of assets, with the board of directors responsible for ensuring the integrity of the company’s financial controls. The chief executive officer and chief financial officer must personally certify the accuracy of financial statements. The external auditor must issue a statement on the existence, adequacy, and effectiveness of the internal control system.
The FRC requires all Public Interest Entities (PIEs) to report on ICFR effective December 31, 2024. The SEC requires all Public Companies to report on ICFR from December 31, 2023.
The Awareness and Knowledge Gap
Research on ICFR implementation in Nigeria reveals significant gaps in awareness and preparedness. A KPMG survey found that 52% of respondents cited lack of clarity and understanding as the major challenge preventing implementation, while 20% cited knowledge gaps. Only 52% of respondents believed they would achieve better compliance with policies and procedures, indicating that organisations may not be fully aware of the broader benefits of ICFR implementation.
The Documentation Challenge
Business processes and controls documentation are critical components of ICFR. The KPMG survey found that 59% of organisations were fully in the process of documenting their processes and controls, while 33% were partially in the process, and 8% had not begun. Among those documenting, only 30% had reached the Risk and Control Matrix phase.
The IFRS 18 Connection
The transition to IFRS 18, effective in 2027, reinforces the need for robust ICFR documentation. IFRS 18 places greater emphasis on data granularity and transparent documentation. Weak data structures, incomplete audit trails, and inconsistent book-keeping create challenges in generating reliable subtotals, defensible classification decisions, and support for retrospective restatement. These requirements form the core of an effective ICFR framework, which provides the controls necessary to strengthen data integrity, standardise classifications, enhance reconciliations, and ensure well-documented reviews.
The COSO Framework: The Foundation for ICFR Documentation
The COSO Internal Control Framework is the most widely used framework for ICFR. The FRC highly recommends the COSO Framework, stating that it satisfies the criteria for a suitable framework and may be used as an evaluation framework for management’s annual internal control evaluation requirements.
The COSO Framework consists of five components, each supported by seventeen principles:
Component 1: Control Environment
The Control Environment sets the tone of an organisation, influencing the control consciousness of its people. It is the foundation for all other components of internal control, providing discipline and structure.
Key elements include:
-
Integrity and ethical values
-
Commitment to competence
-
Board of directors and audit committee participation
-
Management’s philosophy and operating style
-
Organisational structure
-
Assignment of authority and responsibility
-
Human resource policies and practices
Component 2: Risk Assessment
Risk Assessment is the identification and analysis of relevant risks to the achievement of objectives, forming a basis for determining how the risks should be managed.
Key elements include:
-
Identifying financial reporting risks
-
Considering the potential for fraud
-
Identifying and assessing changes that could significantly impact the system of internal control
Management should consider “what could go wrong” within a financial reporting element to identify the sources and potential likelihood of misstatements. The risk assessment should include consideration of the vulnerability of the entity to fraudulent activity, including fraudulent financial reporting, misappropriation of assets, and corruption.

Component 3: Control Activities
Control Activities are the actions established through policies and procedures that help ensure that management’s directives to mitigate risks to the achievement of objectives are carried out. Control activities may be preventive or detective in nature and encompass a range of manual and automated activities.
Types of controls include:
-
Manual controls: Controls that do not rely upon IT application-produced information or action
-
IT-dependent manual controls: Manual controls (usually detective and corrective controls) that are dependent upon complete and accurate processing to be fully effective
-
Application controls: Automated actions of the entity’s IT applications without input from a person, relating to procedures used in the critical path of transactions or other financial data
-
IT general controls: Controls that support the continued functioning of automated aspects of prevent, detect, and correct controls
Key control activities include:
-
Authorisations and approvals
-
Verifications
-
Reconciliations
-
Segregation of duties
-
Business performance reviews
-
Physical controls over assets
Component 4: Information and Communication
Information is necessary for the entity to carry out internal control responsibilities to support the achievement of its set objectives. Management must obtain or generate and use relevant and quality information from both internal and external sources, in a timely manner, to support the functioning of other components of internal control.
Key elements include:
-
Obtaining or generating and using relevant, quality information
-
Internally communicating information, including objectives and responsibilities for internal control
-
Communicating with external parties regarding matters affecting the functioning of internal control
Component 5: Monitoring Activities
Monitoring Activities are ongoing evaluations built into business processes at different levels of the entity, as well as separate evaluations conducted periodically. Findings are evaluated against criteria established by regulators, recognised standard-setting bodies, or management and the board of directors, and deficiencies are communicated to management and the board.
Key elements include:
-
Selecting, developing, and performing ongoing and/or separate evaluations
-
Evaluating and communicating internal control deficiencies in a timely manner
-
Following up to ensure corrective actions are implemented
The ICFR Documentation Pack: Components and Structure
The ICFR Documentation Pack is the collection of documents that supports management’s assessment of ICFR effectiveness. It typically includes the following components:
1. Overall ICFR Evaluation Strategy Memorandum
Management should document its overall strategy for evaluating ICFR. This comprehensive memorandum establishes the evaluation approach, the evaluation procedures, the basis for management’s conclusion about the effectiveness of controls, and the entity-level and other pervasive elements that are important to management’s assessment.
Key contents:
-
Scope of the ICFR assessment
-
Framework used (COSO)
-
Evaluation methodology and procedures
-
Roles and responsibilities
-
Timeline and milestones
-
Basis for conclusions
2. Process Documentation
Business processes and controls documentation are critical components of ICFR. Management must document its business processes, including the flow of transactions from initiation through authorisation, processing, recording, and reporting.
Key contents:
-
Process narratives
-
Flowcharts
-
Process maps
-
Key process owners and responsibilities
-
Systems and applications used
3. Risk and Control Matrix (RCM)
The Risk and Control Matrix is the core document of the ICFR Documentation Pack. It maps financial reporting risks to the controls that address them.
Key contents:
-
Financial reporting elements (accounts, disclosures)
-
Risks of material misstatement
-
Controls that address each risk
-
Control type (manual, IT-dependent, application, IT general)
-
Control frequency
-
Control owner
-
Evidence of control operation
-
Assessment of control design and operating effectiveness
4. Control Testing Documentation
Management must document the testing of controls to support its assessment of operating effectiveness. This includes both testing of design and testing of operating effectiveness.
Testing of Design: Assess whether the control, if operating as intended, provides reasonable assurance that control objectives are being met.
Testing of Operating Effectiveness: Assess the functionality and effectiveness of controls in place.
Key contents:
-
Test plan and methodology
-
Sample selection and size
-
Test procedures performed
-
Results of testing
-
Conclusions on design and operating effectiveness
-
Identified deficiencies and remediation plans
5. Entity-Level Controls Documentation
Entity-level controls are controls that operate across the entire organisation and have a pervasive impact on ICFR. These include controls over management override, the risk assessment process, centralised processing and shared service environments, the control environment, and monitoring activities.
Key contents:
-
Control environment assessment
-
Management override controls
-
Risk assessment process documentation
-
Monitoring activities documentation
-
Board and audit committee oversight documentation
6. IT General Controls Documentation
IT general controls support the continued functioning of automated aspects of prevent, detect, and correct controls. These controls are essential for the reliability of automated application controls and IT-dependent manual controls.
Key IT general control areas:
-
Access to programs and data: Manage access to provide access only to authorised, appropriate users who are restricted to performing authorised, appropriate actions
-
Program changes: Make changes to IT application programs and other relevant IT environment components that are appropriate and function as intended
-
Program development: Manage the development and acquisition of IT systems
-
Computer operations: Manage IT operations to provide a reliable processing environment
7. Management’s Annual Assessment Report
Management’s annual assessment of ICFR must be documented in a formal report that is included in the entity’s annual report.
Required contents:
-
A statement of management’s responsibility for establishing and maintaining adequate ICFR
-
A statement identifying the framework used by management to conduct the required evaluation
-
Management’s assessment of the effectiveness of ICFR as of the end of the most recent fiscal year
-
Disclosure of any material weaknesses identified
-
A statement that the registered public accounting firm has issued an attestation report on management’s assessment
Management is not permitted to conclude that ICFR is effective if there are one or more material weaknesses that have not been fully addressed or mitigated.
8. CEO/CFO Certification
The chief executive officer and chief financial officer must certify that the signing officer has reviewed the report, the report does not contain any untrue statement of a material fact, and the financial statements fairly present the financial condition and results of operations of the entity.
The certification must also state that the signing officers:
-
Are responsible for establishing and maintaining internal controls
-
Have designed such internal controls to ensure that material information is made known to them
-
Have evaluated the effectiveness of the entity’s internal controls as of a date within 90 days prior to the report
-
Have presented their conclusions about the effectiveness of internal controls
-
Have disclosed to the auditors and audit committee all significant deficiencies and material weaknesses
-
Have identified whether there were significant changes in internal controls
9. Auditor Attestation Report
The external auditor must issue an attestation report on management’s assessment of ICFR. The report must contain a statement as to the existence, adequacy, and effectiveness or otherwise of the internal control system of the PIE.
Key contents:
-
Opinion on management’s assessment of ICFR
-
Basis for opinion
-
Definition and limitations of ICFR
-
Procedures performed
-
Conclusion
Documenting Multiple Locations and Business Units
Management’s consideration of financial reporting risks generally includes all of its locations or business units. When the controls necessary to address financial reporting risks operate at more than one location or business unit, management must generally evaluate evidence of the operation of the controls at the individual locations or business units.
Management may determine that ICFR risk of the controls that operate at individual locations is low. In such situations, evidence gathered through self-assessment routines or other ongoing monitoring activities, combined with evidence from a centralised control that monitors the results of operations at individual locations, may constitute sufficient evidence for the evaluation.
In other situations, management may determine that, because of the complexity of judgment in the operation of the controls at the individual location, the risk that controls will fail to operate is high, and therefore more evidence is needed about the effective operation of the controls at the location.
The Evidential Matter Requirement
Management’s assessment must be supported by evidential matter that provides reasonable support for its assessment. The nature of the evidential matter may vary based on the assessed level of ICFR risk of the underlying controls and other circumstances.
Reasonable support for an assessment would include the basis for management’s assessment, including documentation of the methods and procedures it utilises to gather and evaluate evidence.
The evidential matter may take many forms and will vary depending on the assessed level of ICFR risk for controls over each of its financial reporting elements. Management may document its overall strategy in a comprehensive memorandum that establishes the evaluation approach, the evaluation procedures, the basis for management’s conclusion, and the entity-level and other pervasive elements.
If management determines that the evidential matter within the entity’s books and records is sufficient to provide reasonable support for its assessment, it may determine that it is not necessary to separately maintain copies of the evidence it evaluates. In smaller companies, where management’s daily interaction with its controls provides the basis for its assessment, management may have limited documentation created specifically for the evaluation of ICFR. However, management should consider whether reasonable support for its assessment would include documentation of how its interaction provided it with sufficient evidence.
This documentation might include memoranda, emails, and instructions or directions to and from management to entity employees.
In determining the nature of supporting evidential matter, management should also consider the degree of complexity of the control, the level of judgment required to operate the control, and the risk of misstatement in the financial reporting element. As these factors increase, management may determine that evidential matter supporting the assessment should be separately maintained.
How Qeeva Advisory Helps with ICFR Documentation Packs
At Qeeva Advisory, we understand that building and maintaining an effective ICFR Documentation Pack requires technical expertise, disciplined processes, and robust project management. Our team of experienced professionals helps Nigerian and international businesses navigate ICFR requirements and build documentation that supports management’s assessment and the external auditor’s attestation.
Our Core Services
Internal Control Advisory Service – We help you build robust internal controls across cash and treasury, procurement, inventory, IT, and other critical domains. Our services include internal control review, internal control testing, and control components including risk assessment, control activities, information and communication, and monitoring. Our team of professionals helps you build, test, and improve your internal controls through internal control review and internal control testing .
Corporate Governance, Risk and Compliance (GRC) – Explore how effective governance, risk management, and compliance frameworks are essential for organizational success, including enterprise risk management and internal control frameworks. Our GRC services help you build governance frameworks that ensure effective board oversight, transparent decision-making, and accountability .
Advisory Services Nigeria – Our advisory professionals help you understand ICFR requirements, assess your current compliance posture, and develop implementation strategies.
Regulatory Compliance – We ensure your ICFR documentation meets all regulatory requirements under the FRC and SEC guidance. Our regulatory compliance services include regulatory mapping to identify all applicable regulations, agencies, and requirements for your business .
Bookkeeping Services – Accurate records are the foundation of effective ICFR. Our bookkeeping services ensure your financial data is accurate and complete.
Risk Management – We help you identify and manage risks associated with ICFR, including financial reporting risks and control effectiveness risks. Our risk management services help you develop early warning systems and monitor key risk indicators .
Our Service Methodology for ICFR Documentation Packs
At Qeeva Advisory, we follow a structured, collaborative process to deliver high-impact ICFR documentation solutions.
Phase 1: ICFR Readiness Assessment
Objective: Understand your current ICFR posture and identify gaps.
What We Do:
-
Review your current internal control environment and documentation
-
Assess compliance with FRC and SEC ICFR requirements
-
Evaluate your risk assessment processes and control activities
-
Assess your IT general controls and application controls
-
Identify gaps in your ICFR Documentation Pack
Deliverables:
-
ICFR Readiness Assessment Report
-
Gap analysis and priority action plan
-
Implementation roadmap
Related Services: Internal Control Advisory Service and Advisory Services Nigeria
Phase 2: ICFR Framework Design
Objective: Develop a tailored ICFR framework and documentation structure.
What We Do:
-
Design your ICFR evaluation strategy and methodology
-
Develop process documentation (narratives, flowcharts, process maps)
-
Build your Risk and Control Matrix (RCM)
-
Design control testing procedures and documentation templates
-
Develop entity-level and IT general controls documentation
-
Design management’s annual assessment report and CEO/CFO certification templates
Deliverables:
-
ICFR Evaluation Strategy Memorandum
-
Process documentation
-
Risk and Control Matrix
-
Control testing templates
-
Management assessment report templates
Related Services: Internal Control Advisory Service and Corporate Governance, Risk and Compliance (GRC)
Phase 3: Implementation Support
Objective: Implement ICFR documentation and build organisational capability.
What We Do:
-
Train finance and business process teams on ICFR requirements
-
Support control testing and evidence gathering
-
Assist with documentation of control operation
-
Support management’s assessment process
-
Coordinate with external auditors
Deliverables:
-
Training programs for staff
-
Control testing support
-
Documentation support
-
Management assessment support
Related Services: Bookkeeping Services and Regulatory Compliance
Phase 4: Monitoring and Continuous Improvement
Objective: Ensure sustained compliance and continuous improvement.
What We Do:
-
Monitor regulatory changes and update documentation accordingly
-
Conduct periodic ICFR reviews
-
Support internal and external audits
-
Provide ongoing advisory support
Deliverables:
-
Regulatory update alerts
-
Periodic ICFR review reports
-
Ongoing advisory support
Related Services: Risk Management and Regulatory Compliance
Frequently Asked Questions
Q: What is ICFR?
A: Internal Control over Financial Reporting (ICFR) is a process designed to provide reasonable assurance regarding the reliability of financial reporting and the preparation of financial statements for external purposes in accordance with generally accepted accounting principles. It includes policies and procedures that pertain to the maintenance of records, provide reasonable assurance that transactions are recorded as necessary, and provide reasonable assurance regarding prevention or timely detection of unauthorised acquisition, use, or disposition of assets.
Q: Which organisations are required to implement ICFR in Nigeria?
A: The FRC requires all Public Interest Entities (PIEs) to report on ICFR effective December 31, 2024. The SEC requires all Public Companies to report on ICFR from December 31, 2023. PIEs include governments and government organisations, listed entities, regulated non-listed entities, public limited companies, private companies that are holding companies of public or regulated entities, concession entities, privatised entities, entities engaged in public works with annual contract sum of N1 billion and above, licensees of government, and all other entities with annual turnover of N30 billion and above.
Q: What framework should be used for ICFR?
A: The FRC highly recommends the COSO Framework. It consists of five components (Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities) supported by seventeen principles.
Q: What is the Risk and Control Matrix?
A: The Risk and Control Matrix (RCM) is the core document of the ICFR Documentation Pack. It maps financial reporting risks to the controls that address them, including control type, frequency, owner, evidence of operation, and assessment of design and operating effectiveness.
Q: What is the difference between testing of design and testing of operating effectiveness?
A: Testing of design assesses whether the control, if operating as intended, provides reasonable assurance that control objectives are being met. Testing of operating effectiveness assesses the functionality and effectiveness of controls in place.
Q: What are IT general controls?
A: IT general controls support the continued functioning of automated aspects of prevent, detect, and correct controls. They include access to programs and data, program changes, program development, and computer operations.
Q: What must be included in management’s annual assessment report?
A: Management’s annual assessment report must include a statement of management’s responsibility for ICFR, a statement identifying the framework used, management’s assessment of effectiveness, disclosure of any material weaknesses, and a statement that the external auditor has issued an attestation report.
Q: What is the CEO/CFO certification requirement?
A: The chief executive officer and chief financial officer must certify that they have reviewed the report, the report does not contain any untrue statement of material fact, the financial statements fairly present the financial condition and results of operations, they are responsible for establishing and maintaining internal controls, they have designed such internal controls, they have evaluated the effectiveness of internal controls within 90 days prior to the report, and they have disclosed all significant deficiencies and material weaknesses to the auditors and audit committee.
Q: How can Qeeva Advisory help with ICFR documentation?
A: We provide ICFR readiness assessment, framework design, implementation support, and ongoing monitoring. Our services include ICFR evaluation strategy, process documentation, Risk and Control Matrix development, control testing templates, management assessment report templates, and training. Our internal control services help you safeguard assets, improve the reliability of financial information, and establish and maintain compliance measures .

The Bottom Line
The ICFR Documentation Pack is the evidentiary foundation for management’s assessment of internal control over financial reporting. In Nigeria, ICFR is a statutory requirement for PIEs and Public Companies, and the documentation pack must be robust enough to support management’s conclusion and the external auditor’s attestation.
Key Takeaways:
Understand the Regulatory Requirements: The FRC requires PIEs to report on ICFR effective December 31, 2024. The SEC requires Public Companies to report from December 31, 2023.
Use the COSO Framework: The FRC highly recommends the COSO Framework, consisting of five components and seventeen principles.
Build the Core Documents: The ICFR Documentation Pack includes the Overall ICFR Evaluation Strategy Memorandum, Process Documentation, Risk and Control Matrix, Control Testing Documentation, Entity-Level Controls Documentation, IT General Controls Documentation, Management’s Annual Assessment Report, CEO/CFO Certification, and Auditor Attestation Report.
Document Evidential Matter: Management’s assessment must be supported by evidential matter that provides reasonable support. The nature of the evidential matter varies based on assessed ICFR risk.
Address Multiple Locations: When controls operate at more than one location, management must evaluate evidence of the operation of controls at the individual locations or business units.
Your job is to be prepared. Assess your ICFR readiness. Build your documentation pack. Test your controls. Document your conclusions. Seek professional guidance.
With the right approach and the right partner, you can turn ICFR documentation from a compliance burden into a foundation for reliable financial reporting and stakeholder trust.
Suggested Reading from Our Blog
Internal Control Advisory Service – Learn how to build robust internal controls across cash and treasury, procurement, inventory, IT, and other critical domains. Our internal control services help you safeguard assets, improve the reliability of financial information, and establish and maintain compliance measures .
Corporate Governance, Risk and Compliance (GRC) – Explore how effective governance, risk management, and compliance frameworks are essential for organizational success, including enterprise risk management and internal control frameworks .
Advisory Services Nigeria – Strategic guidance for navigating ICFR complexity and building compliance frameworks.
Regulatory Compliance In Nigeria – Comprehensive overview of tax and regulatory compliance requirements for Nigerian businesses.
Bookkeeping Services – Accurate records are the foundation of effective ICFR. Our bookkeeping services ensure your records are accurate and complete.
Reference Links / Sources
ICAN – ICFR Implementation Process at a Glance – COSO Framework components and principles, categorisation of controls (manual, IT-dependent manual, application, IT general), and control objectives.
Nigeria Mortgage Refinance Company – ICFR Assurance Report – Definition and limitations of ICFR, management’s responsibility, and external auditor’s assurance engagement procedures.
FRC Nigeria – Guidance on Management Report on ICFR – Management’s annual assessment requirements, control framework requirements (COSO), auditor attestation requirements, and material weakness considerations.
AOPS – Understanding ICFR Public Awareness Series – COSO components (Control Activities, Information and Communication, Monitoring Activities), underlying principles, and ICFR implementation effective dates.
FRC Nigeria – Evidential Matter to Support the Assessment – Reasonable support for management’s assessment, documentation of methods and procedures, and multiple location considerations.
FRC Nigeria – Identifying Controls that Adequately Address Financial Reporting Risks – Risk of misstatement considerations, fraud risk assessment, and efficiency considerations in control selection.
KPMG – A Guide to Implementing Internal Controls over Financial Reporting in Nigeria – Survey findings on awareness and knowledge gaps, documentation progress, and the history of ICFR regulation in Nigeria.
SEC Nigeria – Circular on Compliance with Sections 60-63 of ISA – Filing requirements for ICFR reports for 2023 and subsequent years.
Qeeva Advisory – Internal Control Advisory Service – Internal control review, testing, and control components including risk assessment, control activities, information and communication, and monitoring.
Qeeva Advisory – Corporate Governance, Risk and Compliance (GRC) – Enterprise risk management, internal control advisory, risk management services, and GRC methodology.
Let’s Talk About Your ICFR Documentation Needs
Building and maintaining an effective ICFR Documentation Pack is essential for compliance and reliable financial reporting. At Qeeva Advisory, we understand the challenges faced by Nigerian businesses in meeting ICFR requirements.
Whether you need help with ICFR readiness assessment, framework design, or documentation support, we are here to support you.
📞 Call us: (+234) 802 320 0801, (+234) 807 576 5799
📧 Email: info@qeeva.com
📍 Visit us: 5, Ishola Bello Close, Off Iyalla Street, Alausa, Ikeja, Lagos, Nigeria
Contact us today to schedule a consultation. Let us help you navigate ICFR documentation with confidence.
Your journey to reliable financial reporting starts with a conversation. Let’s talk.




