International Peer-Reviewed Journal•Open Access•ISSN 2456-8880
irejournals@gmail.com•+91-7433024337

Home / Current Issue / Paper 1722410

1722410 Vol 10 · Issue 2 Download Paper

Internal-Control Analytics and Audit-Informed Process Improvement: A Scalable Governance Model for Growth-Stage Organizations

Ashley Munashe Shambare Nelia Mlambo Melody Rachael Chitukutuku Deline Kufandada Munashe Naphtali Mupa

Subject area: Management and Commerce  ·  Area of research: Accounting and Auditing

DOI: 10.64388/IREV10I2-1722410

Abstract

This study develops and empirically demonstrates a scalable governance model that links transaction-level internal-control analytics to audit-informed process improvement in growth-stage organizations. The analysis uses the Online Retail II transaction dataset, distributed through Kaggle and originally archived by the UCI Machine Learning Repository, comprising 1,067,371 transaction lines, 53,628 invoices, and 43 countries between December 2009 and December 2011. Rather than treating reversals, data-quality defects, and transactional irregularities as isolated bookkeeping problems, the study frames them as governance signals that can be translated into practical control redesign, escalation logic, and dashboard-based oversight. Six forward-looking control-gap indicators were constructed missing customer identifiers, duplicate lines, price outliers, quantity outliers, non-positive prices, and extreme-value invoices together with a separate reversal indicator for credit-note intensity. The study combines full-population descriptive analytics, monthly and country heatmaps, issue co-occurrence analysis, invoice-level anomaly detection, and rank-based association testing. The results show that 36.16% of all transaction lines contained at least one control gap. Missing customer identifiers (22.77%) and price outliers (15.03%) were the most prevalent issues, followed by quantity outliers (7.91%), extreme-value invoices (7.48%), and duplicate lines (6.30%). Temporal concentration was evident: December 2010 recorded the highest average control-gap score (31.42), while December 2011 exhibited the highest return-to-gross ratio (32.11%), signalling heightened pressure on reconciliation and approval processes during peak-cycle periods. Geographic hotspot analysis showed the highest composite control-gap indices among the Netherlands and the United Kingdom in the high-volume country set. A co-occurrence heatmap further revealed that missing customer identifiers and price outliers appeared together on 10.89% of all lines, indicating that master-data weakness and pricing-control weakness frequently interacted. As a secondary validation step, an Isolation Forest flagged 5.00% of invoices as anomalous; flagged invoices showed an average of 2.79 control gaps compared with 1.01 for non-flagged invoices, and anomaly scores were strongly associated with invoice gap counts (Spearman rho = 0.624, p < 0.001). The study contributes a governance architecture that translates exception analytics into five operational stages: data capture and standardisation, continuous exception monitoring, risk-based audit triage, control redesign with ownership, and dashboard monitoring for board and management review. The findings support the view that internal audit becomes more valuable when it moves beyond periodic sampling and instead uses full-population analytics to direct scarce remediation capacity toward the most consequential process weaknesses. For growth-stage organizations, the practical implication is clear: scalable governance does not require heavyweight bureaucracy, but it does require disciplined exception logic, threshold-based approvals, and a closed-loop link between audit findings and process owners.

Keywords

internal control analytics; internal audit; governance; process improvement; anomaly detection; growth-stage organizations; Online Retail II

References

[1] ACFE (2024) Occupational Fraud 2024: A Report to the Nations. Austin, TX: Association of Certified Fraud Examiners.

[2] Adebiyi, O., Nwokedi, A.O. and Mupa, M.N. (2025) 'An Analysis of Financial Strategies, and Internal Controls for the Sustainability of SMMEs in the United States', Iconic Research and Engineering Journals, 8(7), pp. 340-356.

[3] Alqudah, H., Amran, N.A., Hassan, H., Lutfi, A., Alessa, N., Alrawad, M. and Almaiah, M.A. (2023) 'Examining the critical factors of internal audit effectiveness from internal auditors’ perspective: Moderating role of extrinsic rewards', Heliyon, 9(10), e20497. doi: 10.1016/j.heliyon.2023.e20497.

[4] Azizan, A.F. and Ali, M.M. (2024) 'The Effect of Internal Control Mechanism Towards Fraud Prevention in Small and Medium Enterprises', Indonesian Journal of Sustainability Accounting and Management, 8(1), pp. 178-188. doi: 10.28992/ijsam.v8i1.843.

[5] COSO (2026) Internal control. Committee of Sponsoring Organizations of the Treadway Commission. Available at: https://www.coso.org/internal-control (Accessed: 21 June 2026).

[6] Duan, H.K., Vasarhelyi, M.A. and Codesso, M. (2025) 'Integrating Process Mining and Machine Learning for Advanced Internal Control Evaluation in Auditing', Journal of Information Systems, 39(1), pp. 55-75. doi: 10.2308/ISYS-2022-028.

[7] Hossain, M.Z. (2025) 'Effectiveness of Internal Control Systems in Preventing Financial Fraud in SMEs', SSRN Electronic Journal. doi: 10.2139/ssrn.5255489.

[8] Jans, M. and Eulerich, M. (2022) 'Process Mining for Financial Auditing', in van der Aalst, W. et al. (eds.) Process Mining Handbook. Lecture Notes in Business Information Processing, vol. 448. Cham: Springer, pp. 445-467. doi: 10.1007/978-3-031-08848-3_15.

[9] Kaggle (n.d.) Online Retail II UCI. Available at: https://www.kaggle.com/datasets/mashlyn/online-retail-ii-uci (Accessed: 21 June 2026).

[10] Liu, G., Wang, J., Sun, Y., Guo, J. and Zhao, Y. (2024) 'Internal audit quality and accounting information comparability: Evidence from China', PLOS ONE, 19(10), e0310959. doi: 10.1371/journal.pone.0310959.

[11] Mupa, M.N., Chiganze, F.R., Mpofu, T.I., Mangeya, R. and Mubvuta, M. (2024) 'The Evolving Role of Management Accountants in Risk Management and Internal Controls in the Energy Sector', Iconic Research and Engineering Journals, 8(2), pp. 859-881.

[12] Netshifhefhe, K., Netshifhefhe, M.V., Mupa, M.N. and Murapa, K.A. (2024) 'Integrating Internal Auditing and Legal Compliance: A Strategic Approach to Risk Management', Iconic Research and Engineering Journals, 8(4), pp. 446-465.

[13] Taanisa, T., Mukwata, N.A., Sydney, J., Ganyani, L., Maturure, R.N., Chingezi, E., Yelduora, P.G. and Mupa, M.N. (2026) 'AI-Enabled Audit Analytics for SME Financial Reporting and Anomaly Detection: A Risk-Based Framework for Early Irregularity Identification and Control Strengthening', World Journal of Advanced Research and Reviews, 30(3), pp. 1113-1126. doi: 10.30574/wjarr.2026.30.3.1596.

[14] The IIA (2024) Global Internal Audit Standards. Lake Mary, FL: The Institute of Internal Auditors.

[15] U.S. Small Business Administration Office of Advocacy (2025) 2025 Small Business Profile: United States. Washington, DC: U.S. Small Business Administration.

[16] UCI Machine Learning Repository (2019) Online Retail II. Available at: https://archive.ics.uci.edu/ml/datasets/online+retail+II (Accessed: 21 June 2026).

[17] Álvarez-Foronda, R., Ruiz-Martín, C., Laviada, A.F. and Núñez-Carballosa, A. (2023) 'Implementation model of data analytics as a tool for improving internal audit processes', Frontiers in Psychology, 14, 1140972. doi: 10.3389/fpsyg.2023.1140972.

How to cite this paper

Ashley Munashe Shambare, Nelia Mlambo, Melody Rachael Chitukutuku, Deline Kufandada, Munashe Naphtali Mupa "Internal-Control Analytics and Audit-Informed Process Improvement: A Scalable Governance Model for Growth-Stage Organizations" Iconic Research And Engineering Journals Volume 10 Issue 2 2026 Page 2118-2129 https://doi.org/10.64388/IREV10I2-1722410
Ashley Munashe Shambare, Nelia Mlambo, Melody Rachael Chitukutuku, Deline Kufandada, Munashe Naphtali Mupa "Internal-Control Analytics and Audit-Informed Process Improvement: A Scalable Governance Model for Growth-Stage Organizations" Iconic Research And Engineering Journals, vol. 10, no. 2, Aug. 2026, doi: https://doi.org/10.64388/IREV10I2-1722410
Ashley Munashe Shambare, Nelia Mlambo, Melody Rachael Chitukutuku, Deline Kufandada, Munashe Naphtali Mupa (2026). Internal-Control Analytics and Audit-Informed Process Improvement: A Scalable Governance Model for Growth-Stage Organizations. Iconic Research And Engineering Journals, 10(2). doi: https://doi.org/10.64388/IREV10I2-1722410
Ashley Munashe Shambare, Nelia Mlambo, Melody Rachael Chitukutuku, Deline Kufandada, Munashe Naphtali Mupa "Internal-Control Analytics and Audit-Informed Process Improvement: A Scalable Governance Model for Growth-Stage Organizations" Iconic Research And Engineering Journals, vol. 10, no. 2, Aug. 2026. Crossref, https://doi.org/10.64388/IREV10I2-1722410
@article{1722410,
      author = {Ashley Munashe Shambare, Nelia Mlambo, Melody Rachael Chitukutuku, Deline Kufandada, Munashe Naphtali Mupa},
      title = {Internal-Control Analytics and Audit-Informed Process Improvement: A Scalable Governance Model for Growth-Stage Organizations},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {2},
      pages = {2118-2129},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722410.pdf},
      abstract = {This study develops and empirically demonstrates a scalable governance model that links transaction-level internal-control analytics to audit-informed process improvement in growth-stage organizations. The analysis uses the Online Retail II transaction dataset, distributed through Kaggle and originally archived by the UCI Machine Learning Repository, comprising 1,067,371 transaction lines, 53,628 invoices, and 43 countries between December 2009 and December 2011. Rather than treating reversals, data-quality defects, and transactional irregularities as isolated bookkeeping problems, the study frames them as governance signals that can be translated into practical control redesign, escalation logic, and dashboard-based oversight. Six forward-looking control-gap indicators were constructed missing customer identifiers, duplicate lines, price outliers, quantity outliers, non-positive prices, and extreme-value invoices together with a separate reversal indicator for credit-note intensity. The study combines full-population descriptive analytics, monthly and country heatmaps, issue co-occurrence analysis, invoice-level anomaly detection, and rank-based association testing. The results show that 36.16% of all transaction lines contained at least one control gap. Missing customer identifiers (22.77%) and price outliers (15.03%) were the most prevalent issues, followed by quantity outliers (7.91%), extreme-value invoices (7.48%), and duplicate lines (6.30%). Temporal concentration was evident: December 2010 recorded the highest average control-gap score (31.42), while December 2011 exhibited the highest return-to-gross ratio (32.11%), signalling heightened pressure on reconciliation and approval processes during peak-cycle periods. Geographic hotspot analysis showed the highest composite control-gap indices among the Netherlands and the United Kingdom in the high-volume country set. A co-occurrence heatmap further revealed that missing customer identifiers and price outliers appeared together on 10.89% of all lines, indicating that master-data weakness and pricing-control weakness frequently interacted. As a secondary validation step, an Isolation Forest flagged 5.00% of invoices as anomalous; flagged invoices showed an average of 2.79 control gaps compared with 1.01 for non-flagged invoices, and anomaly scores were strongly associated with invoice gap counts (Spearman rho = 0.624, p < 0.001). The study contributes a governance architecture that translates exception analytics into five operational stages: data capture and standardisation, continuous exception monitoring, risk-based audit triage, control redesign with ownership, and dashboard monitoring for board and management review. The findings support the view that internal audit becomes more valuable when it moves beyond periodic sampling and instead uses full-population analytics to direct scarce remediation capacity toward the most consequential process weaknesses. For growth-stage organizations, the practical implication is clear: scalable governance does not require heavyweight bureaucracy, but it does require disciplined exception logic, threshold-based approvals, and a closed-loop link between audit findings and process owners.},
      keywords = {internal control analytics; internal audit; governance; process improvement; anomaly detection; growth-stage organizations; Online Retail II},
      month = {August},
      doi = {https://doi.org/10.64388/IREV10I2-1722410}
  }