
Article
State government internal control frameworks: Lessons from ARMICS
Nov. 14, 2025 · Authored by Christopher Kalafatis, Randy Sherrod, Peter Tsengas
Loading...
In today’s dynamic public sector environment, internal control frameworks are more than just compliance tools; they’re strategic assets. Whether you're managing fiscal operations, overseeing human resources or safeguarding information technology (IT) systems, a robust internal control framework can elevate your agency’s performance, accountability and resilience. In addition, a strong internal control framework can help limit the opportunity for fraud. One standout example is Virginia’s Agency Risk Management and Internal Control Standards (ARMICS), a program that offers a comprehensive blueprint for risk management and control evaluation across state agencies.
Whether your agency works with state-mandated programs like ARMICS or is considering implementing an internal control framework for the very first time, we invite you to join us as we explore the benefits, challenges, and essential steps of implementing an internal control framework to transform your public sector governance.
Internal control frameworks are structured systems designed to ensure effective and efficient operations, reliable financial reporting and regulatory compliance. In the public sector, where transparency and stewardship are paramount, these frameworks serve as the backbone of impactful governance.
Virginia’s ARMICS program exemplifies how a state government can institutionalize risk management and internal controls. It mandates that agencies document significant fiscal processes, assess risks and test controls annually. The program’s structured approach offers a road map for other states and municipalities seeking to strengthen their internal control environments.
Agencies must identify significant fiscal processes and document them using narratives or flowcharts. This includes outlining internal controls within each process.
A comprehensive risk assessment involves questionnaires, interviews and a SWOT (strengths, weaknesses, opportunities, threats) analysis to identify vulnerabilities.
Agencies test the design and operating effectiveness of controls, using sample sizes based on control frequency.
Agencies certify that their internal control systems are functioning effectively, reinforcing accountability.
While the benefits are clear, implementing an internal control framework, especially one modeled after ARMICS, comes with challenges.
Documenting, assessing and testing controls requires time, effort and expertise. Smaller agencies may struggle to allocate dedicated personnel or provide adequate training.
There’s a risk that the framework becomes overly procedural, leading to “check-the-box” compliance rather than meaningful engagement. Agencies must guard against losing sight of the strategic value of controls.
Cultural shifts toward accountability and documentation can be slow. Staff may be reluctant to adopt new processes or formalize existing ones.
The success of a framework depends heavily on leadership commitment and staff engagement. Without consistent interpretation and application of standards, effectiveness can vary widely across departments.
A strong focus on control can sometimes stifle innovation. Agencies must strike a balance between risk mitigation and agility, especially in fast-paced environments.
For agencies considering an ARMICS-like model, here’s a step-by-step guide to building a resilient internal control framework:
Begin by mapping out key fiscal operations, such as payroll, procurement and revenue collection. Documentation should include:
A thorough risk assessment should analyze potential events or conditions that could impact operations. Use a combination of:
Common pitfalls to avoid include insufficient documentation, lack of agency-wide evaluation and outdated process narratives.
Controls should address all aspects of significant fiscal processes and aim to meet the following objectives:
Controls must be clearly described and assigned to specific owners, with frequency and testing procedures outlined.
Develop a master spreadsheet listing all controls and related risks, including:
Sample sizes should reflect control frequency. For example: 25 samples for daily controls, three for monthly, and two for quarterly. Document test results consistently and validate findings with management.
Any deficiencies identified during testing should be documented and discussed with management. Action plans should be developed to remediate issues and ensure future compliance.
Expand the framework to cover human resources (HR) and IT controls. These areas are critical to agency integrity and should be tested using similar procedures and sample sizes based on control frequency.
Agencies must assess the internal controls of third-party vendors performing significant fiscal functions. Review System and Organization Controls (SOC) reports or other documentation to identify potential risks to financial operations or compliance.
Internal control frameworks are essential for public sector agencies striving for operational excellence, financial integrity and regulatory compliance. Programs like ARMICS demonstrate how a structured, consistent approach can yield significant benefits, from improved transparency to strategic alignment.
While implementation requires commitment and resources, the payoff is substantial. Agencies that invest in internal controls not only reduce risk but also build trust with stakeholders and position themselves for long-term success.
Whether you're starting from scratch or refining an existing framework, the principles of ARMICS offer a valuable guide. With experienced guidance, you can navigate the complexities and unlock the full potential of your internal control environment.
At Baker Tilly, we understand the unique challenges faced by public sector organizations. Our dedicated public sector practice includes over 350 professionals serving more than 4,000 clients across 48 states. We’ve worked with state entities, municipalities, school districts, tribal governments, universities and more. We specialize in helping public sector agencies build and maintain robust internal control frameworks. Our services include:
We understand the unique challenges faced by public sector organizations and offer practical, scalable solutions to enhance governance and accountability.

Article
Discover how consolidated IT security models like VITA enhance cybersecurity, reduce costs and align with frameworks for public sector resilience.