Mike Masoud | September 8, 2025
An organization may possess a robust internal control system—complete with clear approval rules, segregation of duties, due diligence, audit trails, and escalation procedures—yet remain dangerously exposed when a powerful executive can quietly switch those safeguards off.
That is the true threat of management override: the controls appear intact, policies remain active, and records seem complete, while authority is quietly leveraged to bypass the very mechanisms designed to prevent fraud, corruption, and abuse. The primary vulnerability is rarely a missing control; it is the individual who operates as if the control does not apply to them.
Not every override is improper. Exceptional circumstances may require legitimate exceptions. The governance problem begins when exceptions become informal, undocumented, recurring, personally directed, or effectively immune from challenge.
Five Takeaways for Boards and Management
- Good controls cannot protect an organization when powerful individuals can routinely bypass them.
- Document, justify, authorize, independently review, and trace any legitimate exception.
- Management override becomes substantially more dangerous when corporate culture penalizes dissent, leaving employees fearful that exercising Competent Questioning (Masoud, 2026a) may carry career consequences.
- Repeated “one-time exceptions” can become an unofficial parallel internal control system.
- Boards should know who can override material controls, under what conditions, and how those overrides are reported and reviewed.
A Familiar Management Override
A company has a sound vendor-onboarding process. New vendors require due diligence, conflict-of-interest disclosure, documented approval, and compliance with the applicable approved policy.
A senior executive instructs procurement to engage a consultant immediately because the matter is “strategically important.” Due diligence, employees are told, can follow later.
The consultant is engaged and payment is approved; however, the missing documentation is never completed.
Months later, internal audit discovers that the consultant had an undisclosed relationship with a person involved in the decision.
When an Exception Becomes a Parallel Internal Control System
A legitimate exception should operate through a defined governance process. The reason should be documented, approval authority clear, additional risk considered, and the exception reviewable afterward.
Repeated informal exceptions create something different: a second system in which formal controls apply to ordinary employees while influential people operate through personal instruction.
At that point, the exception is no longer exceptional.
Why Seniority Can Defeat Good Controls
Employees may recognize that a request is unusual but still comply because it comes from someone senior:
“Approve it this time.”
“Do not delay the payment.”
“I know this vendor.”
“Do not escalate this.”
None proves misconduct. But each should prompt questions when it asks someone to bypass a control without documented justification and review.
This is precisely where Competent Questioning (Masoud, 2026a) becomes an operational necessity. It requires those entrusted to govern, manage, audit, regulate, or approve to ask clear, relevant, timely, and evidence-seeking questions before risk matures into misconduct or institutional failure.
When Existing Controls Are Deliberately Circumvented
The Siemens case provides a powerful example. In 2008, Siemens AG pleaded guilty to criminal violations of the FCPA’s internal control and books-and-records provisions. The U.S. Department of Justice stated that Siemens engaged in systematic efforts to falsify corporate records and circumvent existing internal controls. Court records described mechanisms including limiting audits, obscuring approval trails, and allowing certain third-party payments on a single signature despite a “four eyes principle” requiring authorization by two managers (U.S. Department of Justice, 2008a; 2008b).
When Senior Authority Becomes Part of the Fraud
United Commercial Bank provides a different warning. Ebrahim Shabudin, its Chief Operating Officer and Chief Credit Officer and the second most senior officer in executive management, was convicted after trial of seven offenses arising from a scheme to conceal losses and inflate the bank’s financial statements. One conviction was specifically for circumventing internal accounting controls. He was later sentenced to 97 months in prison (U.S. Department of Justice, 2015).
Competent Questioning before the Override
Before accepting a material exception, decision-makers should ask:
What control are we being asked to bypass?
Why is the exception necessary?
Who has authority to approve it?
What evidence supports the urgency?
What additional risk does it create?
Who will independently review it?
When will any deferred requirement be completed?
Has the same “exception” occurred before?
This also reflects Entrusted Authority Intelligence: the competence and judgment required to exercise entrusted authority responsibly, supported by competence, integrity, and decision-making effectiveness (Masoud, 2026b).
Five Controls Organizations Should Consider
- Define who may authorize material exceptions.
- Require written business justification.
- Record material overrides in a traceable register.
- Require independent review or compensating controls.
- Report patterns of significant override to the board or audit committee.
What Boards Should Ask
The key question is simple:
Boards should also look for patterns by executive, vendor, transaction type, business unit, and frequency. A series of separately approved exceptions may reveal a systemic weakness that no individual exception shows.
One Hard Takeaway
A well-designed control does not protect an organization when authority can silently switch it off.
The true measure of an effective internal control system is not whether rules are followed when compliance is convenient. It is whether the organization preserves independent challenge, documentation, and accountability when someone with significant authority demands an exception.
When authority repeatedly defeats control, the root issue is no longer the individual exception—it is a compromised governance system.
References
Masoud, M. (2026a) Competent Questioning: An Anti-Corruption Governance Concept. The American Anti-Corruption Institute (AACI). Available at: https://www.theaaci.net/Competent-Questioning (Accessed: 8 September 2026).
Masoud, M. (2026b) Entrusted Authority Intelligence: An Anti-Corruption Governance Concept. The American Anti-Corruption Institute (AACI). Available at: https://www.theaaci.net/Entrusted-Authority-Intelligence (Accessed: 8 September 2026).
U.S. Department of Justice (2008a) Siemens AG and Three Subsidiaries Plead Guilty to Foreign Corrupt Practices Act Violations and Agree to Pay $450 Million in Combined Criminal Fines. 15 December. Available at: https://www.justice.gov/archive/opa/pr/2008/December/08-crm-1105.html (Accessed: 8 September 2026).
U.S. Department of Justice (2008b) United States v. Siemens Aktiengesellschaft: Statement of Offense, Cr. No. 08-367-RJL. U.S. District Court for the District of Columbia. Available at: https://www.justice.gov/archive/opa/documents/siemens-ag-stmt-offense.pdf (Accessed: 8 September 2026).
U.S. Department of Justice (2015) Former United Commercial Bank Chief Credit Officer Sentenced to Over Eight Years for Felony Fraud Conviction. 1 September. Available at: https://www.justice.gov/archives/opa/pr/former-united-commercial-bank-chief-credit-officer-sentenced-over-eight-years-felony-fraud (Accessed: 8 September 2026).
Disclaimer
This article is provided for educational and informational purposes only. It does not constitute legal, regulatory, audit, compliance, or financial advice. The existence of an exception, override, or control weakness does not, by itself, establish fraud, corruption, or other misconduct. Organizations should evaluate relevant circumstances, follow applicable governance and internal control procedures, and obtain appropriate professional advice where necessary.
External cases are discussed solely to illustrate governance and internal control lessons based on the cited official sources.







































