How to Establish Internal Controls for Your China FIE: 2026 Guide

Date:

Share post:






How to Establish Internal Controls for Your China FIE: 2026 Guide | China Gateway 360


How to Establish Internal Controls for Your China FIE: 2026 Guide

Document Reference: CG360-CORPORATE-GOV-GUID-006
Last Updated: July 2026
Jurisdiction: People’s Republic of China

Disclaimer: This guide provides general information for foreign-invested enterprises operating in China. It does not constitute professional audit or legal advice. Companies should engage qualified PRC auditors and legal counsel for their specific circumstances.

Table of Contents

1. The Internal Control Imperative for FIEs in 2026

For foreign-invested enterprises operating in China, establishing robust internal controls is no longer merely a matter of good governance — it is a regulatory necessity. The regulatory environment in 2026 demands that FIEs demonstrate effective internal control systems across financial reporting, operational processes, compliance, and data security. Weak internal controls expose FIEs to financial fraud, regulatory penalties, personal liability for legal representatives, and reputational damage that can affect the parent company’s global standing.

The Company Law 2024 Revision introduced strengthened requirements for corporate governance structures, including explicit obligations for boards of directors to establish and oversee internal control systems. Article 67 of the Company Law 2024 requires the board to “establish a sound internal management system” and “supervise the implementation of internal controls.” For FIEs, this statutory mandate means that internal controls must be documented, operational, and verifiable — not merely aspirational.

Additionally, the Foreign Investment Law requires FIEs to comply with all PRC regulations governing corporate operations, and SAMR has increasingly used non-compliance with internal control requirements as grounds for enhanced scrutiny during annual reporting and license renewals. The Ministry of Finance (MoF) has also issued “Basic Standards for Enterprise Internal Control” (C-SOX), which apply to all enterprises operating in China, including FIEs, though enforcement has historically been more rigorous for listed companies and financial institutions.

2026 Enforcement Context: Since January 2026, SAMR has coordinated with the Ministry of Finance on a joint inspection initiative targeting internal control deficiencies at FIEs with annual revenues exceeding RMB 100 million. Early results indicate that approximately 35% of inspected FIEs received corrective action notices, with the most common findings being inadequate segregation of duties, weak approval authority documentation, and insufficient data security controls.

2. Internal Control Framework: COSO Alignment and PRC Requirements

China’s internal control framework, commonly referred to as C-SOX, draws heavily from the COSO (Committee of Sponsoring Organizations) Internal Control — Integrated Framework but incorporates China-specific requirements. FIEs are well-advised to align their internal controls with both frameworks to satisfy both local regulatory requirements and global parent company standards.

The PRC “Basic Standards for Enterprise Internal Control” (Caikuai [2008] No. 7, as supplemented) identifies five interconnected components:

  1. Internal Environment: Governance structure, organizational chart, HR policies, corporate culture, and assignment of authority and responsibility.
  2. Risk Assessment: Identification and analysis of risks relevant to achieving the FIE’s objectives, including financial reporting risks, operational risks, and compliance risks specific to the China operating environment.
  3. Control Activities: Policies and procedures that ensure management directives are carried out, including approvals, authorizations, verifications, reconciliations, and segregation of duties.
  4. Information and Communication: Systems that capture and communicate relevant information in a form and timeframe that enables personnel to carry out their responsibilities.
  5. Monitoring: Ongoing evaluations and separate evaluations (internal audits) to assess whether internal controls are present and functioning.

For FIEs, the key challenge is bridging the gap between the parent company’s global control framework (often SOX 404 or equivalent) and the PRC C-SOX requirements. In practice, this means maintaining two sets of control documentation that align at the control objective level but may differ in specific procedures. The Ministry of Finance has indicated that FIEs may adopt a single integrated framework provided that all C-SOX requirements are met.

3. Segregation of Duties and Approval Authority Matrix

Segregation of duties is the cornerstone of any effective internal control system, yet it remains one of the most challenging areas for FIEs in China, particularly those with lean operations where one person may handle multiple functions. The fundamental principle is that no single individual should be in a position to initiate, approve, execute, and record a transaction.

Minimum Segregation Requirements for FIEs:

  • Cash and Treasury: The person who initiates a payment must be different from the person who approves it, and the person who records it must be different from both. In practice, this means at least three separate individuals or roles.
  • Procurement and Payables: The person who selects a supplier and negotiates terms must not be the same person who approves the purchase order or processes the payment.
  • Inventory Management: Physical custody of inventory must be separated from inventory record-keeping and from the authorization of inventory adjustments.
  • Payroll: The person who maintains employee master data must be different from the person who processes payroll calculations, and both must be different from the person who disburses payroll funds.
Control Area Incompatible Duties Recommended Minimum Staffing Common FIE Deficiency
Cash Management Initiation, Approval, Recording, Reconciliation 3 roles (2 minimum with dual sign-off) CFO both approves and reconciles bank statements
Procurement Vendor Selection, PO Approval, Goods Receipt, Payment 4 roles (3 minimum) Operations manager selects vendor and approves PO
Accounts Payable Invoice Verification, Payment Approval, Check Signing 3 roles Same person verifies invoice and signs check
Inventory Physical Custody, Record-Keeping, Adjustment Authorization 3 roles Warehouse manager adjusts inventory records
Payroll Employee Data Maintenance, Payroll Calculation, Disbursement 3 roles HR manager both enters new hires and processes payroll
IT Access User Administration, System Administration, Security Monitoring 3 roles (or external provider) IT administrator has both admin and user rights
Fixed Assets Acquisition Approval, Custody, Depreciation Recording, Disposal 4 roles (3 minimum) Department head approves and disposes of assets
Tax Filing Tax Calculation, Return Preparation, Return Review, Payment 3 roles (2 minimum with external review) Same accountant prepares and files tax returns

Approval Authority Matrix: Every FIE should maintain a documented Approval Authority Matrix (AAM) that clearly specifies:

  1. Transaction types covered (procurement, capital expenditure, hiring, contracts, bank payments, asset disposals)
  2. Monetary thresholds for each approval level (department head, CFO/GM, legal representative, board of directors, shareholders)
  3. Required supporting documentation for each approval level
  4. Emergency approval procedures with post-approval ratification requirements

The AAM should be approved by the board of directors annually and distributed to all personnel with approval authority. In 2026, SAMR inspectors have been requesting to see AAM documentation as part of the joint inspection initiative, and FIEs without written AAMs have been cited for control deficiencies.

4. Financial Controls Under Chinese Accounting Standards (ASBE)

FIEs in China must maintain their statutory books in accordance with the Accounting Standards for Business Enterprises (ASBE), issued by the Ministry of Finance. While ASBE has been substantially converged with IFRS, significant differences remain, and FIEs must implement specific controls to address these differences.

Critical Financial Control Areas for FIEs:

Revenue Recognition: ASBE 14 (Revenue) differs from IFRS 15 in several respects, particularly regarding the timing of revenue recognition for long-term contracts and bundled service arrangements. FIEs must maintain detailed contract review procedures to ensure revenue is recognized correctly under both ASBE and the parent company’s reporting framework. Controls should include: contract-level revenue recognition assessments, documented five-step analysis (under ASBE 14), and quarterly review of revenue contracts by qualified PRC accountants.

Related Party Transactions: Under ASBE 36 and SAMR disclosure requirements, all related party transactions must be identified, documented, and disclosed. The Foreign Investment Law also requires FIEs to report certain related party transactions in the annual information report. Controls should include: a maintained list of all related parties, pre-approval of related party transactions exceeding RMB 500,000, arm’s-length documentation for pricing, and quarterly reconciliation of related party balances.

Asset Impairment: ASBE 8 requires annual impairment testing for fixed assets, intangible assets, and goodwill. The methodology for determining recoverable amounts under ASBE can differ from IFRS or US GAAP approaches. FIEs should maintain documented impairment testing procedures with clear assumptions that are reviewed by both PRC and parent company auditors.

Tax Reconciliation: The gap between accounting profit and taxable profit under PRC tax law requires meticulous reconciliation. FIEs must maintain a permanent tax reconciliation file that tracks all temporary and permanent differences, including transfer pricing adjustments, entertainment expense disallowances, and withholding tax on deemed dividends.

Regulatory Update — 2026: The Ministry of Finance issued new guidance in March 2026 on revenue recognition for multi-element contracts common in technology FIEs. Companies with software-plus-service revenue models should review their ASBE 14 controls against this new guidance, which requires more granular identification of performance obligations than previously applied.

5. IT Controls, Data Security, and Cybersecurity Compliance

IT controls for FIEs in 2026 are shaped by three intersecting regulatory regimes: the Cybersecurity Law (CSL), the Data Security Law (DSL), and the Personal Information Protection Law (PIPL). Together, these laws impose comprehensive requirements on how FIEs manage information systems and data.

IT General Controls (ITGC):

  • User Access Management: User accounts must be provisioned based on the principle of least privilege. Access reviews must be conducted quarterly, with terminated employees’ access revoked within 24 hours. SAMR and the Cyberspace Administration of China (CAC) have coordinated to require FIEs to maintain access logs for a minimum of six months for regulatory inspection.
  • Change Management: All changes to production systems — including ERP upgrades, configuration changes, and security patches — must follow a documented change management process with separation of development, testing, and production environments. Changes affecting financial systems require pre-approval from the CFO.
  • Backup and Disaster Recovery: ASBE-compliant financial data must be backed up daily with off-site storage. The DSL requires important data to be stored within mainland China, and FIEs must document the geographic location of all data storage. Since the CAC’s February 2026 guidance update, FIEs subject to cross-border data transfer requirements must also demonstrate the ability to restore systems within 48 hours of a data incident.

Data Security Controls:

  • Data classification protocols (general, important, core) as defined under the DSL
  • Cross-border data transfer impact assessments for any data leaving China
  • Personal information protection impact assessments for any processing of PI of more than 1 million individuals annually
  • Data localization controls ensuring that “important data” as defined by industry-specific catalogues remains stored and processed within China

Cybersecurity Controls: FIEs classified as Critical Information Infrastructure (CII) operators face additional obligations, including mandatory cybersecurity threat testing, dedicated security personnel, and incident reporting within two hours. Even non-CII FIEs should implement multi-factor authentication for financial systems, intrusion detection systems, and regular penetration testing.

6. Inventory, Procurement, and Fixed Asset Controls

Physical asset controls are a common area of deficiency for FIEs, particularly those with manufacturing operations or significant fixed asset bases in China.

Inventory Controls:

  • Cycle Counting: High-value inventory items (defined as items with unit cost exceeding RMB 50,000 or total value exceeding RMB 500,000) should be counted monthly. All other inventory should be counted quarterly, with a full physical inventory conducted at fiscal year-end.
  • Inventory Adjustment Approvals: Any inventory write-off or adjustment exceeding RMB 10,000 (or a lower threshold set by the board) must be approved by the CFO in writing, with supporting documentation for the adjustment reason (damage, obsolescence, theft, or count discrepancy).
  • Third-Party Inventory: Inventory held at third-party warehouses or by contract manufacturers must be confirmed in writing quarterly, with physical inspection at least annually.

Procurement Controls:

  • Vendor Master Data: New vendor setup must require documented due diligence (business license, bank account verification, and anti-corruption screening). Changes to vendor bank details must be verified through a call-back procedure.
  • Competitive Bidding: Procurement exceeding RMB 500,000 requires at least three competitive bids. Single-source procurement above this threshold requires documented justification and CFO approval.
  • Three-Way Matching: No payment shall be processed without three-way matching of the purchase order, goods receipt note, and supplier invoice.

Fixed Asset Controls:

  • Fixed asset register must be maintained and reconciled to the general ledger quarterly
  • Physical verification of fixed assets with unit cost exceeding RMB 5,000 must be conducted annually
  • Asset disposals require documented board or management approval depending on the disposal value relative to the AAM thresholds
  • Construction-in-progress must be reviewed quarterly, and capitalization triggers must be documented to prevent inappropriate deferral of depreciation

7. Anti-Corruption Compliance and Fraud Prevention

Anti-corruption controls are critical for FIEs operating in China, where both PRC law and extraterritorial legislation (the US Foreign Corrupt Practices Act and the UK Bribery Act for parent companies) impose overlapping requirements. The PRC Anti-Unfair Competition Law and the Criminal Law prohibit bribery of government officials and commercial bribery, with penalties including criminal liability for both the company and responsible individuals.

Essential Anti-Corruption Controls for FIEs:

  • Gifts and Entertainment Policy: Clear monetary limits for gifts (RMB 500 per recipient per occasion recommended maximum), entertainment expenses (RMB 400 per person per meal), and a prohibition on cash equivalents (gift cards, vouchers). All gifts and entertainment must be recorded in a centralized log.
  • Third-Party Due Diligence: All sales agents, distributors, customs brokers, and government liaison consultants must undergo anti-corruption due diligence before engagement. This includes background checks, beneficial ownership identification, and contractual anti-corruption representations and warranties.
  • Facilitation Payments: Zero-tolerance policy for facilitation payments, with clear guidance on how to handle situations where government officials or third parties request expediting payments.
  • Whistleblower Hotline: An independently operated whistleblower hotline (anonymous and available in Chinese and English) that allows employees and third parties to report suspected violations. The hotline must be operated by a third party or the internal audit function, not by management.
  • Political Contributions and Sponsorships: Absolute prohibition on political contributions. Sponsorships and charitable donations must be pre-approved by the compliance officer and reviewed for potential conflicts of interest.

Fraud Prevention Controls:

  • Expense Report Auditing: Random audit of at least 10% of employee expense reports monthly, with 100% audit of reports from employees in high-risk roles (procurement, government affairs, sales management).
  • Bank Account Verification: Monthly reconciliation of all bank accounts by someone independent of the cash management function, with direct confirmation of balances from banks (not relying solely on bank statements).
  • Payroll Verification: Quarterly verification of the employee master file against HR records, including confirmation that all employees on the payroll are genuine (to prevent ghost employee fraud).
  • Journal Entry Review: All manual journal entries exceeding RMB 50,000 must be reviewed and approved by a senior finance manager who did not prepare the entry.

8. Internal Audit Function and Regulatory Reporting

An effective internal audit function is the backbone of a sustainable internal control system. For FIEs in China, the internal audit function must be structured to provide independent assurance while navigating the practical realities of a relatively small local operation.

Internal Audit Structure:

  • Reporting Line: The internal audit function should report functionally to the board of directors (or the audit committee) and administratively to the China country manager or CFO. Direct reporting to the CFO alone compromises independence.
  • Outsourced vs. In-House: FIEs with annual revenues below RMB 200 million may consider outsourcing internal audit to a qualified PRC audit firm. Larger FIEs should maintain at least one dedicated internal auditor on staff.
  • Audit Plan: A risk-based annual audit plan should be approved by the board of directors. Areas of high inherent risk for FIEs include procurement, treasury, related party transactions, tax compliance, and data security.

Regulatory Reporting Controls:

  • Annual Report (SAMR Nianbao): Controls should ensure that the annual report is reviewed for accuracy before submission, with documented support for all reported figures. The submission deadline (June 30 each year) must be tracked with a compliance calendar.
  • Foreign Investment Information Report: Quarterly submissions to the Ministry of Commerce must be reconciled to the general ledger before filing. The legal representative’s certification of these reports means that review controls must be robust.
  • Tax Filing Reconciliation: Controls should ensure that tax returns are prepared by one person, reviewed by a second person, and approved by the CFO or tax manager before filing. All tax payments should be reconciled to the tax return and general ledger monthly.
  • Transfer Pricing Documentation: FIEs must maintain contemporaneous transfer pricing documentation for all related party transactions. Annual transfer pricing benchmarking studies should be completed before the tax filing deadline, with local file and master file documentation maintained as required by State Taxation Administration regulations.
Implementation Roadmap for 2026: China Gateway 360 recommends a phased approach: Phase 1 (Months 1-3): Document the current control environment and identify gaps against C-SOX requirements. Phase 2 (Months 4-6): Implement critical controls in treasury, procurement, and financial reporting. Phase 3 (Months 7-9): Deploy IT controls and data security measures. Phase 4 (Months 10-12): Establish the internal audit function and conduct a full control self-assessment. Each phase should include training for affected personnel.

China Gateway 360 — Building Robust Governance for Your China Operations

This guide is part of our Corporate Governance series for foreign-invested enterprises. For assistance with internal control design, C-SOX compliance, internal audit setup, or control remediation, contact our team at governance@china-gateway360.com.

Last reviewed: July 2026 | Next scheduled review: January 2027

Reference: CG360-CORPORATE-GOV-GUID-006


Related articles

How a Foreign Biotech Startup Entered China’s Precision Medicine Market: Case Study

How a Foreign Biotech Startup Entered China's Precision Medicine Market: Case Study In 2023, NovaOnco Therapeutics, a US-based AI biotech startup, exe

How Legend Biotech Secured FDA Approval for CAR-T Therapy: Case Study

How Legend Biotech Secured FDA Approval for CAR-T Therapy: A China Biotech Case Study This case study examines how Legend Biotech (传奇生物, Legend Biotec

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study

How Innovent Biologics Achieved Global Clinical Trial Leadership: Case Study body{font-family:'Segoe UI',Tahoma,Geneva,Verdana,sans-serif;line-height:

How BeiGene Built a Billion-Dollar Biotech in China: Case Study

How BeiGene Built a Billion-Dollar Biotech in China: Case Study How BeiGene Built a Billion-Dollar Biotech in China: Case Study The story of BeiGene's