Home / Platform / Operational & Financial Controls Self-Audit
Hotel Operations Self-AuditOperational & Financial Controls Self-Audit
249 control points across 73 sub-processes and ten operational areas, scored against a 130-point risk-weighted model. Points are allocated by materiality, not evenly — so the score reflects where the money and the risk actually sit.
What the assessment covers
Ten areas, weighted by what is at stake. Points are allocated by materiality rather than evenly — revenue and cost controls carry the most, because that is where the risk lives. Each area is scored independently and rolls up to a weighted compliance score.
Room Revenue
Rate integrity, paymaster and rebate control, and reconciliation — the largest revenue line in the hotel and the most heavily weighted area in the assessment.
Food & Beverage
Voids, discounts, open checks, cost of sales and stock — where consumption and revenue most often fail to reconcile.
Finance
Cash handling, banking, disbursements and accounting, including the month-end discipline behind them.
Human Resources
Payroll, timekeeping, system access and employee records, with segregation of duties around people costs.
Governance
Licences, insurance, tax and subcontractor control, plus whether management reviews and acts on control failures.
Accounts Receivable
Credit approval, invoicing, collections and reconciliation across the city ledger.
Purchasing & Stocks
Supplier approval, ordering, receiving and inventory control.
Information Technology
Access rights, servers and IT support — the system permissions that underpin every other control.
Miscellaneous Revenue
Leased outlets, spa and shared-profit arrangements — income streams that are rarely reviewed.
Security
Crisis control, logs and surveillance, alongside asset protection and key control.
What it is measured against
What a control self-assessment is really for
Done well, self-assessment gives leadership something a central audit team alone cannot: one common standard applied across every property, ownership sitting with the teams who run the controls, and low-scoring areas flagged before they become audit findings.
Where self-assessment programmes fall short
Three recurring issues quietly undermine CSA. Controls marked “in place” from observation or memory rather than verified against a required proof. Scores optimised rather than accurate, because recognition rewards high numbers — so the assessment measures confidence rather than control. And a gap with on-site reviews: when properties score well on the CSA but raise findings on the audit, the self-assessment is not being applied rigorously.
Our scoring is risk focussed
Every question is scored on the same four-point scale, and a score on its own is never enough, the portal allows to upload the evidence behind it and the action that follows.
The control does not exist
No procedure, no ownership, no record. Scores zero and drives a corrective action automatically.
In place but not consistent
The control exists on paper but is not applied reliably, or the evidence is incomplete. Partial credit, with the gap documented.
Operating and evidenced
The control exists, is followed day to day, and there is documentation to prove it.
Not applicable
Excluded from the denominator rather than scored as a failure, so properties are not penalised for services they do not run.
Every answer is supported
Notes and evidence are captured against the question itself, so the reviewer sees the reasoning rather than just the number.
Gaps get an owner
Anything below full compliance carries a corrective action, tracked to closure and re-tested at the next cycle.
Full Maturity Rating allowing for portfolio wide benchmark
Section scores roll into a weighted overall compliance rating, but critical controls are reported separately, so a property cannot pass overall while failing something that matters.
Excellent, Good, Adequate, Needs Improvement
A plain-English band on top of the percentage, so a General Manager, Director of Finance and a Head of Internal Audit read the same result the same way.
Flagged independently of the score
Questions marked critical raise an alert on their own. A strong overall percentage never buries a failed critical control.
Where the gap actually sits
Each section carries its own score and band, so a single overall number resolves into the two or three areas actually causing it.
Nothing is finished until someone signs it off
Assessments move through a controlled review cycle with named roles, so a self-assessment carries the same discipline as an audit rather than becoming a tick-box exercise.
In Progress
The assessor works through the questionnaire, scoring each control and capturing evidence.
Submitted
The completed assessment is locked and passed to a reviewer.
Awaiting Review
A reviewer checks scoring and evidence, and either signs off or returns it.
Returned
Rejected assessments go back with comments so gaps are corrected, not argued over.
Signed Off
The result is final, findings become tracked corrective actions with owners.
We start it, your team sustains it
The platform is not marked homework. PROFIX conducts the initial assessment, trains your internal team to run it, and stays involved through the review cycle. We created the properties for you to do assessments
We assess first
PROFIX conducts the baseline assessment on site, so the first score is independent, and the standard is set correctly.
We train your team
Your assessors learn what each control means and what evidence is expected, so scoring stays consistent between cycles.
Your team reassesses
Periodic self-assessment on your own schedule, per property, without waiting for an audit to be scheduled.
A reviewer signs off
Nothing is final until reviewed. Rejected assessments return with comments rather than being quietly accepted.
Improve and re-test
Corrective actions carry into the next cycle, so the score becomes a trend rather than a snapshot.
Compare properties side by side
Select up to four properties and overlay their section performance on a single view. See which property leads, which needs attention, and exactly which sections drive the gap.
Where the gap actually is
Every section scored and overlaid across properties, so a low overall score resolves into the two or three sections actually causing it.
Good, Adequate, Needs Improvement
Each property ranked with a clear compliance band, so the portfolio picture is readable at a glance.
Critical issues surfaced first
Critical questions raise alerts independently of the score, so a property cannot pass overall while failing something that matters.
Before you run it
How does this differ from an internal audit?
Same control framework, different operator. An internal audit is performed by us; this is performed by your team on a cycle you set, with our review. Most clients run both — audit annually, self-assess quarterly.
Do we need all ten areas?
No. Scope to the areas that matter for the property. Anything excluded is marked N/A and removed from the denominator.
Who typically owns it?
The Financial Controller or Director of Finance, with department heads answering for their own areas and the General Manager reviewing before sign-off.
Does it align with ICFR work?
Yes. The control set is built on the same internal control principles, so findings feed directly into ICFR and risk-based audit planning.
Ready to Work With a Firm That Actually Knows Your Industry?
Whether you need a statutory audit, a food safety review, an HMA advisory, or a complete risk advisory engagement — PROFIX Consulting is ready to help.