Home / Insights / The Self-Assessment You Can Actually Trust

Operational Controls

The Self-Assessment You Can Actually Trust

May 18, 2026  ·  3 min read

Dubai, UAE — 18 May 2026 · Written by George Stoyanov · 8 min read

Control self-assessment works only when it reflects what is really happening across the operation. What makes one reliable, and where most programmes fall short.

What a Control Self-Assessment Is Really For

Control Self-Assessment lets each hotel evaluate its own internal controls — approvals, reconciliations, system checks and documentation — across the whole operation, rather than waiting for a periodic audit. Done well, it gives leadership something a central audit team alone cannot.

Standardise the controls

One common standard applied across every property, so expectations and results are comparable portfolio wide.

Give management ownership

Responsibility for maintaining controls sits with the teams who run them day to day, not only with internal audit.

Surface risk early

Low-scoring areas and properties are flagged before they become audit findings, losses or revenue leakage.

249Control points
10Operational areas
130Risk-weighted points

Where Self-Assessment Programmes Fall Short

CSA delivers real value, but a few recurring issues can quietly undermine it.

Answers not backed by evidence

Controls are often marked “in place” from observation or memory, rather than verified against a required proof: a report, reconciliation or approval trail.

Scores optimised, not accurate

Where recognition rewards high scores, teams tend toward the reassuring answer. The assessment then measures confidence rather than control.

A gap with on-site reviews

When properties score well on the CSA but raise findings on the on-site review, it is a sign the self-assessment is not being applied rigorously.

“These are design problems, not people problems. When a self-assessment is built around evidence and real risk, it stops being a formality and starts guiding decisions.”

— George Stoyanov, Platform Chairman

Four Principles That Separate Assessment From Checklist

  1. Evidence-based — Every control tied to a specific proof and frequency — screenshots, logs, approval trails, reconciliations — so answers are verified, not asserted.
  2. Risk-weighted — Not every control matters equally. Points are allocated by materiality, so the score reflects where the money and the risk sit.
  3. Accountable — A named performer, reviewer and owner for each control, with Delegation of Authority embedded and segregation of duties by design.
  4. Benchmarked — Scored and comparable across the portfolio, so leadership can rank properties, target audits and track control maturity over time.

Inside the PROFIX Operational Controls CSA

One evidence-based, risk-weighted standard applied across the whole operation. Points are allocated by materiality, not evenly. Each control is assessed against a required evidence standard and rolls up to a weighted compliance score per area and overall, so the number reflects where hotel risk concentrates.

249Control points assessed
10Operational areas
73Sub-processes / control areas
130Risk-weighted points

Every answer backed by proof

A defined evidence standard and frequency for each control.

A performer, reviewer and owner

Recorded for every control, with Delegation of Authority embedded.

Gaps logged as action plans

Tracked to closure and re-tested at the next cycle.

Ten Areas, Weighted by What Is at Stake

Revenue and cost controls carry the most points, because that is where the risk lives.

Room Revenue — 25 pts

Rate integrity, paymaster and rebate control, reconciliation.

Food & Beverage — 23 pts

Voids, discounts, open checks, cost of sales and stock.

Finance — 17 pts

Cash handling, banking, disbursements and accounting.

Human Resources — 13 pts

Payroll, timekeeping, system access and records.

Governance — 12 pts

Licences, insurance, tax and subcontractor control.

Accounts Receivable — 10 pts

Credit, invoicing, collections and reconciliation.

Purchase & Stocks — 9 pts

Supplier, ordering, receiving and inventory.

Information Technology — 7 pts

Access, servers and IT support.

Miscellaneous Revenue — 7 pts

Leased outlets, spa and shared-profit arrangements.

Security — 7 pts

Crisis control, logs and surveillance.

Ready to Work With a Firm That Actually Knows Your Industry?

Whether you need a statutory audit, a food safety review, an HMA advisory, or a complete risk advisory engagement — PROFIX Consulting is ready to help.

Get Started

Ready to Work With a Firm That Actually Knows Your Industry?

Whether you need a statutory audit, a food safety review, an HMA advisory, or a complete risk advisory engagement — PROFIX Consulting is ready to help.