Home / Platform / Operational & Financial Controls Self-Audit

Hotel Operations Self-Audit

Operational & Financial Controls Self-Audit

249 control points across 73 sub-processes and ten operational areas, scored against a 130-point risk-weighted model. Points are allocated by materiality, not evenly — so the score reflects where the money and the risk actually sit.

249Control points assessed
73Sub-processes and control areas
10Operational areas
130Risk-weighted points
Scope

What the assessment covers

Ten areas, weighted by what is at stake. Points are allocated by materiality rather than evenly — revenue and cost controls carry the most, because that is where the risk lives. Each area is scored independently and rolls up to a weighted compliance score.

25 pts

Room Revenue

Rate integrity, paymaster and rebate control, and reconciliation — the largest revenue line in the hotel and the most heavily weighted area in the assessment.

23 pts

Food & Beverage

Voids, discounts, open checks, cost of sales and stock — where consumption and revenue most often fail to reconcile.

17 pts

Finance

Cash handling, banking, disbursements and accounting, including the month-end discipline behind them.

13 pts

Human Resources

Payroll, timekeeping, system access and employee records, with segregation of duties around people costs.

12 pts

Governance

Licences, insurance, tax and subcontractor control, plus whether management reviews and acts on control failures.

10 pts

Accounts Receivable

Credit approval, invoicing, collections and reconciliation across the city ledger.

9 pts

Purchasing & Stocks

Supplier approval, ordering, receiving and inventory control.

7 pts

Information Technology

Access rights, servers and IT support — the system permissions that underpin every other control.

7 pts

Miscellaneous Revenue

Leased outlets, spa and shared-profit arrangements — income streams that are rarely reviewed.

7 pts

Security

Crisis control, logs and surveillance, alongside asset protection and key control.

Grounded in

What it is measured against

Critical operational controlsKey financial controlsSegregation of dutiesIndustry best practiceLeading standards followed by leading brandsUniform system of accounts
Why self-assessment

What a control self-assessment is really for

Done well, self-assessment gives leadership something a central audit team alone cannot: one common standard applied across every property, ownership sitting with the teams who run the controls, and low-scoring areas flagged before they become audit findings.

249Control points assessed
73Sub-processes and control areas
10Operational areas
130Risk-weighted points
Common challenges

Where self-assessment programmes fall short

Three recurring issues quietly undermine CSA. Controls marked “in place” from observation or memory rather than verified against a required proof. Scores optimised rather than accurate, because recognition rewards high numbers — so the assessment measures confidence rather than control. And a gap with on-site reviews: when properties score well on the CSA but raise findings on the audit, the self-assessment is not being applied rigorously.

Scoring

Our scoring is risk focussed

Every question is scored on the same four-point scale, and a score on its own is never enough, the portal allows to upload the evidence behind it and the action that follows.

0 · Not in place

The control does not exist

No procedure, no ownership, no record. Scores zero and drives a corrective action automatically.

1 · Partial

In place but not consistent

The control exists on paper but is not applied reliably, or the evidence is incomplete. Partial credit, with the gap documented.

2 · Fully in place

Operating and evidenced

The control exists, is followed day to day, and there is documentation to prove it.

N/A

Not applicable

Excluded from the denominator rather than scored as a failure, so properties are not penalised for services they do not run.

Evidence

Every answer is supported

Notes and evidence are captured against the question itself, so the reviewer sees the reasoning rather than just the number.

Corrective action

Gaps get an owner

Anything below full compliance carries a corrective action, tracked to closure and re-tested at the next cycle.

Reading the result

Full Maturity Rating allowing for portfolio wide benchmark

Section scores roll into a weighted overall compliance rating, but critical controls are reported separately, so a property cannot pass overall while failing something that matters.

Compliance bands

Excellent, Good, Adequate, Needs Improvement

A plain-English band on top of the percentage, so a General Manager, Director of Finance and a Head of Internal Audit read the same result the same way.

Critical alerts

Flagged independently of the score

Questions marked critical raise an alert on their own. A strong overall percentage never buries a failed critical control.

Section health

Where the gap actually sits

Each section carries its own score and band, so a single overall number resolves into the two or three areas actually causing it.

Workflow

Nothing is finished until someone signs it off

Assessments move through a controlled review cycle with named roles, so a self-assessment carries the same discipline as an audit rather than becoming a tick-box exercise.

01

In Progress

The assessor works through the questionnaire, scoring each control and capturing evidence.

02

Submitted

The completed assessment is locked and passed to a reviewer.

03

Awaiting Review

A reviewer checks scoring and evidence, and either signs off or returns it.

04

Returned

Rejected assessments go back with comments so gaps are corrected, not argued over.

05

Signed Off

The result is final, findings become tracked corrective actions with owners.

How it is run

We start it, your team sustains it

The platform is not marked homework. PROFIX conducts the initial assessment, trains your internal team to run it, and stays involved through the review cycle. We created the properties for you to do assessments

01

We assess first

PROFIX conducts the baseline assessment on site, so the first score is independent, and the standard is set correctly.

02

We train your team

Your assessors learn what each control means and what evidence is expected, so scoring stays consistent between cycles.

03

Your team reassesses

Periodic self-assessment on your own schedule, per property, without waiting for an audit to be scheduled.

04

A reviewer signs off

Nothing is final until reviewed. Rejected assessments return with comments rather than being quietly accepted.

05

Improve and re-test

Corrective actions carry into the next cycle, so the score becomes a trend rather than a snapshot.

ComplimentaryIncluded with internal audit and risk engagements
Board-readyEvery completed assessment exports as a branded PDF
Per propertyRun across a portfolio, compared side by side
Benchmarking

Compare properties side by side

Select up to four properties and overlay their section performance on a single view. See which property leads, which needs attention, and exactly which sections drive the gap.

Section overlay

Where the gap actually is

Every section scored and overlaid across properties, so a low overall score resolves into the two or three sections actually causing it.

Overall ranking

Good, Adequate, Needs Improvement

Each property ranked with a clear compliance band, so the portfolio picture is readable at a glance.

Alert summary

Critical issues surfaced first

Critical questions raise alerts independently of the score, so a property cannot pass overall while failing something that matters.

Questions

Before you run it

How does this differ from an internal audit?

Same control framework, different operator. An internal audit is performed by us; this is performed by your team on a cycle you set, with our review. Most clients run both — audit annually, self-assess quarterly.

Do we need all ten areas?

No. Scope to the areas that matter for the property. Anything excluded is marked N/A and removed from the denominator.

Who typically owns it?

The Financial Controller or Director of Finance, with department heads answering for their own areas and the General Manager reviewing before sign-off.

Does it align with ICFR work?

Yes. The control set is built on the same internal control principles, so findings feed directly into ICFR and risk-based audit planning.

Get Started

Ready to Work With a Firm That Actually Knows Your Industry?

Whether you need a statutory audit, a food safety review, an HMA advisory, or a complete risk advisory engagement — PROFIX Consulting is ready to help.