Accounts payable controls for a lean finance team.
Protect the points where vendors are created, invoices are approved, payment instructions change, cash is released, and activity is reconciled.
A lean finance team may not be able to assign a different employee to every accounts-payable task. Useful controls should protect the points where a vendor is created, an obligation is approved, payment instructions change, cash is released, and activity is reconciled. When duties are concentrated, clear authority, documented approvals, restricted access, and independent management review become more important.
Map the complete payment process
Begin by documenting how a transaction moves through the company:
- A vendor is approved and entered into the system.
- An invoice is received.
- Goods or services are confirmed.
- The invoice is coded and approved.
- A payment batch is prepared.
- An authorized person releases payment.
- The payment is recorded.
- The bank account and vendor records are reconciled.
For each stage, identify who can initiate, change, approve, release, record, and review activity. This often exposes gaps more clearly than a general policy stating that “all invoices require approval.”
Protect vendor setup and payment changes
Access to the vendor master should be limited to designated personnel. New vendors should have documented business support, appropriate tax information, and approval from someone with the necessary authority.
Changes to bank accounts or payment instructions deserve particular attention. A request received by email should be verified through a previously established contact method—not a telephone number or link contained in the request itself. The FBI’s business-email-compromise guidance specifically recommends verifying changes in account numbers or payment procedures with the person making the request.
A lean team can strengthen this process by requiring:
- Independent verification of sensitive vendor changes.
- Evidence of the verification date and method.
- Secondary approval for bank-account changes.
- A report of newly created or recently changed vendors.
- Separation between changing payment details and releasing the next payment, where practical.
Require evidence before approving invoices
An approver should be able to see the invoice, business purpose, coding, and evidence that the goods or services were received. Where the company uses purchase orders, the invoice can be compared with the approved order and receiving information.
The review should also consider duplicate invoice numbers, unusual quantities or pricing, sales-tax treatment, credits, and whether the expense belongs to the correct period, entity, location, or project. Approval authority should be documented by amount, transaction type, and organizational responsibility. Employees should not approve their own expenses, and exceptions to the normal process should be recorded and reviewed rather than handled informally.
Separate payment preparation from release
When staffing permits, the person preparing a payment batch should not be the only person able to release it. Final payment authority should remain with an authorized company representative who can review the payment register and supporting documentation.
Banking platforms may offer dual authorization, transaction limits, alerts, or positive pay. Management should evaluate the available features and retain appropriate cash-disbursement authority.
If one employee must prepare and record payments, a different authorized person can review the supporting documents and release the batch. That is a practical separation of the most sensitive stages even when full segregation is not possible.
Use compensating controls when duties are concentrated
A compensating control provides independent oversight where ideal separation is impractical. Examples for a lean team include:
- Owner or executive review of each payment register before release.
- Bank alerts sent to a person who does not prepare payments.
- Review of new vendors and recent vendor-master changes.
- Independent review of monthly bank reconciliations.
- Comparison of significant vendor statements with the payable ledger.
- Review of duplicate-payment, manual-check, or payment-exception reports.
- Periodic review of user access and payment limits.
The reviewer should have enough information and authority to question an item, stop a payment, and document the resolution. A signature alone is weak evidence if the reviewer cannot see what was examined.
Reconcile and monitor after payment
Monthly bank reconciliations should be completed promptly and reviewed by someone other than the preparer when practical. The review should address outstanding checks, rejected or reversed payments, unexpected bank fees, and transactions recorded directly through the bank.
Management may monitor urgent manual payments, activity outside normal processing dates, repeated invoice amounts, newly changed bank instructions, and other exceptions. These indicators warrant follow-up; they do not establish that fraud or misconduct occurred.
Preserve supporting records and access evidence
Retain invoice, approval, receiving, vendor-change, payment, and exception evidence. Give system users individual credentials and access appropriate to their responsibilities, change rights promptly when roles change, and review the access list periodically.
Keep responsibility and review scope clear
Company management is responsible for vendor approval, accounting records, system access, payment authority, bank relationships, control design, and decisions about corrective action. An outside accounting provider may prepare invoices or payment batches within an agreed scope, but the company should define and retain appropriate approval and oversight responsibilities.
A focused accounts-payable control review can examine a selected process, document the workflow, inspect agreed evidence, and communicate observations for management’s consideration. It does not determine whether fraud occurred, provide a legal or regulatory conclusion, or guarantee that future errors, losses, or misconduct will be prevented.
Control principles can be informed by established frameworks. For example, the GAO Green Book discusses preventive and detective control activities, although it is a federal-government standard rather than a private-company requirement.
Our Internal Audit services support management or a designated governance group through selected operational and internal-control reviews. This work is distinct from an external financial-statement audit, which John W. Halloran CPA, P.C. does not perform. For broader context, read when a privately held company may consider an internal-control review or explore Client Accounting Services. To discuss the current process and responsibilities, tell us about your business.
Frequently asked questions
Can a lean finance team maintain useful AP controls without adding staff?
Yes. The company can separate the most sensitive steps where practical and use independent management review, banking controls, alerts, reconciliations, and exception reports as compensating controls. The design should fit the company's actual workflow and available resources.
Should an outside accounting provider release company payments?
The arrangement depends on the agreed scope, but management should define and retain appropriate final approval and oversight. An authorized company representative should understand what is being paid and have access to the supporting documentation.
Does an accounts-payable control review guarantee that fraud will be prevented or detected?
No. Controls reduce risk but do not eliminate it. A review does not guarantee prevention or detection, determine whether fraud occurred, or provide legal conclusions. Management remains responsible for the process and its response to identified issues.
Tell us what is changing in your business.
Share your company, priorities, and timing. We review each inquiry and generally respond within one business day with the appropriate next step.