04 Finance systems
Implementing the Finance Stack
How we select and sequence a finance stack: ledger, AP, payroll, expense, reporting, with cutover at a period boundary and a parallel run first.
What this covers
03Financial controls
Textbook segregation of duties assumes a finance department. You have an office administrator, an operations manager and an owner. Here is the matrix that actually works at that size.
In a fifteen person company the finance function is often one administrator and an owner who signs things between customer calls. Standard control guidance tells you to separate authorisation, execution, recording and reconciliation across four people. You do not have four people. What you can do is separate the two combinations that actually cause losses, put a small number of compensating controls where a split is impossible, and write the whole thing down so it survives the administrator going on leave. That is the matrix below. It is designed to be adopted in an afternoon and tested quarterly, not to satisfy an auditor's questionnaire. The matrix is designed and installed by Khaled Hawari, whose roughly eight years in Ottawa practice were spent looking at what companies this size actually do rather than at what a control framework assumes they do.
ScopeWhat the engagement covers
Every payment, receipt and journal involves four duties: authorising the transaction, executing it, recording it in the ledger, and reconciling the account afterwards. In a small company you cannot separate all four, so you separate the two combinations that turn an error into a loss. The first is execution and reconciliation: whoever can move money must never be the person who reconciles the account the money moved through, because that combination lets a payment be made and then hidden. The second is authorisation and vendor or employee master data: whoever approves a payment must not be the person who can create or change the payee's banking details, because that combination lets a payment go to a new destination without anyone noticing. Every other overlap in a company this size is survivable with a compensating control. Those two are not.
Across the payment cycle we assign five roles, and only three of them belong to your staff. Vendor set up and banking detail changes are requested by the operations manager and confirmed independently by the owner using a phone number the requester did not supply. Purchase approval sits with the operations manager up to the threshold you set, and with the owner above it. Invoice entry and coding sit with the office administrator or with us. Payment release in the bank requires the owner, or two named approvers where your bank supports dual release. Recording in the ledger sits with whoever entered it. Reconciliation of the bank and card accounts sits with us, never with the person who releases payments or enters invoices. Review of the reconciliations sits with a second person on our side. The point of writing it out this way is that each cell has one name, and the two forbidden combinations never appear in the same row.
When a duty genuinely cannot be split, you replace separation with visibility. The strongest and cheapest compensating control at this size is the owner reviewing a payment register rather than individual invoices: one list, every payment made in the period, payee, amount, approver, with new payees flagged. It takes minutes and it catches the thing that individual invoice signing does not, which is a familiar looking payment to an unfamiliar destination. Alongside it we set dual release in online banking wherever the bank offers it, restrict who can add a payee, turn on alerts for new payees and for payments above a threshold, and take the payment file out of email entirely. Corporate cards get a monthly statement review by someone other than the cardholder, and the owner's own card is reviewed by us, because the owner's spending is the one card in most small companies that nobody looks at.
Payroll is where the largest single-transaction exposure sits in a small company, and it is almost always run by one person. The split we install is narrow and specific: whoever prepares the payroll run does not approve it, and whoever approves it does not have the ability to add an employee or change banking details unilaterally. New employee set up requires the signed offer or the record of hire as support, and a change to an employee's deposit details requires confirmation with the employee through a channel other than the one the change request arrived on, because a fraudulent deposit change request that looks exactly like an employee email is one of the most common attacks on companies this size. After each run, gross pay and remittances are tied back to the register during the close, which is a detective control rather than a preventive one, but it is a control that has actually found errors.
Controls in small companies cluster around money going out and neglect money not coming in. Credit notes, discounts and receivable write-offs are all ways for revenue to disappear without a payment ever being made, and in most companies this size any one person can issue one. The matrix puts credit notes and write-offs above a threshold you set under owner approval with a written reason code, and it puts every credit note issued in the period on the same register the owner reviews for payments. Customer banking details for incoming payments, and any change to a remittance instruction sent to a customer, are treated with the same confirmation discipline as vendor details, because redirecting an incoming payment is quieter and takes longer to notice than redirecting an outgoing one.
A control that is never tested is a paragraph in a document. Each quarter we walk a small sample end to end: pick payments from the register and trace back to the approval, the invoice, the purchase authority and the bank confirmation, then pick a vendor banking change and trace to the independent confirmation. Findings go in an exception log with an owner and a due date, and the log is reviewed at the next quarter's walkthrough rather than being filed. The walkthrough memo is short and it is written for the owner, not for an auditor. Where the answer is that a control was skipped because the person who performs it was away, that is a design finding rather than a discipline finding, and we fix it by naming a backup in the matrix.
The matrix above is deliberately built for a company where the owner is still close enough to the detail to be a real control. That stops being true somewhere between twenty five and forty people, when the owner no longer recognises the payees on the register and the review becomes a formality. At that point the control set has to shift from owner review to system enforcement: approval workflow in the accounting or AP system with thresholds and delegated authority, purchase orders for categories that need them, and a delegation of authority document that says who can commit the company to what. We flag the transition when the register review stops catching anything, and we rewrite the matrix rather than adding controls on top of a design that has been outgrown.
OutputWhat you receive
FAQAsked before signing
Most of what this matrix prevents is not an employee stealing. It is a redirected vendor payment, a duplicate payment, a banking detail change that came from a spoofed email, or an error nobody catches for eight months because the person who made it is the person who reconciles. Those happen in companies where everyone is honest.
The matrix itself is drafted from a walkthrough of your existing cycles in the first weeks and agreed in one session. The banking changes, dual release, payee restrictions and alerts usually take longer, because they depend on your bank's process rather than ours. Testing starts the quarter after the design is agreed.
Then we lean harder on the detective controls: the payment register review, the new payee flag, alerts on payments above a threshold, and a tighter reconciliation cadence than monthly on the account that moves the most money. We also document that the preventive control is unavailable, so the gap is a known and accepted one rather than an unnoticed one.
It gives both of them something specific to look at, which is usually what they are asking for. It is not an assurance engagement and it does not substitute for one. If your lender has a defined control requirement in the credit agreement, bring us the wording and we will map the matrix against it and tell you plainly where it does not reach.
NextThe other engagements
04 Finance systems
How we select and sequence a finance stack: ledger, AP, payroll, expense, reporting, with cutover at a period boundary and a parallel run first.
What this covers
05 Fractional finance lead
What a fractional finance lead does in the first ninety days: diagnostic, cash discipline, a close that holds, and a finance calendar for the year ahead.
What this covers
06 Close remediation
Taking over a month-end that has stopped working: triage first, then the suspense and reconciliation backlog, a restatement decision, one clean period.
What this covers
Bring the last three periods and whoever currently touches the ledger. An hour is enough to tell you whether this engagement is the right one and what it would take to run it.