Introduction
Financial fraud does well when companies do not have clear policies on how employees may put in a request, who may review it, who has the go ahead to approve it and who is in charge of processing financial transactions. A robust authorization and approval process puts in place a structure which is defined in terms of what each employee’s responsibility is and which puts forward that no transaction may pass until it has the right amount of watchful eye. This is very much the case for expenses, invoices, payments, and fund transfers which in turn affect a company’s cash and financial records. We see that companies should put in writing their authorization procedures for expenses which detail which employees may sign off on spending, what support material is required and at what point do we see a need for more approval. When these polices are used as they are meant to be, management is able to cut back on unauthorized spending, to identify at large issues sooner, to improve accountability and to put in place a solid audit trail which in turn supports financial reporting and compliance.
Which party set off the transaction? Does the transaction pass all checks? Has the right person given it a go? Does the amount in question fit within what is approved for that employee? Do we have all the support docs? Has the transaction been run through for duplication, errors, conflicts of interest, or out of the ordinary issues? Also a well put together process will see to it that one employee doesn’t run the gamut of a transaction from start to finish. By separating out responsibilities it is made much harder for an individual to put forward a false transaction, get it approved, process the payment, and then cover it up in the accounting records.
Authorization and Approval Workflow
Authorization and in fact approval are similar concepts but are not always the same thing. What is the case of authorization is that it is what gives some one the formal right to go through with a transaction or do a financial transaction. As for approval that is more of a check off that a certain transaction has met all of the organizations’ policies. For instance a department manager may have the authority to go ahead with expenses up to a certain value, at which point the finance team steps in to check that the expense reports have the right support and is put into the proper accounting category. By which time a payment may go through many stages before it is out the door. The employee puts in the request, the relevant manager looks at the business need behind the request, finance looks at the back up and the accounting issues and only once all that is in order does the payment person go ahead and make the payment. Out of this process what we do see is that by defining each stage we remove a lot of the confusion that may arise and also it is much easier to determine responsibility when something does go wrong.
The first step in the workflow should be to identify which major financial activities require authorization. This may include employee expenses, procurement requests, purchase orders, supplier invoices, payroll adjustments, bank transfers, reimbursements, credit card transactions, refunds, journal entries, and capital expenditures. We should have a documented process for each transaction type which details what actions take place from start of the process through to final record. Also we must avoid putting in very complex procedures which may cause employees to go around the controls, when the process is either hard to follow or takes a long time. At the same time the process must be strong enough to stop inappropriate transactions from going through. We are trying to create a workflow that is practical, transparent and in proportion to the financial risk we are trying to manage. Higher risk or high value transactions should of course get more scrutiny than routine low value transactions.
Designing an Authorization Matrix
An authorization matrix is a very useful tool for which we put in place financial accountability as it clearly ties together transaction types and dollar amounts with which parties are to give their ok. The matrix also which organizations put in place should identify the post or role which is authorized to go ahead with each type of transaction and the max amount that person may go ahead to approve. For ex a company may have a department head approve of routine expenses up to 1,001 to $10,000 and a senior exec for larger transactions. The actual numbers to put in should be determined by the size of the organization, risk profile, financial resources, and regulatory environment which we are in as opposed to what other orgs may be doing. Also the matrix should put out which in fact does have authority to delegate approval, what is the what is the situation which will see that delegation take place, what is the duration of that delegation and who is to document any temporary changes.
In the creation of the matrix we see that organizations should break out different transaction types which are not to say that they should only look at dollars. A large payment may in fact present little risk if it is from a new supplier, related party, includes sensitive info, or is an atypical transaction. Also a regular operating expense may have low risk despite being for a large sum. The matrix should thus look at things like transaction value, type of spend, budget allocation, supplier standing, contract details, and also what conflicts of interest may be present. Also it should put forward which transactions require multiple approvals. For example we may see that wire transfers over a certain amount require dual approval, and payments to related parties may require extra management or board level review. This risk based approach we see to be more effective than a single size fits all approval structure.
Setting Appropriate Approval Thresholds
Approval levels which determine at what point a transaction is approved at one level in the organization and at what point it is passed to a higher level. They should be practical and well documented. If the threshold is too great employees may have too great a degree of control over the company’s money which in turn increases the issue of fraud or error. If the threshold is too low senior management may be flooded with routine approvals which cause delays and in turn employees may find way around the system. A balanced approach usually puts routine low risk transactions in the hands of operational managers and saves the large, out of the ordinary, sensitive or strategic transactions for higher level approval. Also thresholds should be reviewed at regular intervals as the size of the organization, spending trends, staff structure and financial risk may change over time.
Organizations must pay attention to efforts which try to get around approval thresholds by dividing up transactions into smaller amounts. For instance an employee must not have ability to break a 5,000 items just in order to keep under a manager’s approval amount. As a result the system should have features which identify series of related transactions, repeat orders from the also suppliers, and those that present within a brief time frame. Also we see that in which case may be appropriate to have cumulative spending include in the approval thresholds as well as single invoices. Also it is for the finance teams to put in place account and report tools that will recognize out of the ordinary trends and look at transactions that look like they are being broken up on purpose in an effort to get by higher level authorization. This mix of clear limit documentation and monitoring help to make sure the approval thresholds are used as real controls and do not become a point of which to get around the system.
Establishing Authorization Procedures for Expenses
Expense authorization should go in before an employee spends of company funds when practical does. Employees should know what expenses are allowed, which are to have prior approval, what records must be kept, and the turnaround for putting in claims. Also a robust expense system may see a staff member put in a request which details the business reason for the expense, the estimated amount, date, cost center and support info before they make a large purchase. Then the responsible manager looks at whether the expense is a must, is reasonable, in budget, and in line with what the company policy says. After the expense is made the employee presents receipts or as required docs which then is checked over by finance before payment or recording. This also puts in many points of which improper spending can be caught at instead of only looking into it once the money has gone out.
Expense policies also include high risk areas which should be addressed — travel, entertainment, cash advances, company credit cards, mileage claims, and those involving staff or related parties. We should define which expenses are off limits, which require extra approval, and what the policy is for missing documentation. Managers may not always approve what their team members submit, especially when the issue is personal benefit to the employee or a conflict of interest. Also employees should not be in charge of approving their own expenses. When possible the approver should have in depth knowledge of the business which the expense relates to in order to determine its legitimacy. Consistent documentation and independent review creates a record which internal auditors, external auditors, regulators, or management may look at.
Creating a Secure Invoice Approval Process
Invoices present another key area for fraud prevention which includes issues of fake suppliers, duplicate invoices, inflated charges, and unauthorized purchases which in turn cause large scale financial losses. An effective invoice process begins with verification that the order for goods or services was in fact put in and received. As per the company’s purchase procedure finance may compare the vendor invoice with a signed purchase order and receipt documentation. This is what is known as a three way match which in turn helps to bring to light any issues before payment is made. The invoice then goes to the proper person for approval which is determined by the authorization matrix. The approver is to check that the purchase was in fact legitimate, the amount is right, that the products or services were received and also that the expense is that of the organization and not an individual employee.
Invoice also shall include controls on supplier info. We do not accept changes to a supplier’s bank account based only an email or message for new payment details. Also that which is sensitive related to suppliers should be independently verified using the trusted contact info which we have in our record. Also which employees are to approve invoices should be aware of duplicate invoice numbers, atypical pricing, unknown suppliers, urgent payment requests, and inconsistency between the invoice and purchase docs. Once an invoice is approved and paid it the system should put in a prevention that that same invoice will not be processed again. These controls reduce risk of both intentional fraud and honest admin errors also they make sure that what is recorded in the company’s accounts payable is in fact real obligations.

Establishing Controls for Fund Transfers
Fund transfers need in place very strong authorization measures which are due to the fact that money may very well move very fast and by the time you realize it’s in a fraudulent account may be very hard to get back. We recommend that companies identify which employees will put out the requests for transfer, which will give the OK’s and which will see that the transaction through. Where possible these roles should be played by different people. For example one staff may put in a payment request, another do the check of the support documentation and receiver info, and an authorized banking officer may go ahead and release the transaction. For large value transfers we recommend that there be extra layers of approval and that where appropriate a 2 out of 3 approvals be required. Also within the bank transfer protocols we also see the need to include emergency payment procedures which in no way should be used as a reason to go around normal control processes.
A sound payment process has in place the elements of support which include explanation for the payment and the recipient. For supplier payments this may consist of a signed invoice, purchase order, contract, and proof of delivery. For internal account transfers documentation should detail the transaction and the account it is going to. We maintain very tight control over online banking info, approval tools, payment devices and access privileges. Employees must not share credentials when another is required to do a transaction. Also we recommend that management review regularly bank agreements and remove former employee’s access as soon as they leave or change role. Thus we reduce the chance that former employees, unauthorized staff, or hacked accounts will carry out or approve of the payments.
Separating Duties within the Workflow
Segregating duties is a must as authorization controls break down when an individual has too much of a role in a transaction. What we aim for is to have the functions of initiating, approving, processing, recording, and reconciling a transaction performed by different people. For instance, the person who adds a new supplier to the account system should not also be the one to approve that supplier’s invoices and cut checks to it. Also it is not a good idea for the person doing the bank reconciliation to be the same which has full access to do bank transfers. By separating out these roles you create independent cross checks which in turn increase the chance that errors and fraud will be caught before they do large damage.
Small companies do not always have the head count to fully separate duties within each process. In that which they don’t have the staff, management should put in place compensating controls which is better than to do away with the principle all together. A business owner or senior exec should do independent reviews of bank statements, supplier lists, payment reports, expense claims, and reconciliations. Also regular review of exception reports to identify out of the ordinary transactions, manual payments, changes to supplier info, or transactions which go outside normal procedures. What we should see is that the person who carries out a financial transaction is not the same person which reviews if that transaction was in fact legitimate. Even in a very small company which may be resource constrained they can put in place meaningful oversight when they structure responsibilities in a deliberate independent review which is applied consistently.
Documenting the Approval Process
A workflow does only work if employees buy into how it is supposed to function and management can prove out that the required controls were put in play. Also it is up to each organization to put in place their authorization policies, process guides, approval matrices, and relevant accounting system rules. They should identify which employees have what approval authority, what the parameters of that authority are, what support documents are required, what the processes are for escalations, what is off limits for that employee, and we also see what procedures are in place for exceptions. Support documentation for the approval should be maintained in a form that traces back to the original transaction. Per the organization’s systems this may include electronic approvals, workflow reports, signed off forms, purchase orders, invoices, receipts, or any other supporting documentation. The aim is to create a clear audit trail which shows what was approved, by whom, when and what the basis was for that approval.
Documentation should also include changes to authorization rights. Upon promotion, transfer, extended leave, or out of the organization go an employee’s approval authority should be reviewed and updated right away. Temporary authorizations should have set start and end dates which should not be open ended. We should maintain a current authorization register which finance employees may use at any given time. We should do periodic reviews which bring to light out dated permissions, in active users, duplicate approval rights, or employees which have changed responsibilities. This is very true in electronic systems which may have access which remains active past an employee’s role change. Keeping authorization records up to date prevents transactions from being approved by which do not have the appropriate authority.
Using Technology to Strengthen Approval Workflows
Technology when used well can speed up and standardize authorization processes as well as improve their visibility. In accounting and enterprise systems we see transactions routed to the right approver by transaction type, division, cost center, or amount. Also we have automated controls which put a stop to employees’ self-approval, which in turn will also reject out of the question any transaction which has hit a certain approval threshold and at the same time require a 2nd approval in case of certain risks. We also see that electronic workflows put in place which generates time stamps of when each transaction was looked at and approved which in turn identifies which employee handled what. Also these features which replace the use of informal emails and paper docs and get rid of manual tracking at the same time make it much easier for the finance teams to see what is still out for approval and also to notice anything out of the ordinary.
However technology should play a supportive role in terms of sound control structure which in no way should it replace management judgment. An automated workflow may still put out weak results if approval limits are set wrong, employees are given too great access, or management doesn’t review exceptions. Also it is put forth that access rights should follow the principle of least privilege which means that employees should be given only the system privileges which are related to their roles. Also organizations should test approval workflows at regular intervals to determine that transactions are going where they are supposed to and that unauthorized users are not getting around controls. Also it is put that System generated reports should be looked over for atypical approval trends, repeated overrides, transactions approved out of the normal business processes and other exceptions. What we see is that by use of tech in association with strong policies, segregation of duties, and human oversight we create a much more reliable financial control environment.
Monitoring, Reviewing, and Improving the Workflow
Authorization schemes are a living document which must be reviewed once in to time. Systems which collect and report performance of work flow, and which also track staff compliance are very useful. Management can analyze approval variances, out of line charges, late approvals, atypical spending, repeat submissions, changes to supplier info, and also look into very large close to threshold spend items. Also internal audit or some other independent review unit can determine that supporting documents exist and that the right people were involved in the approval process. Once an issue is brought to light management should look into the root of the problem instead of just fixing the error. Repeated issues may be due to the fact that staff do not know the rules, we have built in too many steps in the process, our go off point for approvals is off, or there is a defect in our system settings.
Organizations should go ahead and revise their authorization matrix and approval processes when we see large scale business changes take place. Expansion into new markets, management turn over, new banking relationships, acquisitions, regulatory changes, or large scale changes in spend we that’s where we see new risks appear. We also see the need for training of staff when we have large scale changes to financial procedures and managers should present approving a transaction as a responsibility which is serious in nature and not a routine matter. Also we see that a strong control culture which encourages employees to question out of the ordinary requests and report what they suspect to be irregularities instead of just going ahead and processing what may appear to be an urgent transaction. Also key is that we put in place regular monitoring which improves the formal workflow and also the overall attitude of the organization towards financial responsibility.
Conclusion
An effective authorization and outlay process which in turn puts in place a structure against unauthorized transactions, financial fraud, errors and poor accountability. We see at the base a clear authorization matrix which details what levels of approval different transactions require and what the proper monetary thresholds are. Also we see that organizations put in place specific procedures for expenses, invoices, purchases and fund transfer which in which it is made sure that transactions are supported by the right documentation and that they are looked over by the proper authorities. We have segregation of duties which is to say that one person does not control the full financial process; also we have compensating controls which put in extra oversight when staff is limited which full separation is not possible. Tech can do the job of automation, enforce approval limits and maintain audit trails but it has to back up good policies and also be a part of a regular review.
The best approval systems may not be the most complex ones; rather they are the systems that employees buy into, managers which they which to live by, and finance teams which can monitor easily. We recommend that organizations frequently review approval levels, authority of which to sign off, system access, transaction exceptions, and what constitutes proof of approval to see that as the business changes out so do our controls. Also when authorization is very much a known quantity, approvals are separate processes, documentation is a strong point, and financial movement is watched closely organizations put up a large barrier to unauthorized transactions. Also at root they instill a culture which is that of responsible use of company funds and that every large scale financial decision can be traced back to a responsible party. Thus what we are saying is that authorization and approval processes are a key element of a larger internal control and fraud prevention system.
Get more well researched information about Authorization and approval workflow here.



