Controlling financial information.
WHO NEEDS ACCESS
You Your accountant Anyone who records transactions
WHO DOES NOT
Everyone else.
WHAT TO LIMIT
Who can see bank details Who can authorise payments Who can export data Who can change past records
THAT LAST ONE
Past periods should not be editable once closed.
WHAT TO SET UP
Individual accounts, not shared logins Appropriate permissions Two-factor authentication on financial systems
WHAT TO MONITOR
Who accessed what, where the system reports it.
FOR SEPARATION OF DUTIES
Where practical, the person who records payments is not the person who authorises them.
For a very small business that may not be possible.
Apply it where amounts justify it.
WHEN SOMEONE LEAVES
Remove access immediately Change shared credentials Review what they could access
WHAT TO REVIEW
Access quarterly.