Preventing loss.
WHAT CONTROLS SYSTEMS SHOULD ENFORCE
Separation between initiating and approving Approval thresholds by amount Restrictions on who may create suppliers and customers Restrictions on who may change bank details Audit trails on everything
WHY SEPARATION MATTERS MOST
It prevents a single person completing a fraudulent transaction alone.
WHAT SUPPLIER CREATION CONTROLS PREVENT
Fictitious suppliers receiving payment.
WHAT TO REQUIRE
Verification, by someone other than the requester.
WHAT BANK DETAIL CHANGES REQUIRE
Confirmation through a known channel, not the one requesting the change.
WHY
Diverted payment fraud depends on that omission.
WHAT TO REVIEW REGULARLY
New suppliers created Bank details changed Credit notes issued Manual journal entries Payments outside normal patterns
WHY MANUAL JOURNALS SPECIFICALLY
They can move amounts without a transaction, and are a common concealment route.
WHAT TO RESTRICT
Who may post them, and require approval.
WHAT ACCESS REVIEW SHOULD ESTABLISH
That permissions match current roles That departed staff have none
WHAT TO RUN
That review, periodically and after any departure.
WHAT TO ENSURE ABOUT AUDIT TRAILS
That they cannot be altered by those they record.