This article is for owners, directors and boards of businesses that have grown past the point where one person sees every payment and knows every customer. The point varies with complexity, and for a business with several entities or locations it can arrive well before $10 million in turnover. It covers which internal controls to add as the business scales, why each one matters, and the order in which to put them in place so the work is manageable.
The control that worked was you
In a business of ten people, the owner approving every payment is a control, and a good one. They know the suppliers, they recognise an unusual invoice, and they notice when a regular customer has not paid. Nothing is written down because nothing needs to be.
That control stops working when the volume outgrows one person's attention. Approving two hundred payments a week becomes a click through a list. The owner stops recognising every supplier because there are now three hundred of them. The finance team grows from one bookkeeper who has been there for years to three people, one of whom started last month. Each of those changes is a sign of a business doing well, and each one removes a check that used to happen without anyone designing it.
Separate the person who approves from the person who pays
The first control to formalise is the division between approving a payment and making it. The person who enters a supplier invoice should not be the person who releases payment from the bank, and the bank portal should require a second authoriser above a set amount.
The step that protects against fraud aimed at growing businesses is a rule for supplier bank details. Business email compromise works by sending an invoice or an email that appears to come from a real supplier, with new bank details. The Australian Cyber Security Centre's small business cyber security handbook recommends verifying payment requests through a trusted channel, such as calling the sender on a number you already hold. Applied as a standing rule, every change to a supplier's bank details is confirmed by phone on a known number before the change is saved, and the confirmation is recorded.
In a small finance team full separation may not be possible. Where one person has to do both, a monthly review of all payments and all changes to supplier details by someone outside the team covers most of the gap.
Write down who can approve what
A delegation of authority sets out, by role, how much each person can approve and for what. A department manager might approve operating expenses up to $5,000, the finance manager up to $25,000 and anything above that goes to a director. Capital expenditure, new contracts, pay changes and hiring decisions each get their own limits.
The document does two things. It lets decisions be made without everything routing through the owner, which matters more as the business grows. It also gives the auditor, the bank and any future investor a clear answer to the question of who can commit the business, which they will ask.
One page is enough to start with. It is worth reviewing whenever someone changes role, because a delegation that names a person who has left is a gap in its own right.
Make the month-end close a process with an owner
In a smaller business the books are finished when they are finished. Once there are several entities, a payroll of fifty and inventory in more than one location, the close needs a timetable, a checklist and a named person responsible for each step.
The checklist covers bank and credit card reconciliations, the payroll and super reconciliation, accruals for supplier bills not yet received, stock movements and intercompany balances. Each reconciliation is prepared by one person and reviewed by another, and the reviewer signs off. A close completed within ten working days gives management numbers while they can still act on them.
Control who can change the systems
Accounting, payroll and banking software all allow permissions to be set by role. Permissions accumulate as people join and change roles, because giving someone access is quicker than working out exactly what they need. The result can be several people able to change payroll rates or supplier bank details, including people whose job does not require it.
A permissions review twice a year, and a checklist that removes access on the day someone leaves, keeps this in hand. Payroll and supplier master data deserve the closest attention, because a change in either moves money.
Reporting a board can act on
As a business brings in outside directors, an investor or a lender with covenants, the monthly report becomes a governance document. It needs the profit and loss, the balance sheet and the cash position, the key numbers against budget, and a short commentary that explains the variances and flags anything the board needs to decide.
A board pack of six to eight pages, delivered at the same point each month, does more for governance than a longer report that arrives late. Our article on reading a profit and loss statement covers the figures that belong at the front of it.
The order to put internal controls in place
Start with payments and supplier bank details, because that is where the money moves and where fraud is aimed. Then write the delegation of authority, which takes a day and removes a large share of the bottleneck around the owner. The month-end close follows, then systems permissions, then the board pack. The first two can be in place within a month and the full set within a quarter, which spreads the work across normal operations without a separate project.
Questions we are asked
What are internal controls?
Internal controls are the rules and checks a business uses to make sure payments are approved, records are accurate and assets are protected. Examples include dual authorisation of payments, a delegation of authority and reconciliations reviewed by a second person.
When does a growing business need formal internal controls?
When the owner can no longer see every payment or know every supplier. Complexity is a better guide than size: several entities, locations or a growing finance team all bring the point forward.
How does segregation of duties work in a small finance team?
Split the steps of entering, approving and paying across different people where you can. Where one person has to do more than one step, a monthly review of payments and supplier changes by someone outside the team fills the gap.
How do we protect the business against invoice fraud?
Confirm every change to a supplier's bank details by calling the supplier on a number you already hold, before the change is made, and record the call. Use multi-factor authentication on email and banking.
What should a delegation of authority include?
Approval limits by role for operating expenses, capital expenditure, contracts, pay changes and hiring, and who approves anything above each limit.
Building the controls with you
If your business has outgrown the controls that worked when it was smaller, our Finance Hub and growth advisory teams can work out which internal controls to add first and help put them in place. Book a time with us.






