Follow the money and the authority
A small business does not need to begin with a large control manual. Start by identifying where a person could redirect money, create a false record or conceal a transaction. Then ask what would prevent the action and what would reveal it if prevention failed.
High-consequence paths often include supplier bank changes, payment approval, payroll changes, refunds, inventory adjustments and administrator access. The actual priorities depend on your business. A cash retailer and a software company should not receive identical control lists merely because both are small.
The GAO's 2025 Green Book emphasizes risk assessment, preventive controls and management responsibility.1 It sets federal-agency standards; the examples here use its general control-design ideas as a reference, not as a private-business mandate.
Distinguish prevention, detection and correction
A preventive control operates before an unauthorized transaction occurs. A detective control identifies a suspicious or incorrect result. Corrective work addresses the issue and its underlying cause. A useful process often combines them.
For example, requiring independent approval for a supplier bank change can help prevent a redirected payment. Reviewing the change report can identify unauthorized changes. Investigating an exception and restoring correct access is corrective work. A monthly bank reconciliation alone may discover a problem only after money has left.
Define the control precisely: who performs it, what population it covers, when it operates, which criteria are checked and what evidence remains. “Management reviews payments” is an intention. “The owner compares the payment batch to approved invoices and supplier-change confirmations before release” is a procedure.
Original priority-control inventory
The following examples are starting proposals. Adjust them to actual roles, systems, transaction volume and legal requirements.
| Risk path | Preventive idea | Detective idea | Evidence to retain |
|---|---|---|---|
| Supplier bank change | Independent verification through an established contact | Review all bank-detail changes | Confirmation, approver and change log |
| Duplicate or fictitious invoice | Match invoice to authorized purchase and receipt | Review duplicates and unusual suppliers | Purchase, receipt and exception resolution |
| Unauthorized payroll change | Separate change preparation and approval | Compare payroll changes and totals | Approved changes and review notes |
| Inappropriate refund | Require authorization outside the requester where feasible | Review unusual refund patterns | Transaction and approval record |
| Inventory adjustment | Restrict adjustment rights and require reasons | Reconcile counts and investigate differences | Count results and approved adjustments |
| Administrator misuse | Limit privilege and approve changes | Review relevant administrator activity | Access decision and review evidence |
Do not gather more sensitive information than the review requires. Store payroll and account-detail evidence with appropriate restrictions rather than attaching it to a general task list.
Worked example: the supplier email change
Fictional scenario: An office manager receives an email that appears to come from a long-standing supplier. It requests new bank details and says a payment is urgent.
The manager records the request but does not use its new phone number as the verification channel. The designated approver contacts the supplier through a previously verified route, compares the change with the supplier record and documents the result before payment preparation.
If verification fails, the change remains blocked and the issue is escalated. If it succeeds, a separate authorized person releases the payment where staffing allows. A reviewer later checks the complete bank-change report against approved changes, including changes that did not immediately produce a payment.
FTC small-business scam guidance identifies impersonation and urgency as warning signs and recommends clear invoice and payment checks.2 The fictional workflow applies that principle without assuming every unusual request is fraud or promising that one callback defeats every attack.
Make approvals substantive
An approval should reflect a check, not simply a second login. Give the approver access to the underlying information, enough time to review it and authority to reject the transaction. Specify what needs escalation, such as an unusual supplier, changed payee or missing receipt.
Record the reasons for exceptions. If the owner must approve their own reimbursement because no alternative reviewer exists, document that conflict and an appropriate additional review. Do not label the procedure independent when the same person controls preparation, approval and reconciliation.
Avoid predictable loopholes. Splitting one purchase into smaller transactions can evade an amount threshold. Examine connected payments, unusual timing and repeat exceptions where relevant. These are proposed review considerations, not evidence that a fraud-detection system is operating.
Handle small-team limitations honestly
Sometimes full segregation of duties is impractical. Additional review can address the specific missing separation, but it should not become a blanket excuse for unchecked authority. University of Florida's institutional guidance treats compensating controls as a fallback when ideal separation is unavailable.3
A small company might give its owner direct access to bank statements and require a documented reconciliation review, while an external bookkeeper checks selected high-risk changes. The business must decide whether that arrangement is suitable; the example does not promise equivalent protection or prescribe an engagement.
Name the residual limitation. If one administrator can change records and logs, reviewing their own report may not meaningfully challenge their activity. Consider how the reviewer obtains evidence from a source the operator cannot silently alter.
Check whether controls actually operate
Select a recent, defined period and inspect a bounded set of transactions. Include ordinary transactions and the exceptions most likely to challenge the control. Ask whether approvals preceded payment, whether verification used the correct contact and whether discrepancies were resolved.
Keep the population, selection method and limitations with the result. A sample of five invoices does not establish that every invoice was appropriate. A signed policy establishes the instruction, not performance throughout the period.
When a control fails, describe the condition and business exposure before blaming a person. “Three bank changes had no documented verification” is a useful observation. “The finance team is dishonest” is an unsupported conclusion and can create serious harm.
Protect the reporting route
Provide employees a monitored route for concerns and a clear alternative if the concern involves their manager. Explain how reports are handled and protect information appropriately. Do not invite staff to conduct their own surveillance or access records outside their authorization.
For suspected misconduct, preserve relevant information and obtain appropriate legal and investigative expertise. Routine control monitoring is different from establishing wrongdoing. Avoid accusations based on an unexplained exception alone.
An achievable first-month plan
In the first week, map the highest-consequence transaction paths and actual access. In the second, agree on two or three preventive checks and the necessary review evidence. In the third, run the procedures on normal work and resolve usability problems. In the fourth, inspect a sample and revise the design based on findings.
Assign ownership for ongoing review and material changes. A new payroll supplier, bank platform or departing employee can change the control environment. The segregation-of-duties examples provide a more detailed way to map conflicts.
Questions business owners ask
Does trust make controls unnecessary?
No. Clear controls protect trusted employees as well as the organization by making expectations, approvals and evidence visible.
Should every payment need two people?
Design the process for risk, practicality and applicable requirements. The key is a reviewed rationale and safeguards that actually operate—not a universal rule copied without context.
Can software guarantee fraud prevention?
No. Access controls and records can support a process, but people must design and operate it. The readiness assessment offers a general planning starting point; it is not a fraud investigation or verification of control effectiveness.
Sources and references
-
U.S. Government Accountability Office. Standards for Internal Control in the Federal Government: 2025 Green Book (2025-05-15). Federal-agency framework, effective FY2026; voluntary reference here for private-business control design. ↩
-
Federal Trade Commission. Scams and Your Small Business: A Guide for Business. Business-scam guidance supports invoice verification and staff awareness. ↩
-
University of Florida CFO Division. Compensating Controls. Institutional control guidance illustrating alternatives when staff limitations prevent ideal separation. ↩

