Separate payment approval from execution: Invoice approval determines if an invoice follows organisational rules; Payment approval must occur after payment creation, before execution; One person can raise and pay only if another approves, with compensating controls
Image: Business Automation Desk

Human Oversight

Part of Finance process automation

Separating payment execution from approval

Invoice approval confirms that a transaction may proceed under the organisation's rules.

Invoice approval decides whether an invoice may proceed under the organisation’s rules; payment execution sends the money. Keep invoice approval, payment-release authorisation and execution as separate decisions, with permissions that prevent one person controlling the transaction end to end.

Assign supplier-record maintenance, invoice entry, invoice approval, payment approval or release, and bank reconciliation to different people where possible. The invoice approver decides whether the invoice is authorised; a payment approver authorises release after payment creation; a payment releaser executes the approved payment.

If a small team cannot fully separate duties, one person may raise and pay an invoice only if someone else approves it. Add a compensating control that is performed and evidenced, such as a second review above a threshold, after-the-fact spot checks, or dual authorisation on the payment run; document any exception.

Place a payment approval control after payment creation and before execution. Route payments by amount thresholds or funding account rules, and use one, two or three approval levels as required; delegation, foreign exchange approval and re-authentication for sensitive actions can also sit at this stage. Approval moves a payment past the governed hold point; it does not itself send the money.

Review a supplier’s bank-detail change separately from, and before, the next payment to that supplier. Verify the approved amount, payee and account through the organisation’s authorised process, and use dual authorisation on the bank payment run where appropriate. A purchase-order or product-receipt match can support amount and quantity checks, but it does not validate a changed bank account.

Test a changed-bank-detail scenario in a safe environment and record who saw the change and what stopped unauthorised release. After payment, have reconciliation independently compare the executed batch with approved items.

Best Practice Metrics for Payment Controls

Segregation of Duties Implemented
Recommended for all organisations
Supplier Bank Detail Verification
Mandatory before first payment post-change
Reconciliation Frequency
At least weekly for high-volume processes

More from Human Oversight