eProcureAI / Platform / For controllers
RoleThe question a controller has to answer is not whether the control exists. It is whether it applied to every transaction, including during the quarter when everybody was busy.
Structural rather than procedural. Which is the difference that matters at review time.
Every finance function can describe its procurement controls. Far fewer can demonstrate that those controls applied to every transaction rather than to most of them.
The gap usually opens quietly. Somebody covers a colleague during leave and the delegation arrangement hands them both request and approve rights for a fortnight. A supplier is urgently needed so due diligence is completed afterwards. A threshold is bypassed verbally because the committee does not meet until next month.
None of these are malicious. All of them are exactly what a reviewer is looking for, and all of them are invisible until somebody goes looking.
A control written in a policy applies when people remember it. A control enforced by the system applies every time, including in a busy December and including through a delegation chain.
That distinction is the whole argument for moving controls into software. It is not that people are careless, it is that consistency across thousands of transactions is not something humans are good at and software is.
When every approval carries who decided, when and why, and every override is recorded as an override, producing evidence becomes a filter and an export. The alternative, which most controllers know well, is a fortnight of asking people to forward emails.
Not to a sample. Exceptions nobody can explain are worse than having no sample at all.
Request, approve and pay, including through any delegation arrangement.
Or do they blend into normal activity where nobody would find them.
Written at the time by the person who decided, rather than supplied afterwards.
Which is partly a test of the control and partly a test of the system holding it.
Blocking the combination in normal operation is easy. Blocking it when somebody is covering annual leave is the part most implementations miss, and the part reviewers find.
An exception absorbed into normal activity is an exception you cannot review. Recording them separately means your review population is a short list rather than everything.
Population, sample, documents. All three available in minutes rather than assembled over a fortnight from inboxes and shared drives.
The distinction that matters is whether the control runs by itself or whether somebody has to remember it.
| Control | Enforced how | What it prevents |
|---|---|---|
| Separation of duties | System blocks the combination, including via delegation | One person completing a full cycle |
| Approval thresholds | Rules match on department and amount before notification | Purchases approved below the correct level |
| Budget checks | Charge code balance checked at submission | Commitments against money that is not there |
| Three way match | Order, receipt and invoice compared before payment | Paying for goods that never arrived |
| Banking verification | Change verified before payment can release | The most common accounts payable fraud route |
None of these require anybody to consult a policy document, which is why they still work in a quarter when everybody is under pressure.
Cover arrangements combining request and approve. The most common structural gap and the easiest to close.
Permissions carried from a previous position because access followed the person rather than the department.
Several orders staying just below a limit, visible when you look for repeat patterns from one requester.
The purchase happens and the record does not, which is the hardest kind to find afterwards.
A supplier used before checks finished, closed by gating orders on completion.
Insurance and certifications tracked to a date rather than checked once at onboarding.
Consistency across thousands of transactions is a software problem, and treating it as a training problem is why gaps appear.
Design the controls, review the exceptions, and answer the reviewer. Not police every transaction.
Applies every control to every transaction, and keeps the evidence in a reviewable shape.
We will map it onto the system and show which controls become structural rather than procedural.
Book your free demoRelated: All solutions and Access and Permissions