eProcureAI / Platform / For controllers

Role

Controls that ran
whether or not anyone looked

The question a controller has to answer is not whether the control exists. It is whether it applied to every transaction, including during the quarter when everybody was busy.

Structural rather than procedural. Which is the difference that matters at review time.

Control postureThe question asked
The situation

A control that depends on memory is not a control

Every finance function can describe its procurement controls. Far fewer can demonstrate that those controls applied to every transaction rather than to most of them.

The gap usually opens quietly. Somebody covers a colleague during leave and the delegation arrangement hands them both request and approve rights for a fortnight. A supplier is urgently needed so due diligence is completed afterwards. A threshold is bypassed verbally because the committee does not meet until next month.

None of these are malicious. All of them are exactly what a reviewer is looking for, and all of them are invisible until somebody goes looking.

The difference between written and enforced

A control written in a policy applies when people remember it. A control enforced by the system applies every time, including in a busy December and including through a delegation chain.

That distinction is the whole argument for moving controls into software. It is not that people are careless, it is that consistency across thousands of transactions is not something humans are good at and software is.

Evidence should be a search

When every approval carries who decided, when and why, and every override is recorded as an override, producing evidence becomes a filter and an export. The alternative, which most controllers know well, is a fortnight of asking people to forward emails.

What a reviewer tests

Five questions, and they rarely change

Question 1

Did the control apply universally

Not to a sample. Exceptions nobody can explain are worse than having no sample at all.

AnswerEvery transaction
1
Question 2

Could one person complete a cycle

Request, approve and pay, including through any delegation arrangement.

AnswerStructurally prevented
2
Question 3

Are exceptions visible as exceptions

Or do they blend into normal activity where nobody would find them.

AnswerReportable separately
3
Question 4

Is there a reason on every override

Written at the time by the person who decided, rather than supplied afterwards.

AnswerRequired at the time
4
Question 5

Can you produce evidence quickly

Which is partly a test of the control and partly a test of the system holding it.

AnswerFilter and export
5
What changes

Three controls that stop depending on people

Separation of duties, including delegation

Blocking the combination in normal operation is easy. Blocking it when somebody is covering annual leave is the part most implementations miss, and the part reviewers find.

  • Request, approve and pay cannot combine
  • Delegation cannot create the combination
  • Applies during cover and leave arrangements
  • Attempts are logged rather than silently refused
Control checkLive
Request and approveBlocked
Approve and payBlocked
Via delegationAlso blocked
Applies in DecemberYes
StructuralNot procedural

Overrides recorded as overrides

An exception absorbed into normal activity is an exception you cannot review. Recording them separately means your review population is a short list rather than everything.

  • Exception routing rather than silent approval
  • Reason written at the time of decision
  • Reportable separately from routine activity
  • Trend visible if exceptions become common
Override reportLive
RecordedEvery one
ApproverNamed
ReasonAt the time
Review scopeExceptions only
A short listRather than everything

Evidence produced by filter

Population, sample, documents. All three available in minutes rather than assembled over a fortnight from inboxes and shared drives.

  • Filterable population of transactions
  • Sample exported with documents attached
  • Approver, date and reason on each decision
  • Access matrix exportable for review
Evidence requestLive
PopulationFilterable
SampleExportable
DocumentsAttached
TimeMinutes
A searchNot a collection exercise
The control set

Five controls and how each is enforced

The distinction that matters is whether the control runs by itself or whether somebody has to remember it.

ControlEnforced howWhat it prevents
Separation of dutiesSystem blocks the combination, including via delegationOne person completing a full cycle
Approval thresholdsRules match on department and amount before notificationPurchases approved below the correct level
Budget checksCharge code balance checked at submissionCommitments against money that is not there
Three way matchOrder, receipt and invoice compared before paymentPaying for goods that never arrived
Banking verificationChange verified before payment can releaseThe most common accounts payable fraud route

None of these require anybody to consult a policy document, which is why they still work in a quarter when everybody is under pressure.

Where controls usually fail

Six gaps, and most involve cover

Delegation

Both roles, one person

Cover arrangements combining request and approve. The most common structural gap and the easiest to close.

ClosedThrough delegation too
Leavers

Access outliving the role

Permissions carried from a previous position because access followed the person rather than the department.

RemovedOn role change
Splitting

Purchases under a threshold

Several orders staying just below a limit, visible when you look for repeat patterns from one requester.

FlaggedBy pattern
Verbal exceptions

Approved outside the system

The purchase happens and the record does not, which is the hardest kind to find afterwards.

PreventedException routing
Retrospective diligence

Completed after engagement

A supplier used before checks finished, closed by gating orders on completion.

GatedBefore ordering
Expired documents

Cover lapsing quietly

Insurance and certifications tracked to a date rather than checked once at onboarding.

TrackedTo the date
Who does what

The short version of your role

Consistency across thousands of transactions is a software problem, and treating it as a training problem is why gaps appear.

What you do

Design the controls, review the exceptions, and answer the reviewer. Not police every transaction.

The human partLive
Design the control setOnce, then refine
Review exceptionsA short list
Answer the reviewerFrom an export
Investigate patternsWhere they appear
ExceptionsNot everything

What eProcureAI does

Applies every control to every transaction, and keeps the evidence in a reviewable shape.

The automatic partLive
Enforce separationIncluding delegation
Apply thresholdsConsistently
Check budgetsBefore approval
Log every overrideWith a reason
Hold the evidenceWith the transaction
Every transactionIncluding in December
0controls applied rather than sampled
0separation of duties enforced through cover arrangements
0carrying an approver, a reason and a date
0to produce a sample with documents attached
FAQ

Questions people actually ask

How is separation of duties actually enforced?
The system blocks the combination of request, approve and pay for the same person, and no delegation arrangement can create it. That second part is where most implementations have a gap and where reviewers tend to look.
What happens to genuine exceptions?
They are routed rather than silently approved, and each carries an approver, a reason written at the time, and a date. Overrides are reportable separately, so your review population is a short list.
How quickly can we produce audit evidence?
Minutes. Filter the population, export the sample, and the supporting documents are attached to each transaction rather than stored somewhere else.
Can we prove who had which permissions during a period?
Yes. Permissions are held by department with changes recorded, and the matrix exports with the source of every grant.
How are threshold splitting patterns detected?
Repeat purchases from the same requester staying just below a limit are visible as a pattern. When it appears regularly it usually means the threshold sits below how people actually buy.
What about controls during annual leave?
This is the case worth testing. Delegation is scoped and time boxed, both names stay on the record, and the delegate cannot acquire a combination of rights that would breach separation of duties.
Does this cover banking detail changes?
Yes. Changes require verification before any payment can be released, with a second person involved, because it is the most common fraud route into accounts payable.
Will this satisfy our external auditors?
That is their judgement rather than ours. What we can say is that the evidence they usually ask for exists as a by product of transactions rather than needing to be assembled, which is normally the sticking point.

Bring your control matrix

We will map it onto the system and show which controls become structural rather than procedural.

Book your free demo

Related: All solutions and Access and Permissions