eProcureAI / Platform / Financial services

Industry

Controls that hold
when nobody is watching

A control that depends on somebody remembering is not a control. Separation of duties, due diligence and override logging all need to run whether or not anyone is paying attention that week.

Enforced structurally. Including through delegation, which is the loophole most implementations miss.

Third party spendNew supplier proposed
The situation

The control existed. It just did not run that week.

Financial services firms rarely lack procurement controls. What they lack is confidence that the controls ran on every transaction rather than on most of them.

Separation of duties is written down. Then somebody covers a colleague during annual leave, the delegation chain quietly hands them both roles, and for two weeks one person can request and approve the same purchase. Nobody notices, because nothing tells them.

Due diligence is required before engaging a third party. Then a business unit urgently needs a supplier, an exception is granted verbally, and the diligence is completed afterwards if at all.

Structural beats procedural

A control enforced by the system runs every time, including in a busy quarter and including through a delegation. A control written in a policy runs when somebody remembers it.

That difference is the whole argument. The same person cannot request, approve and release payment, and no delegation arrangement can create that combination, because the system will not allow it rather than because a document says it should not happen.

Evidence is a by product, not a project

When every approval carries who decided, when and why, and every override is recorded as an override, producing evidence is a filter and an export. The alternative is a fortnight of asking people to forward emails and hoping they still have them.

What examiners test

Five questions, and they are always the same

Question 1

Did the control apply to every transaction

Not most. A sample showing exceptions nobody can explain is worse than no sample.

AnswerApplied by the system
1
Question 2

Could one person do the whole thing

Including through delegation, which is where most firms discover a gap.

AnswerStructurally prevented
2
Question 3

Was diligence done before engagement

Before the first payment, with the date visible, rather than completed retrospectively.

AnswerGated before ordering
3
Question 4

Are exceptions visible

Overrides recorded as overrides rather than blended into normal activity.

AnswerReportable separately
4
Question 5

Can you show me

Quickly, with documents attached, rather than after a fortnight of collection.

AnswerFilter and export
5
What changes

Three controls that stop depending on people

Separation of duties, including delegation

The combination that matters is request, approve and pay. Blocking it in normal operation is straightforward. Blocking it through a delegation chain is the part most implementations forget.

  • Request, approve and pay cannot combine
  • Delegation cannot create the combination
  • Applies during leave and cover arrangements
  • Attempted combinations are logged
Control checkLive
Request and approveBlocked
Approve and payBlocked
Through delegationAlso blocked
Depends on memoryNo
StructuralNot procedural

Due diligence gated before engagement

A supplier cannot receive an order until diligence is complete and risk has approved. The urgency conversation happens before the commitment rather than after it.

  • Onboarding form scaled to the risk tier
  • Ownership and screening captured
  • Approved by risk rather than the requester
  • No order possible until complete
Before engagementLive
DiligenceRequired first
Risk tierAssigned
Approved byRisk function
Order before completionNot possible
GatedRather than encouraged

Overrides recorded as overrides

Every exception carries an approver, a reason and a date, and is reportable on its own. A firm that cannot list its exceptions does not really know what its controls did.

  • Exception routing rather than silent approval
  • Reason written at the time
  • Reportable separately from normal activity
  • Pattern visible if exceptions become routine
Override logLive
RecordedEvery one
ApproverNamed
ReasonWritten at the time
ReportableSeparately
VisibleRather than absorbed
Third party tiers

Diligence scaled to what the supplier actually does

Applying the same onboarding to a stationery supplier and a data processor wastes effort in one place and misses risk in the other.

TierTypical supplierWhat is collectedRe-review
LowOffice consumables, no data accessStandard onboarding, tax and bankingAnnual validity
MediumFacilities, on site servicesAdds insurance and site requirementsAnnual, with document expiry tracked
HighData processors, outsourced functionsAdds ownership, screening, security reviewMore frequent, with named owner
CriticalFunctions your operation depends onAdds continuity and exit considerationsScheduled and escalated

Tiering is the difference between diligence that is proportionate and diligence people route around because it is uniformly heavy.

Where controls usually fail

Six gaps, most of them during cover

Delegation

One person, both roles

Cover arrangements quietly combining request and approve. The most common structural gap.

BlockedThrough delegation too
Urgency

Diligence done afterwards

A verbal exception that never gets closed out, discovered later by somebody else.

GatedBefore ordering
Leavers

Access that outlives the role

Permissions carried from a previous position because access followed the person.

RemovedOn department change
Thresholds

Split purchases

Several orders staying just below a limit, which is visible when you look for repeat patterns.

VisibleBy pattern
Banking

Details changed by email

The most common fraud route, closed by verifying every change before payment.

VerifiedEvery change
Expiry

Documents quietly lapsing

Insurance and certifications tracked to a date rather than checked at onboarding only.

TrackedTo the date
Who does what

The short version of everyone's job

The point of structural controls is that a busy quarter changes nothing about whether they ran.

What people do

Buy things, and answer for the exceptions. The routine controls do not need their attention.

The human partLive
Business unitRaises the request
RiskApproves new suppliers
ApproverDecides within their limit
AuditReviews exceptions, not everything
JudgementOn exceptions only

What eProcureAI does

Runs the controls on every transaction, without exception and without reminder.

The automatic partLive
Enforce separationIncluding delegation
Gate diligenceBefore engagement
Apply thresholdsConsistently
Log every overrideWith a reason
Produce evidenceBy filter
Every transactionNot a sample
0separation of duties enforced, including via delegation
0diligence completed rather than promised
0carrying an approver, a reason and a date
0to produce an evidence sample with documents
FAQ

Questions people actually ask

How is separation of duties enforced?
Structurally. The same person cannot request, approve and release payment, and no delegation arrangement can produce that combination. That last part matters, because delegation during leave is where most firms find their gap.
Can a supplier be used before due diligence is finished?
No, and that is deliberate. Orders cannot be raised against a supplier until diligence is complete and risk has approved, so the urgency conversation happens before the commitment rather than after.
How are overrides handled?
Every exception carries an approver, a reason and a date, and is reportable separately from normal activity. A firm that cannot list its exceptions does not really know what its controls did.
Does diligence have to be the same for every supplier?
No. Onboarding is scaled by tier, so a stationery supplier and a data processor are treated proportionately. Uniformly heavy diligence is what makes people route around it.
What evidence can we give an examiner?
A filterable population, an exportable sample, and documents attached to each transaction along with who approved it and why. It takes minutes rather than a fortnight.
What happens when somebody changes role?
Their access changes with their department. Old permissions are removed rather than accumulating, which is the usual source of quiet privilege creep.
How are bank detail changes controlled?
Verified before any payment can be released, with a second person involved. It is the most common fraud route into accounts payable and it is worth closing deliberately.
Does this replace our third party risk platform?
Not if you run a dedicated one. This handles onboarding, diligence gating and the purchasing controls around third parties, and works alongside a specialist platform where you have one.

Bring your control matrix to the call

We will map it onto the system and show you which controls become structural rather than procedural.

Book your free demo

Related: All solutions and Access and Permissions