Who should be allowed to release money from your bank account
The control that matters most in a small business costs nothing and takes about ten minutes to put in place. It is simply this: the person who prepares the payment should not be the person who releases it.
- Preparing a payment and authorising it are two jobs, and one person should not hold both
- The bookkeeper builds the batch and uploads the file; the owner keeps the banking authorisation
- Trust is not a control, and treating it as one is what makes fraud possible rather than likely
- A control protects the person doing the work as much as it protects the business
- If you cannot say who authorised a payment, you do not have a control
The one division that matters most
Most small business financial controls can be reduced to a single question: who can move money out of the bank account?
The answer should never be the same person who decides what gets paid. Preparing a payment run and authorising it are two different jobs. Separated, an error has to get past two people to become a payment. Combined, nothing stands between an intention and a transfer.
That is separation of duties. It sounds like a phrase from a large organisation's policy manual, and in a business of four people it comes down to who logs into the bank.
What that looks like in practice
The arrangement that works, and it works at almost any size:
- The bookkeeper prepares the batch. Bills are entered, approved, matched to the right supplier and scheduled. The payment file is generated from that.
- The bookkeeper uploads the file to the bank. This is data entry, not authorisation. The payment does not move.
- The owner, or a director, authorises the release. They see the total, the count and the payees before anything leaves.
The critical detail is that the banking authorisation stays with the owner, and it stays there even when it is inconvenient. Handing over the authorisation because approving payments is tedious is the moment the control stops existing, and it is almost always done for convenience rather than for any considered reason.
If your bank supports dual authorisation, use it. Two named people, one to prepare and one to approve, is the control written into the bank rather than into a habit that erodes.
"I trust my bookkeeper"
Almost everyone says this, and in almost every case it is true.
It is also not a control. Trust is a judgement about a person. A control is a property of a system. The two are not substitutes, and the difference shows up precisely when your judgement about a person turns out to have been wrong, which is the one circumstance in which you needed the control.
There is a second argument that lands harder with people who find the first one uncomfortable. A control protects the person doing the work. If a bookkeeper is the only one who can move money, then every discrepancy, every unexplained transaction and every awkward question is theirs to answer alone. Separation means they can demonstrate what they did. Good bookkeepers tend to want this, and a reluctance to have any second pair of eyes is itself worth noticing.
It is also worth saying plainly: the businesses this goes wrong in are not careless ones. They are usually businesses where somebody was trusted, capably, for years.
The questions worth asking yourself
None of these needs an accountant to answer.
- Who can initiate a payment from your business bank account, right now, without anyone else's involvement? If the answer includes anyone other than you, that is the control question.
- When did you last look at a payment run before it went out? Not the bank balance afterwards. The list of payees before.
- Could you produce, today, a record of who authorised a specific payment six months ago? If not, you do not have an audit trail, you have a memory.
- Does anyone other than you have access to the bank token, card or authentication device? Shared credentials mean no payment can be attributed to a person.
- Who reconciles the account, and is it the same person who pays from it? Preparing, paying and reconciling is all three jobs in one pair of hands.
- Does more than one person ever see the bank statement? Not the accounting file. The statement from the bank.
That last one matters more than it sounds. A file can be made to look like anything. The bank statement comes from outside the business and is the one document nobody inside it can edit.
What the software will not do for you
Accounting software has approval workflows and user permissions, and they are worth setting up properly.
They also stop precisely at the edge of the accounting file. Xero can require a second person to approve a bill. It cannot stop a payment that never went through the file at all, and it does not control your internet banking. The most common gap we see is a business with careful bill approval rules inside Xero and a single shared bank login sitting outside it.
Neither will any amount of automation, or of asking an assistant, tell you whether the arrangement in your business is sound, because the answer depends on who holds what, and that is not in any file.
If any of this is uncomfortable to read
That is usually a reasonable signal rather than an unreasonable worry. Setting the arrangement up properly is a conversation rather than a project, and it is a great deal cheaper than the alternative: our forensic accounting case study is what it looks like when nobody asked these questions for long enough.
Book a Call Today and we will talk it through.
Related plain-English guidance
When your BAS is due, and what to check before it is
The due date is the easy part to look up and the wrong thing to worry about. What decides whether a BAS is right is...
What JetConvert does, and what it hands back to you
A conversion tool moves your data into Xero and it does that job well. What it does not do is build the file around...




