Treasury Controls Shouldn't Wait for an IPO

Terece Tai, CPA, CA

8/18/20264 min read

Many companies begin thinking about internal controls when they embark on an IPO journey. That may be appropriate for Internal Controls over Financial Reporting (ICOFR), but treasury controls should not be viewed as an IPO requirement or a milestone that comes later in a company's growth plan.

Treasury controls should be established from day one because cash is often a company's most critical asset.

Most founders inherently understand the importance of tightly controlling cash disbursements. The challenge often emerges as a company grows, builds its finance team, and begins delegating banking authority to employees and managers.

When people think about treasury controls, they often focus on familiar operational controls such as dual signatures on cheques or dual-user payment processing where one employee prepares a transaction and another approves it. While these remain important, there are many more granular controls that are relevant in today's fast-paced treasury environment.

Today, I am not going to dive into those detailed controls. Nor am I going to cover technical topics such as Entity-Level Controls or IT General Controls, which public company control practitioners are already very familiar with.

Instead, I want to focus on a few practical questions that business owners and senior leaders can use to assess the overall strength of their treasury control environment. I often refer to these as the treasury control "ground rules."

1. Can a single individual unilaterally move company funds?

This includes withdrawals, cheque issuance, releasing electronic payments, or spending through company credit cards.

However, it is not enough to understand how payment controls are designed. It is equally important to understand who can change those controls.

For example, could an administrator create fictitious users to bypass dual authorization requirements? Could they disable dual approval settings altogether? Could they temporarily modify online banking entitlements, process unauthorized transactions, and then restore the original settings before anyone notices?

Sometimes the greatest vulnerability is not the payment process itself, but the ability to alter the control environment surrounding that process.

2. If someone can move company funds, do they also have the ability to conceal those transactions within the accounting records?

This is often where treasury risk becomes significantly more serious.

Most employees who commit fraud do not intend to empty the company's bank accounts overnight and disappear. More commonly, the objective is to avoid detection for as long as possible.

Examples of concealment techniques may include one or a combination of the following:

a. Manipulating accounting records through journal entries or bank reconciliations.

b. Creating fictitious Accounts Payable records and related payments.

c. Using ERP administrator or super-user privileges to override accounting records.

d. Burying unauthorized transactions within employee expense reports.

If an individual has the ability to move cash and access any of the functions above, a more sophisticated fraud scenario becomes possible.

It is also important not to rely on external auditors as a compensating control. An audit is not designed to prevent fraud, nor should it be viewed as a substitute for effective treasury controls. In some cases, significant control deficiencies may ultimately lead to a qualified audit opinion.

3. Is "trust" the primary control?

Trust is important in every organization. However, in the internal controls world, relying solely on trust without supporting controls creates a control design deficiency and a control gap.

A common observation in fraud investigations is that internal fraud is frequently perpetrated by a long-serving and trusted employee. There may be many reasons that lead an individual to cross the line, but trusted employees often have a deeper understanding of organizational processes, control weaknesses, and opportunities to circumvent oversight.

Good controls are not built because management lacks trust in employees. They are built because no organization should depend entirely on trust.

Strong controls protect both the company and its employees by reducing opportunities for mistakes, misunderstandings, and intentional misconduct.

4. As an owner or member of senior management, do I promote a strong control environment and provide sufficient oversight?

First, it is important to distinguish oversight from micromanagement.

Budget consciousness, cash flow monitoring, working capital management, and spending reviews are all healthy business practices that can serve as powerful deterrents to fraud.

It is entirely appropriate for management to question unusual transactions, investigate significant budget variances, and seek explanations for unexpected changes in cash flow.

Owners and senior management establish the "tone at the top." Employees pay attention to what leadership measures, questions, and follows up on. A culture that values accountability and transparency often strengthens controls long before formal policies and procedures are documented.

The Key Takeaway

The four questions above are not intended to determine whether fraud has occurred. Rather, they serve as a practical "smell test" for identifying potential vulnerabilities in treasury processes.

When the answer to one or more of these questions raises concern, it may indicate an opportunity to strengthen controls before an issue becomes a financial loss.

Treasury controls do not need to be unnecessarily complex. They do, however, need to be thoughtfully designed, regularly reviewed, and consistently applied.

Growing companies often devote significant effort to increasing revenue, scaling operations, and pursuing strategic growth initiatives. Protecting the cash that supports that growth deserves the same level of attention.

If you are concerned about the resilience of your treasury controls, FX-cient can help assess your current control environment and identify practical opportunities to strengthen segregation of duties, banking controls, treasury governance, and management oversight.

A strong treasury control framework is not just about protecting against fraud. It is about creating the confidence and discipline necessary to support sustainable growth.

Disclaimer: Every organization's control environment is unique. The concepts discussed in this article are intended as general guidance and may not be appropriate for all situations. Readers should evaluate their specific circumstances and seek professional advice where appropriate before implementing changes or making decisions. FX-cient accepts no responsibility for losses, damages, or outcomes resulting from reliance on the information presented.

Disclaimer: This article is intended to share general observations and practical insights related to treasury, finance, and internal controls. It is provided for educational purposes only and should not be considered legal, accounting, audit, or professional advice.