Treasury & FX

Internal Controls for Payment Approval: Who Signs Off

Internal controls for payment approval fix who requests, who approves and who executes each transfer, and above what amount a second signature becomes mandatory. This guide walks through the design for a 10 to 100 employee company.

Equipo Soulbit11 min read
Share
Treasury

At most SMBs, anyone with online banking access can send a payment, and most of those companies have never written down who is supposed to approve it first. While a company has ten employees and the founder signs every wire, the risk stays low because control runs through one trusted person. The moment a second signer shows up, an assistant with banking access or a finance lead with their own login, the lack of a written approval chain stops being an administrative footnote and becomes the most common entry point for both internal and external payment fraud.

In Soulbit Academy we lay out how to design that approval chain: segregation of duties between who requests, who approves and who executes a payment, and the limit matrix that decides when a second signature is required. This control looks inward, and it is different from counterparty risk, which evaluates the outside parties a company moves money through. It is a management practice the company defines and runs on its own, not a feature that depends on any payments platform.

What segregation of duties means in payment approval

Segregation of duties is the practice of splitting the full payment cycle (who requests it, who approves it, who executes it and who reconciles it against the accounting record) across different people, so no single one controls the process end to end. The point is not distrust of the team. It is making sure an error, a fraud or a bad call never depends on one person committing it and also being the one who could hide it from everyone else.

The control framework most auditors and corporate governance committees rely on is the Internal Control - Integrated Framework from COSO, published by the Committee of Sponsoring Organizations of the Treadway Commission. Within its five components, segregation of duties sits inside control activities: the organization selects and develops controls, including separating incompatible tasks, to reduce the risk that a business objective goes unmet. At an SMB with no formal internal audit function, the same principle still applies, just at a smaller scale.

The three roles that need to sit with different people

Requesting, approving and executing a payment are three roles that should sit with three different people whenever team size allows it. Whoever requests it knows why the payment is needed and gathers the supporting document, an invoice, a contract or a purchase order. Whoever approves it reviews that document and authorizes the amount. Whoever executes it sends the money from the company's bank account or payments platform.

Can the same person both request and approve a payment at a ten-employee company?

They should not, even on a small team. When headcount is tight, the minimum acceptable segregation is that whoever requests a payment is never the one who also approves it, and a third person, even a general manager who only spends part of their time on treasury, handles execution or reconciliation. What no company can afford, regardless of size, is one person covering all four roles with zero cross-check.

There is a fourth role that often gets left out of the initial design and that closes the loop: reconciliation. Whoever reconciles compares every executed payment against the accounting record, and needs to be someone other than the person who executed it. Without that fourth role, a duplicate or misdirected payment can go unnoticed for months.

How to build a payment approval limit matrix

A payment approval limit matrix fixes, for each amount range, who can approve a payment alone and above what amount a second signature becomes mandatory. There is no universal threshold, it depends on the company's available cash and risk tolerance, but the structure of the matrix follows a repeatable pattern across 10 to 100 employee companies.

SMB sizeSingle-signer approvalMandatory second signatureBoard or majority-owner approval
10 to 30 employeesUp to a lower amount set by available cashAbove that lower amount and up to a mid-range amountAbove the mid-range amount, or any payment to a new counterparty
30 to 60 employeesUp to a lower amount, reviewed twice a yearFinance lead plus CFO, across a wider mid-range amountTreasury committee, above the mid-range amount or for cross-border payments
60 to 100 employeesUp to a lower amount, reviewed quarterlyCFO plus a second committee signer, within a mid-range amountBoard of directors, above the mid-range amount or for a full payroll run
Table 1. Structure of a payment approval limit matrix by SMB size. The exact amount for each tier is set by each company based on its available cash.

The matrix should also note the currency of the payment, not only its converted amount. A payment of 8,000 dollars and a payment of the equivalent amount in local currency can cross the same matrix threshold, but one of them also carries an exchange rate risk the approver needs to know about before signing.

Should the approval matrix be updated every time the exchange rate moves?

Not on every move, but yes when that move is large enough to push a payment that used to need one signer into the next threshold. The simplest fix is setting the matrix ranges in the company's functional currency and reviewing them, along with the rest of the treasury policy, at least once a year.

How the process changes for international payments and payments to many recipients

A cross-border payment adds one verification step; a mass payment to hundreds of recipients changes the unit of approval: the whole batch, not each payment. The first keeps the request, approve, execute pattern over a single amount and a single counterparty, but adds one more step: verifying the recipient's bank details through a channel other than the one that sent them, typically a call to the supplier's already-known contact number, never the number listed in the email requesting the payment.

The second case, a mass payment sent as a batch (the kind that runs through batch and recurring payroll in stablecoins), changes the unit of approval: instead of reviewing each individual payment, whoever approves it signs off on the entire file, checking the batch total, the number of recipients and a sample of destination accounts before it goes out. The decisive control here is that whoever prepares the disbursement file is never the same person who approves it, because one wrong character in a destination account can misroute that payment without anyone noticing until reconciliation.

What changes in the approval chain when a payment goes to dozens of recipients at once?

It shifts from approving each transaction to approving the full batch before it is sent, with a check on the total amount and a sample of destination accounts. That control needs to be written into the same amount-based approval chain, not treated as a separate process, because the total value of a batch usually crosses the threshold that requires the highest signature in the matrix.

The three fraud patterns segregation of duties prevents

Segregation of duties prevents three frauds: CEO fraud, the change of a supplier's bank details and the fake invoice. The first is CEO fraud, also known as business email compromise: someone impersonates an executive, usually by email, to request an urgent, confidential payment that skips the normal approval chain. Between October 2013 and December 2023, the FBI reported more than 55 billion dollars in exposed losses to this type of fraud through its Internet Crime Complaint Center (IC3), almost always because someone able to execute the payment accepted an instruction outside the normal process.

The second is vendor bank account change fraud: a third party impersonates a real supplier, usually by email, and asks to update the destination account for the next invoice. Without a control requiring verification of any bank account change through a channel other than the email itself, the payment goes out normally to the attacker's account. The third is fictitious invoicing: someone with access to the vendor record creates a fake entity or inflates a real invoice to pay themselves, a pattern that only works when the same person controls vendor onboarding, invoice approval and payment execution.

The Occupational Fraud 2024: A Report to the Nations from the ACFE, which analyzed 1,921 occupational fraud cases across 138 countries, found that 43% of frauds were detected through an internal tip, more than half of them filed by an employee, and that a typical fraud case ran about 12 months before it was caught. An approval chain with separate roles does not replace that internal reporting, but it shortens that 12-month window by requiring at least a second person to review every payment before it goes out. This control is different from AML/KYT transaction monitoring against risk lists, which solves a compliance problem, not a governance one.

None of these three patterns depends on sophisticated hacking. They depend on a gap in the approval chain: one person able to accept an instruction, change a record or authorize a payment without a second, independent check. A company that has already written down who requests, who approves and who executes closes that gap regardless of how convincing the impersonation attempt looks, because the fraudulent instruction still has to pass through a person who was never authorized to approve it alone.

What Soulbit V1 supports here, and what stays a management practice

Soulbit V1 supports part of the evidence behind segregation of duties, without replacing the approval chain. The on-chain history and traceability of every payment leave a record by recipient and by batch, useful for whoever reconciles to confirm that what was executed matches what was approved. Batch and recurring payroll lets a company upload and schedule a disbursement file, which makes it easier to separate preparing the file from approving it, if the company organizes it that way internally.

What Soulbit V1 does not do matters just as much: there is no role-based, multi-level or user-permission approval workflow inside the platform. The chain that decides who requests, who approves and who executes each payment, and at what amount a second signature is required, lives in the company's internal policy and runs before the company ever sends the payment instruction, not as a feature of Soulbit V1.

Payment approval control elementDoes Soulbit V1 support it today?How it gets resolved
Traceability and evidence for every executed paymentYesOn-chain history and traceability by recipient and by batch
Uploading and scheduling batch payrollYesBatch and recurring payroll over a disbursement file
Role-based, multi-level or user-permission approvalNoChain defined and run through the company's internal policy
Verifying a recipient's bank account changeNoCompany's responsibility, through a channel other than the one that sent it
Automatic alerts when a matrix threshold is crossedNoSet by the internal approval matrix, not automated in V1
Table 2. What part of payment approval control Soulbit V1 supports today, and what remains a company management practice.

How often the matrix gets reviewed and who can change it

The approval limit matrix gets reviewed at least once a year, on the same cycle as the rest of the company's treasury policy. That annual cycle is not the only trigger. Headcount growth that adds a new approval tier, a meaningful change in available cash, a fraud or duplicate-payment incident, or a new investor coming on board should each force an off-cycle review.

Changing the matrix should sit with whoever approves the full treasury policy, typically the board or the majority owner, and never with the same person who executes payments day to day. Letting whoever moves the money also decide when a second signature is required defeats the control by design.

Frequently asked questions

What are internal controls for payment approval?

They are the set of rules that stop one person from controlling an entire payment cycle: requesting, approving and executing a payment need to be separate roles, with an amount threshold that triggers a mandatory second signature. The goal is not distrust of the team, it is making sure no single error or fraud can happen and get hidden by the same person at the same time.

What is segregation of duties in payments?

It is the practice of splitting the payment cycle, requesting, approving, executing and reconciling, across different people, so no one controls the process from start to finish. A ten-employee company can resolve this with two people and a minimal cross-check; a hundred-employee company usually needs three or four separate roles plus a committee for larger amounts.

At what amount should a payment require a second signature?

There is no universal threshold, it depends on each company's available cash and risk tolerance. A common practice for a 10 to 100 employee company is to set two or three tiers, for example a manager for smaller payments, manager plus CFO for a mid range, and board or majority-owner approval above a third threshold, reviewed at least once a year.

How does the control change when a payment goes to many recipients at once?

Approval stops reviewing each individual payment and instead authorizes the full batch: the total file amount, the number of recipients and a sample of destination accounts before it is sent. The key control is that whoever prepares the disbursement file is never the same person who approves it, because one wrong character in a destination account routes that payment to the wrong party.

What fraud patterns does segregation of duties prevent?

It mainly prevents three patterns: CEO fraud, where someone impersonates an executive to request an urgent payment outside the normal process; vendor bank account change fraud, where a third party impersonates a real supplier to redirect a legitimate payment; and fictitious invoicing, where someone creates a fake vendor or inflates a real invoice to pay themselves. All three rely on one person being able to request, approve and execute without anyone else checking.

Want your company to add stablecoins to its operations?

Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.

Join the waitlist

Related articles

Treasury

Getting Paid in GBP from Latin America: What Changes

Getting paid in GBP is not the same as getting paid in dollars: the pair is thinner, most Latin American countries publish no official GBP rate, and market hours matter.

11 min read
Getting Paid in GBP from Latin America: What Changes
Treasury

How Much of Your Company's Cash Should Be in Dollars

No fixed number answers how much of a company's cash should sit in dollars. There is, instead, a method: map exposures, calculate the net position, set a range and define when to rebalance.

10 min read
How Much of Your Company's Cash Should Be in Dollars
Treasury

Foreign Currency Monthly Close: Functional vs Presentation

A US parent consolidating a Latin American subsidiary in dollars runs the same monthly close every period: fix functional and presentation currency, retranslate monetary items at the closing rate, and book the exchange difference.

10 min read
Foreign Currency Monthly Close: Functional vs Presentation