Payment runs are among the easiest parts of payables to automate, because grouping approved invoices and producing transfers is mechanical. Two controls inside that process must not be automated, and organisations that automate them anyway generally discover why through an expensive incident rather than through an audit finding.
Safe to automate
Selecting approved invoices due within a window, grouping by supplier, producing the payment file, recording payments against invoices and sending remittance advices. It removes a tedious manual task and the transcription errors that come with rekeying account numbers into a banking portal, which is a real source of misdirected payments.
Keep manual: release by a second person
Whoever prepared the run should not be the only person able to release it. Simple, old and effective, and the moment it lapses is nearly always absence, which means cover arrangements deserve as much thought as the rule itself. Automation should enforce it rather than making it optional below a threshold nobody remembers choosing.
Keep manual: bank detail verification
A change to where a supplier's money goes should be verified using contact details you already hold, by somebody other than whoever received the request, with the verification recorded. No automation substitutes for that check, and the request will always look convincing, because the people who send them are practised at making them convincing.
Questions people ask about automating payments
Can small runs be auto-released?
Some organisations do it below a threshold. It removes the second pair of eyes precisely where money leaves, so make it a deliberate risk decision.
How often should runs happen?
Weekly suits most organisations. Choose the rhythm deliberately and tell suppliers, since most chasing is about the date.
What about card payments?
They bypass these controls entirely, which is convenient and worth reconciling deliberately rather than leaving unexamined.