Payment approval software is the last gate, and it guards a different risk

Updated

Approving an invoice and approving a payment are two different controls guarding two different risks, and organisations that treat the second as a repeat of the first get little from it. Invoice approval asks whether the money is owed. Payment approval asks whether this specific transfer, to this account, for this amount, should leave now. The second question is where fraud is caught.

What the payment gate should check

That the bank details match the verified details held for that supplier. That the total agrees with the approved invoices. That no invoice in the run has been paid before. And that the run itself is what was expected in size and shape. These are checks on the payment as an event rather than on each invoice, and they catch things invoice approval cannot.

Bank detail changes deserve their own control

The highest-value payables fraud is a convincing request to change a supplier's bank details. The defence is procedural: verify using contact details you already hold rather than any supplied in the request, have somebody other than the requester perform the verification, and record it. Software helps by making the change visible and forcing the step; it cannot make the phone call.

Segregation across the run

The person who created the payment run should not be the only person who releases it. This is one of the oldest controls in finance and it remains effective. Software makes it enforceable rather than aspirational, and it makes exceptions visible when somebody has to cover during absence, which is when segregation quietly lapses.

Questions people ask about payment approval software

Is payment approval needed if invoices are approved?

Yes, because they guard different risks. Invoice approval says the money is owed; payment approval says this transfer is correct and has not already happened.

How do we verify bank detail changes?

Using contact details you already hold for that supplier, never those provided in the request, and with the verification recorded by somebody other than whoever received the request.

Should payment runs be scheduled or ad hoc?

Scheduled runs are easier to control and easier for suppliers to predict. Ad hoc payments should be the exception and should be visible as such.

Sources

Related answers

Start Threewayly ProKeep the match, not the spreadsheet