Trust, but Verify: Financial Oversight for Growing Businesses

Small business owners typically spend their time where they believe they create the most value: serving customers, managing employees, overseeing operations, and growing sales. As the business expands, responsibility for billing, collections, payroll, vendor payments, bank reconciliations, and financial reporting is increasingly delegated to the accounting team.

Delegation is necessary, and trust is important. But trust alone is not an internal control.

Owners do not need to become accountants or review every transaction. They should, however, understand how the accounting function operates, who controls key financial activities, what information is independently reviewed, and whether the department could continue functioning if a key employee suddenly became unavailable.

When Too Much Responsibility Rests With One Person

Smaller businesses often have limited accounting staff. One employee may create vendors, process invoices, initiate payments, record transactions, reconcile bank accounts, process payroll, and prepare financial reports.

This concentration of responsibility may develop naturally as the business grows. The employee may be experienced, loyal, and highly trusted. The risk is not necessarily the employee. It is that one person may control an entire financial process without meaningful independent review.

This is commonly referred to as a lack of segregation of duties. Ideally, responsibility for authorizing transactions, moving money, recording activity, and reviewing the results would be divided among different people. When staffing does not allow for that separation, ownership should establish other review procedures, often called compensating controls.

Three Risks Owners Should Consider

The most obvious risk is fraud or misappropriation. An employee who can create a vendor, change its banking information, initiate a payment, record the transaction, and reconcile the bank account may also be able to conceal unauthorized activity. Similar risks can exist in payroll, customer receipts, expense reimbursements, and company credit cards.

The second risk is financial error. Most accounting problems are not intentional. Employees may be overwhelmed, inadequately trained, or simply make mistakes. Duplicate payments, missed invoices, unreconciled accounts, incorrect payroll changes, unsupported journal entries, and inaccurate receivable balances can remain undetected when no one independently reviews the work. These errors may cause ownership to make important decisions using incomplete or inaccurate financial information.

The third risk is dependence on a key person. A business may not realize how much institutional knowledge is concentrated with one employee until that person resigns, becomes ill, or takes an extended leave. Management may suddenly discover that no one else knows how payroll is processed, bills are paid, customer receipts are applied, accounts are reconciled, or financial reports are prepared.

Even an honest and highly capable employee can represent a significant operational risk when procedures are undocumented and no one else understands the role.

    Oversight Does Not Mean Micromanagement

    Effective oversight does not require an owner to perform accounting work. It means creating enough visibility to recognize unusual activity, ask informed questions, and confirm that important financial processes are operating as expected.

    Ownership should understand who can move money, create or modify vendors, change payroll information, post journal entries, and administer access to the accounting system. Owners should also periodically review bank and credit card activity, payroll changes, accounts receivable, significant expenses, and unexpected financial statement fluctuations.

    Sensitive transactions, such as new vendors, changes to payment instructions, payroll adjustments, bonuses, and large electronic payments, may warrant a second approval.

    Critical procedures should also be documented and cross-trained. The accounting function should be able to continue operating if a key employee is unavailable tomorrow.

    The objective is not to create unnecessary bureaucracy. It is to ensure that trust is supported by accountability and verification.

    Why a Financial Statement Audit May Not Address All These Risks

    Owners sometimes assume that the annual financial statement audit addresses the full range of risks within the accounting department. That is not the primary purpose of the audit.

    A financial statement audit is designed to provide reasonable, not absolute, assurance that the financial statements are free from material misstatement, whether caused by fraud or error. The auditor obtains an understanding of internal control to assess financial statement risks and design appropriate audit procedures. In a typical private-company audit, however, the auditor is not engaged to express an opinion on the effectiveness of the company’s internal controls.

    As a result, the audit may not identify every control weakness, smaller unauthorized transaction, operational breakdown, system-access concern, or dependency on a key accounting employee. The audit is focused on whether the financial statements are materially correct, not on providing a comprehensive assessment of everything that could go wrong within the accounting function.

    Going Beyond the Annual Audit

    For owners who want greater visibility into how the accounting function actually operates, targeted procedures are available that go beyond the scope of the financial statement audit. These are not one-size-fits-all engagements. They can be shaped around the areas of greatest concern, whether that is cash handling, vendor payments, system access, or the operational risk of losing a key employee.

    Common approaches include:

    • Segregation-of-duties assessments that evaluate how responsibilities are divided across the accounting function and where gaps in oversight exist.
    • Agreed-upon procedures focused on specific transaction types such as vendor payments, payroll changes, expense reimbursements, bank reconciliations, or company credit card activity.
    • Data analysis designed to surface anomalies like duplicate payments, unusual vendors, round-dollar transactions, or activity outside normal patterns.
    • Accounting system access reviews that examine user permissions, administrator privileges, and whether former employees still have access to sensitive functions.
    • Fraud risk assessments that help ownership understand where unauthorized activity could occur and which controls, if any, could prevent or detect it.
    • Key-person assessments that identify where institutional knowledge is concentrated and whether documented procedures exist to support continuity if a critical employee becomes unavailable.

    Agreed-upon procedures are often a practical starting point because the scope is defined collaboratively. Ownership identifies the highest-priority areas, and the procedures are designed accordingly. This keeps the engagement focused and avoids the cost and complexity of a broader undertaking.

    One practical note: Depending on the relationship with the existing audit firm, independence requirements may affect which services that firm can provide. In some cases, a separate advisor may be more appropriate. Management must remain responsible for decisions, controls, and implementation, regardless of who performs the work.

    Asking the Right Questions

    The most useful question is not simply, “Do I trust my accounting team?”

    Owners should also ask:

    • What financial activity could one person complete without anyone else knowing?
    • What information does ownership independently review?
    • Which responsibilities depend entirely on one employee?
    • How would the company identify an unauthorized payment, significant error, or unusual transaction?

    If those questions are difficult to answer, that is useful information in itself. The goal is not a perfect system. It is a level of visibility appropriate for the size and complexity of the business, supported by enough structure that trust does not have to do all the work.

    Trust should remain part of the relationship. It should simply be supported by visibility, accountability, and verification.

    If you have questions about your current financial oversight practices or would like to explore what a targeted assessment might look like for your business, contact your BMF advisor. We are here to help you identify the right level of visibility and put practical safeguards in place that fit the size and complexity of your organization.

    About the Authors

    Eric D. German
    Eric D. German
    CPA, MAcc
    Partner and Executive Committee Member, Assurance and Advisory

    Subscribe

    Stay up-to-date with the latest news and information delivered to your inbox.

    Subscribe Now