What the month-end close really is (an owner's guide)
A plain-English guide to the month end close process for owners of several businesses: what happens, how long it should take, and what good looks like.
An internal controls small business checklist built for lean teams: seven controls that survive a two-person finance function, and where to start first.
This article is general information, not legal, tax, or accounting advice. Your obligations depend on where you operate, your structure, and any lender or contractual commitments.
An internal control is any step in your process whose purpose is to catch or prevent an error, an omission, or a theft, rather than to record a transaction.
That distinction matters. Entering a bill is bookkeeping. Requiring that a second person approves it before payment is a control. Reconciling the bank is the most effective control most small businesses have, because it forces the ledger to agree with an outside party every month.
A control can be one line in a checklist, as long as somebody performs it and you can tell afterwards that they did.
Small organizations carry more control risk per person, because the same person often initiates, records, and reconciles.
The ACFE's Occupational Fraud 2024: A Report to the Nations, covering 1,921 cases, estimates that organizations lose around 5% of revenue to fraud annually, with a median loss of $145,000 per case. More than half of the frauds studied trace back to weak or overridden internal controls, and 89% involve asset misappropriation: payments to the wrong place, expenses that were not real, cash that did not arrive.
Read that as a design brief. Those frauds were mostly ordinary transactions that nobody independent ever looked at, repeated for a long time.
Errors follow the same logic. Gartner's 2024 survey of 497 controllers and chief accounting officers found that 18% of accountants make financial errors at least daily and 59% make several errors per month. The controls that catch a theft are the ones that catch a typo.
Ordered by how much protection they buy per hour spent.
Reconcile to the statement itself, not the feed, and have it signed off by someone other than the person who posted the transactions. Any unexplained difference stays on a list until it is explained.
In a two-person function this means the bookkeeper prepares the payment run and the owner approves it in the bank. A five-minute habit that defeats most of the asset-misappropriation category outright.
Almost every payment diversion runs through a changed bank detail, not a fake invoice. Confirm any new supplier or changed account number through a channel you already had, not by replying to the email that requested it.
One page: who can approve spend, up to what amount, for which entity. Most groups have never written this down, and discover on the day it matters that three people believed they had authority.
An open period is an uncontrolled period, because entries can move into it after the numbers have been reported. Lock each month once reviewed, and record any reopening with a reason and a name. If you are unsure what a closed period should mean, start here.
Not everything, one thing. This month, every payment over a threshold. Next month, all expense claims. The month after, all manually posted journal entries. Rotating review gives a lean team much of the deterrent effect of a larger one, because nobody knows which population you are looking at.
Every posting, approval, and change should be attributable to a person and a time, and that record should sit outside the reach of the person it describes. This is what makes the others provable rather than claimed.
When separation is impossible, replace it with visibility and after-the-fact review, and say so explicitly.
A one-bookkeeper group cannot have four eyes on everything. What it can have is an owner who personally opens the bank statement each month rather than receiving a summary, who approves the payment run, and who reviews one rotating population of transactions. Write down that separation of duties is not achievable at your size and that these habits are the compensating controls. A lender or an incoming finance hire treats a documented compensating control very differently from a gap nobody mentioned.
A spreadsheet that feeds the books is part of your control environment, and usually the least controlled part of it.
Panko's spreadsheet-error research, synthesising audits of 88 operational spreadsheets, found that 94% contained at least one error, with an average cell error rate of 5.2%. In a small group the ones that matter are those nobody thinks of as financial systems: the payroll allocation, the intercompany recharge, the consolidation workbook, the commission calculation.
The control is not to stop using spreadsheets. Identify the handful whose output posts to the ledger and treat those as systems: one owner, no ad hoc formula edits, a kept version, and a check tying the output to something independent.
Four entities. A holdco, two trading businesses, one property company. One part-time bookkeeper, one owner, no controller.
Duties cannot be separated: the bookkeeper enters bills, posts journals, and reconciles. So the owner takes three jobs. Statements are emailed by the bank directly to the owner, so the bookkeeper never controls the source document the reconciliation is checked against. Every payment run is approved by the owner in the banking portal, with the invoice list attached. And one population is reviewed in detail each month on a four-month rotation: payments above a threshold, expense claims, manual journals, intercompany entries.
Total owner time: under two hours a month, covering initiation, authorisation, and detection.
For a single entity, more than most owners use. Both give you per-user permissions, a log of who posted or changed what, bill approval workflows, period locking, and a proper reconciliation screen. If you run either with everybody signed in as the admin user, you have turned off most of your control environment, and turning it back on costs an afternoon.
The gap is the group. Neither gives you one permission model across several files, a single view of who approved what, or any way to agree intercompany balances between two sets of books. Those become manual, and manual is where the multi-entity control gaps tend to live.
Once a year, walk one transaction of each type from origin to the reported numbers and note where nobody would have caught a problem.
One supplier payment, one customer receipt, one payroll run, one intercompany recharge, one manual journal. At each step, ask who would notice if this were wrong. Where the answer is nobody, you have found a control to add. That afternoon produces a better list than any generic checklist, including this one.
Start with the reconciliation and the payment approval. Those two, performed every month by two different people, cover more risk than the other five combined, and neither requires software or budget.
Then write your one page: who approves what, up to what limit, and which compensating controls exist because separation is not possible. The page is not for a regulator. It is so the answer does not live only in your head.
This is also the logic behind how cruisr works. Running bookkeeping and close on your existing QuickBooks Online or Xero files on an "AI prepares, humans approve" basis is a control design as much as a workflow: preparation and approval are structurally separate, every posting carries its supporting evidence and an attributable record of who approved it, and the period is locked on a fixed cadence. The environment is auditable by design, so the evidence exists before anyone asks for it. cruisr does not perform audits and never moves or holds money; your bank relationships and payment authority stay where they are.
If you would like an outside read on where your group's controls and close leave gaps, get in touch. cruisr runs a free diagnostic on your existing files and comes back within 48 hours with a 30-minute readout.
A plain-English guide to the month end close process for owners of several businesses: what happens, how long it should take, and what good looks like.
The real multi entity consolidation challenges are error risk, chart of accounts drift, key-person risk and no audit trail. Plus when spreadsheets still win.
Latest
Why does month end close take so long? Six named causes, from dependency chains to review bottlenecks, and an honest look at when 15 days is rational.
Free, on your own QuickBooks or Xero, delivered in a 30-minute readout.
No obligation · No migration · Nothing installed · No credit card required