Skip to content
Close & Controls

A financial-controls checklist for lean teams

An internal controls small business checklist built for lean teams: seven controls that survive a two-person finance function, and where to start first.

Hugo Perrin7 min read
On this page

This article is general information, not legal, tax, or accounting advice. Your obligations depend on where you operate, your structure, and any lender or contractual commitments.

What do internal controls mean for a small business?

An internal control is any step in your process whose purpose is to catch or prevent an error, an omission, or a theft, rather than to record a transaction.

That distinction matters. Entering a bill is bookkeeping. Requiring that a second person approves it before payment is a control. Reconciling the bank is the most effective control most small businesses have, because it forces the ledger to agree with an outside party every month.

A control can be one line in a checklist, as long as somebody performs it and you can tell afterwards that they did.

Why does a lean team need controls more, not less?

Small organizations carry more control risk per person, because the same person often initiates, records, and reconciles.

The ACFE's Occupational Fraud 2024: A Report to the Nations, covering 1,921 cases, estimates that organizations lose around 5% of revenue to fraud annually, with a median loss of $145,000 per case. More than half of the frauds studied trace back to weak or overridden internal controls, and 89% involve asset misappropriation: payments to the wrong place, expenses that were not real, cash that did not arrive.

Read that as a design brief. Those frauds were mostly ordinary transactions that nobody independent ever looked at, repeated for a long time.

Errors follow the same logic. Gartner's 2024 survey of 497 controllers and chief accounting officers found that 18% of accountants make financial errors at least daily and 59% make several errors per month. The controls that catch a theft are the ones that catch a typo.

The seven controls worth having

Ordered by how much protection they buy per hour spent.

1. Reconcile every bank and card account, every month, to a statement

Reconcile to the statement itself, not the feed, and have it signed off by someone other than the person who posted the transactions. Any unexplained difference stays on a list until it is explained.

2. Separate the person who approves a payment from the person who sets it up

In a two-person function this means the bookkeeper prepares the payment run and the owner approves it in the bank. A five-minute habit that defeats most of the asset-misappropriation category outright.

3. Control who can add or change a supplier or a bank detail

Almost every payment diversion runs through a changed bank detail, not a fake invoice. Confirm any new supplier or changed account number through a channel you already had, not by replying to the email that requested it.

4. Keep a current list of who can authorise what, with limits

One page: who can approve spend, up to what amount, for which entity. Most groups have never written this down, and discover on the day it matters that three people believed they had authority.

5. Close the period and lock it

An open period is an uncontrolled period, because entries can move into it after the numbers have been reported. Lock each month once reviewed, and record any reopening with a reason and a name. If you are unsure what a closed period should mean, start here.

6. Review the full transaction detail for one thing every month

Not everything, one thing. This month, every payment over a threshold. Next month, all expense claims. The month after, all manually posted journal entries. Rotating review gives a lean team much of the deterrent effect of a larger one, because nobody knows which population you are looking at.

7. Keep the record of who did what

Every posting, approval, and change should be attributable to a person and a time, and that record should sit outside the reach of the person it describes. This is what makes the others provable rather than claimed.

What do you do when you cannot separate duties?

When separation is impossible, replace it with visibility and after-the-fact review, and say so explicitly.

A one-bookkeeper group cannot have four eyes on everything. What it can have is an owner who personally opens the bank statement each month rather than receiving a summary, who approves the payment run, and who reviews one rotating population of transactions. Write down that separation of duties is not achievable at your size and that these habits are the compensating controls. A lender or an incoming finance hire treats a documented compensating control very differently from a gap nobody mentioned.

Where do spreadsheets quietly become a control weakness?

A spreadsheet that feeds the books is part of your control environment, and usually the least controlled part of it.

Panko's spreadsheet-error research, synthesising audits of 88 operational spreadsheets, found that 94% contained at least one error, with an average cell error rate of 5.2%. In a small group the ones that matter are those nobody thinks of as financial systems: the payroll allocation, the intercompany recharge, the consolidation workbook, the commission calculation.

The control is not to stop using spreadsheets. Identify the handful whose output posts to the ledger and treat those as systems: one owner, no ad hoc formula edits, a kept version, and a check tying the output to something independent.

A worked example: a four-entity group with one bookkeeper

Four entities. A holdco, two trading businesses, one property company. One part-time bookkeeper, one owner, no controller.

Duties cannot be separated: the bookkeeper enters bills, posts journals, and reconciles. So the owner takes three jobs. Statements are emailed by the bank directly to the owner, so the bookkeeper never controls the source document the reconciliation is checked against. Every payment run is approved by the owner in the banking portal, with the invoice list attached. And one population is reviewed in detail each month on a four-month rotation: payments above a threshold, expense claims, manual journals, intercompany entries.

Total owner time: under two hours a month, covering initiation, authorisation, and detection.

Can QuickBooks or Xero do this?

For a single entity, more than most owners use. Both give you per-user permissions, a log of who posted or changed what, bill approval workflows, period locking, and a proper reconciliation screen. If you run either with everybody signed in as the admin user, you have turned off most of your control environment, and turning it back on costs an afternoon.

The gap is the group. Neither gives you one permission model across several files, a single view of who approved what, or any way to agree intercompany balances between two sets of books. Those become manual, and manual is where the multi-entity control gaps tend to live.

How should you review controls without turning it into a project?

Once a year, walk one transaction of each type from origin to the reported numbers and note where nobody would have caught a problem.

One supplier payment, one customer receipt, one payroll run, one intercompany recharge, one manual journal. At each step, ask who would notice if this were wrong. Where the answer is nobody, you have found a control to add. That afternoon produces a better list than any generic checklist, including this one.

Where to start

Start with the reconciliation and the payment approval. Those two, performed every month by two different people, cover more risk than the other five combined, and neither requires software or budget.

Then write your one page: who approves what, up to what limit, and which compensating controls exist because separation is not possible. The page is not for a regulator. It is so the answer does not live only in your head.

This is also the logic behind how cruisr works. Running bookkeeping and close on your existing QuickBooks Online or Xero files on an "AI prepares, humans approve" basis is a control design as much as a workflow: preparation and approval are structurally separate, every posting carries its supporting evidence and an attributable record of who approved it, and the period is locked on a fixed cadence. The environment is auditable by design, so the evidence exists before anyone asks for it. cruisr does not perform audits and never moves or holds money; your bank relationships and payment authority stay where they are.

If you would like an outside read on where your group's controls and close leave gaps, get in touch. cruisr runs a free diagnostic on your existing files and comes back within 48 hours with a 30-minute readout.

See the state of your books in 48 hours.

Free, on your own QuickBooks or Xero, delivered in a 30-minute readout.

No obligation · No migration · Nothing installed · No credit card required