Let’s talk

Controls that work in practice

What a maker-checker actually prevents

Most businesses that skip separation of duties do so because they trust their people. That is usually well founded, and it is also not what the control is for.

Ask why a business has no separation between the person who prepares a payment and the person who releases it, and the answer is almost always some version of: we trust her, she has been with us twelve years. That is usually true and entirely beside the point.

A maker-checker is not an accusation. It is a second pair of eyes on work that is easy to get wrong and hard to detect afterwards. Most of what it catches is error, not dishonesty — and the error is the more common cost.

What it actually catches

  • A bank account number transposed, so a genuine payment reaches the wrong party.
  • A supplier's bank details changed on the basis of an emailed request nobody verified.
  • A duplicate payment of an invoice already settled.
  • A rate or quantity that does not match the approved order.
  • A payroll input applied to the wrong employee, or twice.
  • A one-off payment made under a standing approval that did not cover it.

Every one of these is honest. Every one is expensive, and most are only found when the counterparty complains — if they complain.

The fraud cases it closes are specific

Where dishonesty is involved, the pattern in a small finance function is consistent and does not require sophistication: a payee added and approved by the same person, a payroll entry for someone who has left, an advance issued and written off by the same hand, a vendor whose bank details match an employee's.

None of these survive a second person looking at the payee list before release. That is the whole control.

Doing it with four people in accounts

The textbook version assumes staff you do not have. The practical version is about sequencing rather than headcount:

  1. Separate the record from the release

    The person who prepares the payment file should not be the person who authorises it in the bank. If that is genuinely impossible, the authoriser should be outside finance — an owner or director reviewing a payee list takes minutes.

  2. Control the master data, not just the transactions

    Adding or amending a vendor, an employee or a bank account is where the exposure is. Approve changes to the list, and the transactions largely take care of themselves.

  3. Review the exceptions, not everything

    New payees, changed bank details, payments above a threshold, anything outside the usual pattern. Reviewing every transaction is unsustainable and gets abandoned.

  4. Rotate and take leave

    Uninterrupted control of a process by one person for years is itself the risk. A mandatory period where someone else runs it is a control disguised as a holiday.

Why owners resist it, and why that changes

The objection is rarely about cost. It is that introducing a check reads as distrust of someone who has earned trust. That is a real concern and worth naming directly when the control is introduced: it applies to the role, not the person, and it protects the person holding the role as much as the business — because when something does go wrong, an unchecked process leaves them alone with it.

The businesses that adopt this most readily are the ones that have already had an incident. The point of writing it down is to not need that first.

A question this article does not answer.

Talk it through with us