Finance checklist · 6 minutes

10 controls before you release a payment.

For whoever answers for money leaving the company. Each control says what it is, what it looks like when it fails and, where it applies, how Certo Procure covers it. If a control is not in Procure, we say so.

  1. Segregation of duties

    The person who requests the purchase, the person who approves it and the person who prepares the payment are different people.

    When it fails. The same person requests, approves and loads the payment. Nobody notices until the audit.

    In Certo Procure. The requisition, the approval and the payment proposal are recorded with user and date, and payment proposals go through dual control.

  2. Three-way match

    Before paying, the order, the receipt and the invoice agree on what was ordered, what arrived and what is being charged.

    When it fails. It gets paid because the invoice arrived. What was not received, or the price nobody negotiated, goes out anyway.

    In Certo Procure. Before payment, order, receipt and invoice have to match. If evidence is missing, the invoice is held and you see exactly what is missing. Included in Procure Total and Enterprise.

  3. Recorded receipt

    Someone confirms what arrived, how much and when, and that record exists before payment.

    When it fails. The receipt is a "yes, it arrived" in a chat. Partial or missing deliveries get paid in full.

    In Certo Procure. The receipt, partial or complete, is recorded with user and date. No receipt, no payment.

  4. Approved bank account changes

    Any change to a supplier bank account is confirmed through a different channel from the one that requested it and approved by another person before the next payment.

    When it fails. An email arrives with "our new bank details", someone updates the account and the next payment goes to a third party.

    In Certo Procure. The supplier record keeps its tokenized accounts. Confirming the change through another channel and approving it remain part of your treasury procedure.

  5. Approval limits by amount

    Each level of authority approves up to an amount; above it, the approval moves up a level.

    When it fails. A large purchase is approved with an "ok" sent from a phone, or split into several requests to stay under the threshold.

    In Certo Procure. The rule by amount and cost center decides who approves, and every response is recorded with user and date. For example: above US$5,000, finance management approves.

  6. Validated suppliers

    Orders only go to active suppliers whose documents have been reviewed.

    When it fails. A supplier created yesterday, with no file, receives its first payment before anyone has checked who it is.

    In Certo Procure. Every supplier has a record with reviewed documents, and orders go to an active supplier. Document expiration alerts are coming soon.

  7. Duplicate control

    The same invoice is never paid twice, even if it arrives through two channels or gets forwarded again.

    When it fails. The invoice arrives by email and again with the supplier statement. It is paid twice and found in the reconciliation.

    In Certo Procure. The invoice is linked to an order. A second invoice against the same order is held.

  8. Budget by cost center

    Every purchase is charged to a cost center with an owner before the spend is committed.

    When it fails. The spend shows up at month-end as "general expenses" and nobody knows which area requested it.

    In Certo Procure. Every request carries its cost center; budget and accountability travel with the request, and approval follows rules by cost center.

  9. Auditable evidence

    For every payment you can show who requested it, who approved it, what was received and against which invoice, without searching email.

    When it fails. The auditor asks about a payment and the evidence is an email thread titled "RE: RE: RE: invoice" and an "ok" on a phone.

    In Certo Procure. Every decision is recorded with user and date. On Enterprise, you export a CSV with order, invoice and match evidence to your ERP.

  10. Payment proposal released by someone else

    The person who builds the payment proposal is not the person who releases it.

    When it fails. The same person prepares the payment batch and sends it to the bank. A mistake, or something worse, goes out without a second look.

    In Certo Procure. Payment proposals go through dual control. Certo Intelligence explains the differences between order, receipt and invoice, but it never releases payments: a person does that.

How to use this list

Take your last ten supplier payments and ask, for each one, which controls you can prove with evidence rather than by word of mouth.

8–10 controls: the process is governed; check that it stays that way as volume grows.

5–7 controls: money leaves with partial evidence; the gaps are usually in receipts and duplicates.

0–4 controls: payment depends on someone's memory and inbox. Start with approval by amount and the three-way match.

Follow a real purchase, from request to payment.

We configure a flow similar to yours and show every control without hiding the detail.

Request a Procure demo