One person holding bank credentials, payment authority and reconciliation for an office in Al Olaya is the same single point of failure whether the company has five employees or five hundred.

The control framework covers who may initiate a payment, who may approve it, who may transmit it to the bank and who reconciles afterwards, and the requirement is that these are not the same person. In mid-sized Riyadh businesses they frequently are, not through negligence but because the finance team is small and the arrangement grew organically.

Segregation of duties in practice

Perfect segregation is difficult in a small team, and the practical answer is compensating controls rather than pretending. Where one person must both create and transmit, an independent review of the payment file against approved invoices before release, and a next-day reconciliation by someone else, provides meaningful protection. We design for the team that exists rather than the one an ideal framework assumes.

Authority limits and approval hierarchies

Payment authority should be defined by value band and payment type, documented in a delegation of authority matrix and enforced in the system rather than by policy alone. A limit that exists only in a document is not a control, since the system will process whatever a user with the right permission submits regardless of what the policy says.

Bank mandate management

Bank signatories and portal users need reviewing regularly, particularly after staff changes. It is common to find former employees still holding portal access months after departure, or mandates listing people who left years ago. We build a periodic mandate review into the control calendar because this is one of the highest-impact and lowest-effort controls available.

A common Saudi scenario

A Riyadh trading company's finance manager creates supplier payments, holds sole bank portal credentials, and performs the monthly reconciliation. No fraud has occurred, but the exposure is complete and the continuity risk is equally serious, since an unplanned absence would leave the business unable to pay suppliers or staff. Redesigning with dual authorization and a second credential holder addresses both risks in a matter of weeks.

Reconciliation and monitoring

Daily or at minimum weekly bank reconciliation is itself a detective control, since unexplained items surface fastest when reconciliation is frequent. Automated reconciliation through bank integration makes this practical at volume. The framework connects to wider internal control design and forms part of what external auditors specifically test.

Testing controls rather than assuming them

A control framework that has never been tested is a document. We run periodic walkthroughs: attempt to process a payment above a limit, check whether a former employee's portal access is genuinely revoked, verify that the reconciliation is actually performed by someone other than the preparer. Findings are almost always minor and fixable, which is precisely the point of testing before an auditor or an incident does it for you. This sits within broader internal control design and supports automated banking being safe rather than merely efficient.

Local context

Family-owned businesses in Riyadh most often carry concentrated treasury authority in a single trusted individual, where the practical solution is dual authorization rather than a restructuring that the owners would reasonably resist.