The problem with the textbook answer
Standard internal control guidance assumes enough people to separate who authorises a payment, who executes it and who records it. At twelve employees you do not have that. So most small companies read the guidance, decide it does not apply to them, and implement nothing.
That is the wrong conclusion. Small organisations suffer disproportionately from occupational fraud precisely because control gaps are wider, and the losses land on a business less able to absorb them. The right conclusion is to implement the subset that works at your size.
Controls are not an accusation
The usual objection is that adding controls signals distrust of a long-tenured employee. Reframe it: controls protect good employees too. When money goes missing and only one person could have touched it, the absence of controls is what makes them a suspect.
The five that buy the most protection
Ranked by protection per hour of effort at small headcount.
- The owner reviews the bank statement directly. Not the reconciliation, the statement itself, from the bank, monthly. This one habit catches more than anything else on the list and takes fifteen minutes.
- Nobody who creates vendors also approves payments. If one person can add a vendor and pay it, fictitious-vendor fraud is a single action away. Splitting this is usually free.
- Dual approval above a threshold. Pick a number that fits your business and require a second approver above it. Every modern bill-pay system supports this.
- Somebody other than the preparer reviews the reconciliation. That is the review layer, and it is what an outsourced controller most often supplies at small headcount.
- Mandatory uninterrupted time off for anyone handling money. Long-running schemes need continuous maintenance, which is why they surface when the person is away.
Controls you can automate instead of staff
Where you cannot separate people, separate systems. Software enforces rules headcount would otherwise have to.
- Bill pay tools with approval workflows and an audit trail of who approved what
- Corporate cards with per-card limits and merchant category restrictions instead of one shared card
- Positive pay at your bank, which stops cheques you did not issue
- Bank feeds straight into the accounting system, so transactions are not hand-keyed from statements
- Restricted admin rights, with journal entry posting limited and logged
Where it usually goes wrong
- Payroll: ghost employees and unauthorised rate changes. Review the payroll register line by line each run.
- Vendors: fictitious vendors and duplicate payments. Review the new-vendor list monthly, and it will be short.
- Expense reimbursement: duplicate and personal claims. Require receipts and approval by somebody other than the claimant.
- Cash and cheques: skimming and unauthorised cheques. Lock the stock, use positive pay, restrict who can sign.
- Journal entries: manual entries that hide the other four. Require a second reviewer above a threshold, especially near period end.
What to do this quarter
Do not attempt a full control framework. Pick the three cheapest gaps and close them.
Write down who can approve what and up to what amount, then give it to the bank and the bill-pay system so it is enforced rather than remembered. One page is enough, and having it written is most of the benefit.