Payment control and assurance

Nothing settles
untested.

Payables and receivables are administered under documented control, tested before disbursement, cleared against the register, and posted with the entries and evidence the close requires.

Payables controlReceivables controlAssuranceClose and reconciliationControl environment

Standard of practice

Disbursement without independent testing is an unmitigated control gap, and it is the ordinary condition of most payables functions.

Charge detail is approved against contract rate and tolerance band by a performer who is also the approver, under a due date that does not move. Deviation is detected in recovery audit, long after settlement, where recovery is a collection matter rather than a control one. The exception rate is never measured because the population was never tested.

ReconLog places assurance ahead of the payment file. Testing is performed on the population, exceptions are worked under maker-checker separation, and the determination carries its evidence, its calculation trace and its lineage into the ledger.

Scope

Disciplines

Administered together or severally. Engagements ordinarily commence where the exposure is largest and widen once the register reconciles.

Custody

Payables control

Intake, capture, indexing, extraction and registration. Coding, GL and cost-object assignment. PO and receipt referencing, three-way matching, quantity, price, tax and freight variance against match tolerance. Parking, blocking and release. Payable and liability creation, payment-term and discount-date determination. Payment proposal, selection, prioritisation, grouping and batching. Payment-file creation, validation and authorisation. Bank submission and acknowledgment, settlement confirmation, clearing entry, payment application, residual and vendor-account clearing. Supplier-statement reconciliation, aging, due and overdue buckets, blocked and exception queues. Duplicate-document and duplicate-payment prevention.

Exposure

Receivables control

Billing, receivable creation and posting, statement generation and delivery. Collection activity, queue and strategy. Dunning, reminder cycle, delinquency and past-due management. Aging buckets, credit limit, credit exposure, credit, order and billing holds. Promise to pay and payment commitment. Cash receipt, identification, matching, allocation and posting. Automatic and manual cash application, unapplied, unidentified and on-account receipts. Short-pay handling, deduction management, dispute management. Bad-debt provision, doubtful-account allowance, write-off and collection recovery.

Testing

Assurance

Inspection, observation, inquiry and walkthrough. Random, judgmental, statistical, attribute and monetary-unit sampling. Vouching, tracing, recalculation, reperformance, external and internal confirmation. Completeness, accuracy, cutoff, existence, valuation, classification, authorisation and presentation assertions. Control and compliance testing against design and operating effectiveness. Deviation rate against tolerable deviation, projected against tolerable error. Analytical procedures, variance and trend analysis, exception and root-cause analysis. Duplicate, anomaly, overbilling and leakage detection.

The entry

Close and reconciliation

Expense recognition, accrued liability, prepaid expense, deferred revenue, accrued and unbilled revenue. Work in progress, reserve movement, impairment and intercompany allocation. Journal preparation, validation, routing, authorisation, posting and reversal, including recurring, adjusting, reclassification, allocation, accrual and deferral journals. Ledger-to-subledger, bank-to-book, control-account and intercompany reconciliation. Reconciling items certified, aged and supported. Account and balance rollforward.

Architecture

Control environment

Control objective, activity, frequency, performer, reviewer and approver. Maker-checker separation, segregation of duties, delegated authority and authorisation limits. Beneficiary and bank-account verification, independent callback, payment-velocity and payment-limit checks, allowlists and payment block. Sanctions and watchlist screening, conflict checking. Entity-level, transaction-level, application and IT-dependent controls. Control gap, redundant and complementary controls, remediation plan, retest and validation. Record lineage, calculation and decision trace, immutable evidence, retention and disposition.

Coverage

A control set written for one vendor service will clear what another would block.

Charge basis, billing unit, rate band, tolerance and allowable quantity are conventions of the vendor service, not of accounting. A single generalised rule set raises exceptions against ordinary practice and clears charge detail that is not. Each service under coverage carries its own control set, charge vocabulary and submission register.

Engagement

Submit a population, not a proposal request.

A register extract, the contract terms it was raised under, and the aging it sits in. The practice returns the exceptions identified, the assertions tested, and the determination it would have recorded.