Playbook 6.3

Building Internal Financial Controls That Prevent Fraud and Errors

The minimum control framework every SME needs — and the five control failures that account for most of the losses

6–8 weeksMedium complexityStage 2–4Verified 21 August 2026

Who this is for

SMEs where financial controls are informal, undocumented, or concentrated in a single person — typically the promoter or a long-tenured CFO. Businesses that have experienced unexplained variances, cash shortfalls, or vendor payment irregularities. Any business preparing for institutional investment where internal control quality will be assessed.

What it costs you to ignore it

The average SME fraud is not committed by an outsider — it is committed by a trusted employee over an extended period, enabled by the absence of basic controls. The median loss in an SME fraud case in India is ₹35–50 lakh. The controls that would have prevented it cost a fraction of that to implement. The second cost is reputational: a business that has experienced a fraud, or whose control environment suggests it could, is uninvestable.

The diagnosis behind it

This playbook is triggered by a Red or Critical finding on:

Vital 6 — Financial Integrity

The Protocol

1

Map your five highest-risk financial processes: vendor payments, payroll, cash handling, expense reimbursements, and revenue collection. For each, document who initiates, who approves, and who reconciles. Any process where the same person does all three is a control failure.

Owner
CFO
Duration
1 week
Cost
Internal time only
Done looks like
Five high-risk processes mapped; segregation of duties gaps identified
2

Implement segregation of duties for all payment processes: the person who raises a purchase order cannot also approve the invoice or authorise the payment. If headcount is too small for full segregation, the promoter or CFO must be the approver — not a delegate.

Owner
CFO + CEO
Duration
2 weeks
Cost
Internal time; process redesign only
Done looks like
Payment authorisation matrix documented; no single-person payment process remains
3

Implement a vendor master control: new vendors can only be added to the payment system by a designated controller, with supporting documentation (GST certificate, bank details on letterhead). Changes to existing vendor bank details require dual approval.

Owner
CFO
Duration
1 week
Cost
Internal time; accounting software configuration
Done looks like
Vendor master control implemented; dual approval for bank detail changes active
4

Implement a monthly bank reconciliation discipline: all bank accounts reconciled within 5 working days of month end, reviewed by the CFO, and signed off. Unreconciled items older than 30 days escalated to the CEO.

Owner
CFO
Duration
1 month to establish
Cost
Internal time only
Done looks like
Bank reconciliation process documented; first month completed on schedule
5

Implement an expense and travel policy with defined limits, mandatory receipts, and a 30-day submission deadline. Reimbursements above the policy limit require CFO approval; above ₹50,000 require CEO approval.

Owner
CFO
Duration
1 week
Cost
Internal time; policy drafting only
Done looks like
Expense policy documented, communicated, and enforced
6

Conduct a surprise cash count and petty cash audit once per quarter. Rotate the person who performs the count. The purpose is not to catch fraud — it is to ensure that everyone knows a count could happen at any time.

Owner
CFO / internal audit
Duration
Ongoing
Cost
Internal time only
Done looks like
Quarterly surprise audit schedule established; first count completed

What you can do yourself vs what needs help

Steps 1–6 are executable internally by a competent CFO. If the CFO is new, or if the business has already experienced a loss or irregularity, an independent internal audit review — typically ₹50,000–₹1,50,000 for an SME — provides an objective baseline and is worth the cost.

Regulatory content verified 21 August 2026. Re-verify before acting on any threshold or compliance date.