No Per-User Pricing!

Scale your entire team without your software bill going up. Flat-rate means you pay one price, no matter how many users you add.

Back to Knowledge Base Complete Guides

Internal Controls for Approvals: The Complete Guide (2026)

Internal controls for approvals are the mechanisms that ensure no single person can commit an organization's money or authority alone: segregation of duties, authorization limits, verified payee data, documented evidence, and independent review. This guide covers the complete framework — the five core controls, how they map to COSO and SOX expectations, why they fail in practice, and the difference between controls that live in a policy document and controls the software makes impossible to bypass.

Every payment error, fraud case, and failed audit finding traces back to one of two roots: a decision one person made alone, or a decision that left no evidence. Approval controls exist to break both failure modes. For the general workflow framework, see Approval Workflows: The Complete Guide; for the AP-specific application, Accounts Payable Approval: The Complete Guide. This guide is the control layer underneath both.

What are internal controls for approvals?

Internal controls are the policies, procedures, and system-enforced rules governing how decisions get made and recorded. For approvals, they answer three questions: who is allowed to decide what, what proves the decision was made, and who else checked.

Controls pursue three objectives simultaneously: prevent honest errors (wrong amounts, wrong payees, duplicates), prevent fraud (one-person schemes, diverted payments), and preserve evidence (the record an auditor, lender, or court can rely on later). A control that achieves one and not the others is half a control.

Preventive, detective, and corrective controls

Every approval control falls into one of three types — strong processes use all three layers, because preventive controls always leak something.

Type Job Approval examples
PreventiveStop it from happeningSegregation of duties, approval matrix, vendor verification, mandatory routing
DetectiveCatch it when it happensThree-way match, duplicate detection, exception aging, periodic review
CorrectiveFix it and keep the evidenceException handling, revocation with the trail preserved

The five core approval controls

1. Segregation of duties

No single person holds two conflicting powers: the requester never approves, the approver never pays, the person who adds a vendor never approves it. Collusion requires two people, and two-person schemes are dramatically rarer, riskier, and easier to detect than one-person ones. The complete guide: Segregation of Duties in Accounts Payable.

2. Authorization limits (the approval matrix)

Decision rights scale with risk: small amounts need the department head, large commitments need finance and the CFO. The matrix is the rulebook; the workflow is the enforcement. Template included in What Is an Approval Matrix?

3. Payee verification

You pay who you believe you're paying. New vendors enter the master file only through a verification queue, and payment data is pulled from verified records — never typed from an invoice, which is precisely where fraudsters edit it. The twelve-control version: How to Prevent Vendor Fraud.

4. Evidence and documentation

Every action — submission, approval, rejection, revocation, comment — is attributed, timestamped, and tamper-evident. A trail an administrator can edit is a log, not evidence. How the strongest implementations work: Unbroken Audit Trails.

5. Monitoring and review

Controls age. Thresholds drift, exceptions accumulate silently, new categories appear with no owner. Someone must periodically review what's pending, what's aging, and what changed — a control that nobody watches quietly stops being a control.

What auditors actually test (COSO and SOX, in plain terms)

The COSO framework — the basis of most internal-control regulation — defines five components: control environment, risk assessment, control activities, information and communication, and monitoring. Approval matrices and segregation of duties are control activities; your audit trail is information; your reviews are monitoring. SOX formalizes this for public companies; private companies meet the same expectations through lender covenant reviews, investor due diligence, and external audits.

Auditors test two things about every control: design (does the control exist and does it address the risk) and operating effectiveness (did it actually operate all year). Operating effectiveness is tested by sampling transactions and tracing evidence. An approval control without an evidence trail fails operating effectiveness by default — the rule existed, but nobody can prove it was followed.

How approval controls fail in practice

  • Override under pressure. "Just this once" approvals under deadline are how controls erode — each exception makes the next one easier.
  • Drift. A $5,000 threshold set three years ago is a different control today. Nobody scheduled the review, so it never happened.
  • Evidence gaps. Verbal approvals, hallway sign-offs, deleted email threads — the decision happened; the proof didn't.
  • Single-point dependency. One approver for everything creates the bottleneck and the fraud risk in the same person.
  • Policy-only enforcement. The control exists in the PDF, not the process. Auditors test the process.

Policy controls vs structural controls

The distinction that decides whether controls survive contact with a busy month: a policy suggests; a structure enforces.

Control Policy version Structural version
Segregation of duties"Requesters shouldn't approve their own requests"The system never shows the requester the approve button
Approval matrixA matrix in the policy folder$60K physically cannot skip the CFO stage — routing is automatic
Vendor verification"Finance should verify new vendors"New payees wait in a queue; the master file accepts nothing unverified
Evidence"Keep the approval emails"Hash-chained trail no one can edit — including administrators
Corrections"Ask IT to fix it in the database"Revocation appends a correction; the original record stays — see Smart Revoke

Controls fail in busy months, not quiet ones. The structural versions hold precisely when attention is elsewhere — which is the only time controls are actually needed.

How to choose software that enforces controls

  1. Does it enforce segregation of duties, or merely permit it? Look for role-based access where conflicting powers are structurally separated.
  2. Are authorization limits configurable per amount, category, and department — and enforced by routing, not by memory?
  3. Can the audit trail be edited or deleted by anyone? Ask this one directly. The answer separates evidence from logs.
  4. Are corrections recorded, not overwrites? Mistakes happen; the question is whether fixing them destroys the record.
  5. Is there a vendor approval gate before the master file accepts a new payee?
  6. Is the evidence exportable — grouped by request, showing who, what, when, and at which stage?
  7. Is two-factor authentication mandatory rather than optional?
  8. Are exceptions visible and aging — or silent until they become audit findings?

Frequently Asked Questions

What are internal controls for approvals?

The mechanisms ensuring no single person can commit an organization's money or authority alone — segregation of duties, authorization limits, payee verification, documented evidence, and monitoring.

What is segregation of duties?

Splitting a process so no one person holds two conflicting powers — the requester never approves, the approver never pays, the vendor-adder never approves the vendor. See the complete guide.

Are approval controls required by law?

Directly for public companies under SOX. For private companies: expected by external auditors, frequently required by lender covenant reviews and investor due diligence, and enforced in practice by every serious customer's procurement process.

What is the difference between preventive and detective controls?

Preventive controls stop the error or fraud before it happens (segregation, routing, verification). Detective controls catch it after (three-way match, duplicate detection, review). Every process leaks — the detective layer is what catches the leak.

How do you enforce segregation of duties in software?

Role-based access control that structurally separates the powers: users who can submit cannot approve their own requests, users who approve cannot execute payment, users who add vendors cannot approve them. The system makes the violation impossible rather than prohibited.

Approvdit enforces the structural versions of all five controls — role-based segregation, matrix-driven routing, a vendor approval gate, and a hash-chained audit trail no administrator can edit. Book a live demo to see each control running.