← All postsHow-to

Payment approval: who signs off, at what amount, and how to keep it quick

Payment approval is the last control before money leaves. It has to be strict enough to stop the one bad payment and light enough that the other four hundred go out on time.

How-toP

Payment approval is the checkpoint between an invoice arriving and money leaving the account. Small companies often run it informally — the founder looks at the bank screen once a week — and that works right up until it doesn't: a duplicate invoice paid twice, a supplier's bank details changed by someone who is not the supplier, a subscription still billing eighteen months after the project ended.

The point of a written payment approval rule is not bureaucracy. It is that fraud and error both rely on a single person being able to originate and release a payment without anyone else looking. Separate those two acts and most of the risk goes away, at a cost of a few minutes a week.

The three checks a payment approval should make

  • Is it owed? A purchase order or an agreement, a delivery that actually happened, and an invoice whose amount matches both. This is the classic three-way match, and it catches nearly all honest errors.
  • Is it new? Same supplier, same amount, similar date is the signature of a duplicate — usually a re-sent invoice paid twice, occasionally something worse.
  • Is it going to the right account? Bank details on an invoice are not evidence. Any change of payee details gets verified out of band, by calling a number you already had, never one printed on the invoice.

Payee-detail fraud is now the most common way small companies lose four figures at once. The email looks right, the invoice looks right, the IBAN is one the attacker controls. A single rule — new or changed bank details are confirmed by voice on a previously known number, without exception and regardless of urgency — prevents almost all of it.

Setting thresholds people can remember

  1. Below a small amount, the budget owner alone releases it. Recurring, contracted, unchanged — no second pair of eyes needed.
  2. Above that, two people: the person who requested it and someone who did not. Preparer and approver must never be the same person, whatever the amount.
  3. Above a larger amount, or for anything outside the approved budget, a director approves and the reason is written down in one line.
  4. New suppliers get onboarded once — details verified, records kept — rather than checked at payment time when everyone is in a hurry.
  5. Pay on a published run, weekly or fortnightly. A fixed run is what stops "urgent" from being the default routing.
  6. Reconcile the run against the bank the next day, because approval that is never checked against what actually left is not a control.

Two thresholds and one absolute rule are usually the whole policy. Any more and people stop being able to recite it, which means they stop applying it consistently, which is the same as not having it.

Keeping payment approval fast

Speed comes from batching, not from cutting checks. One payment run a week, prepared in one sitting, approved in one sitting: the approver sees a list with supplier, amount, what it is for, and whether anything changed since last time. Approving twenty payments in a batch takes about as long as approving three ad hoc ones, and it is more accurate, because differences stand out against the previous run.

The other half is being a good payer. Approval delays cost supplier goodwill, and suppliers who expect delays quote higher or ask for prepayment. Publishing your payment terms internally — approved by Wednesday, paid Friday — turns chasing into arithmetic.

Where Ettex fits

On the receivable side, Ettex Invoices keeps every invoice at a status you can see at a glance — draft, pending, paid, overdue, cancelled — with a responsible person on each one, which is what makes a weekly review possible rather than an archaeology exercise. Requests to pay something can be collected through Ettex Forms so they arrive with the fields your approver needs instead of as a forwarded mail, and the policy itself lives in Ettex Docs where the version that is current is unambiguous.

To be clear about the boundary: Ettex does not connect to your bank, does not release payments, and has no built-in two-person authorisation on a payment run — the release itself happens in your bank or accounting system, which is where dual authorisation belongs. What Ettex holds is the paperwork and the status around it.

Common failures

  • The same person prepares and releases. Everything else in the policy is decoration if this is true.
  • Approval based on the invoice alone, with nobody confirming the goods or work arrived.
  • Bank details updated from an email request. This is the expensive one.
  • No supplier list, so nobody notices a payee that has never been paid before.
  • Subscriptions on a card that renew without ever passing through approval again — worth an annual review of everything recurring.
  • Approvals recorded nowhere, so the audit question "who authorised this" has no answer.

Frequently asked

What is payment approval?

The authorisation step before money is released: confirming the payment is owed, is not a duplicate, and is going to the correct account, by someone other than the person who prepared it.

Who should approve payments in a small company?

Anyone accountable for the budget, provided they did not raise the request themselves. The separation matters more than the seniority — a founder approving their own reimbursements is the same gap as anyone else doing it.

What threshold should require a second approver?

Low enough that a single mistaken payment cannot hurt, high enough that routine small payments flow. Many small companies set it near a week of operating cost, then adjust once they see how many payments clear the bar.

How do you prevent invoice fraud?

Verify any new or changed bank details by voice on a number you already held, never one from the invoice or email. Match invoices to an order and a delivery, and treat urgency as a warning sign rather than a reason to skip a step.

Is a purchase order required before approving payment?

Not for everything, but for anything above your second threshold it is the cheapest evidence that the spend was agreed before it happened rather than justified afterwards.

How often should payments run?

Weekly or fortnightly on a published day. A fixed run improves accuracy, makes approval a single task, and lets you tell suppliers when to expect money.

Payment approval earns its keep on the one payment a year it stops. Two thresholds, never the same person twice, and bank details verified by voice — the rest is making the weekly run boring enough that nobody wants to skip it.

MI
Written by Maria I.

Part of the Ettex team — writing about product, engineering and the future of work.

More posts
Get the best of the Ettex blogProduct news, guides and tips — straight to your inbox, no spam.