Where treasury policies and procedures break down

This process usually breaks where a policy changes hands. Approved policy rarely reaches the procedure desk intact. Bank and system access drift from what the policy allows. Urgent payments bypass the documented route, and audit findings close on paper without changing daily work. Each leaves a visible trace.

Policy approved, procedure left behind

A finance committee approves a policy. Counterparty limits tighten, or a new approval threshold appears. The document is published and everyone assumes the desk has absorbed it.

Often nobody has rewritten the step-by-step procedure. The treasury system still holds the old limits, and work carries on as before.

How to tell: compare the policy's effective date with the last edit date on each procedure. Pull limit settings from the treasury management system and from each bank portal. Read them against the approved policy text. Mismatches here are common and seldom raised, because the old settings still let payments flow.

Scope that stops at head office

Governance documents often name treasury as owner of every bank relationship. Subsidiaries and project teams still open accounts locally, sometimes with signatories who have never read the policy. These accounts sit outside monitoring until a balance surfaces in consolidation or an auditor's bank confirmation.

What gives it away: reconcile the treasury account register against bank confirmations and the ledger's chart of accounts. An account that appears in only one place marks a gap in scope.

Controls split between treasury and IT

On paper, treasury defines system security requirements. Someone else implements them, usually IT or the bank administrators. Entitlements on bank portals are the weak point.

A person changes roles and keeps the ability to release payments. A temporary administrator becomes permanent. Dual authorisation gets switched off during an outage and nobody switches it back on.

Where to look: request the user entitlement report directly from each bank, not from internal records. Search for anyone who can both create and approve a payment, and for leavers who still hold access. Check for shared logins as well. If the access review is signed by someone who cannot read the bank's report format, the control exists in name only.

The urgent payment route

Every treasury has an exception path for payments that cannot wait. Late tax payments and intercompany funding requested by phone are typical. The path is meant to be rare. Over time it becomes the normal channel for anyone who missed a cutoff.

The real exposure is beneficiary set-up. Payee details added under pressure skip the independent callback that the procedure requires. Fraudulent requests to change bank details aim at exactly this gap.

Evidence: review how often payments are flagged as urgent and who asks for them. A small group of repeat requesters points to a planning problem upstream of treasury. Then check whether beneficiary records created on the same day as their first payment carry proof of a callback.

Monitoring that never feeds revision

Monitoring, audit and revision are separate steps with separate owners. Internal audit raises a finding. Treasury agrees an action. The action is marked closed once a memo exists, whether or not the procedure changed.

Cycle memos written for external auditors make this worse. They describe how the work should run, and the same text gets reused each audit cycle long after practice has moved on.

Warning signs: trace a closed finding to the procedure it was meant to change. Unchanged procedure text means the finding was closed administratively. A scramble whenever auditors send their request list is another clue. Staff rebuilding evidence that should already exist shows controls are performed but not recorded.

Spreadsheets that hold the real rules

Cash positioning and limit monitoring frequently live in a workbook owned by one analyst. Its formulas encode the actual policy, including thresholds nobody approved. Bank-to-ledger reconciliation may run there too, with unexplained differences carried forward under a plug line.

What to check: ask for the file used to make the daily funding decision. Look for hardcoded limits and for reconciling items with no explanation of their age. If only one person can explain the workbook, the procedure depends on that person being in the office.

Questions to ask the people who run it

Documented procedures describe intent. These questions surface what actually happens.

  • When a payment has to go today and the approver is unavailable, what do you do?
  • Who told you about the last policy change, and how did you hear?
  • Which bank portal settings have you asked IT or the bank to change? Did anyone check the change against policy?
  • What do you keep in your own files because the system cannot hold it?
  • Which audit finding did you fix, and which one did you only document?
  • If you were away, which part of this would stop?
  • Where do you override a system warning, and does anyone review those overrides?
  • Are there bank accounts you know about that treasury does not manage?

Answers that hesitate, or that differ between colleagues on the same desk, usually point straight at the break.

Sources

APQC's Process Classification Framework® (PCF) is an open standard developed by APQC, a nonprofit that promotes benchmarking and best practices worldwide. To download the full PCF or to view definitions and measures, please visit www.apqc.org/pcf.