Insights

The warning signs were there all along: lessons from preventable system failures

Advisory
By Satyam Saha – get in touch

People hear "audit" and think it is about the numbers. Honestly, that is the smaller part of the job. A financial system assessment is really asking one question the whole way through: can this system be trusted to catch its own mistakes, or is it only getting checked once a year, by us, after the fact. Those are very different situations, and most business owners never think about which one they are in until a system breakdown forces the question.

A case worth knowing about

There is a case the Serious Fraud Office prosecuted that is a good, real example of what we mean, and we keep coming back to it. Te Roopu Āwhina ki Porirua Trust, a charity doing social work with whānau and kids in Porirua, had a finance administrator who started part-time in 2019 and, over a couple of years, became the only person who really touched the money end to end. She raised payments, she approved them, she reconciled the accounts. By the time it was caught, she had moved $1.06 million into accounts she controlled, mostly by swapping her own bank details in for real suppliers' when payments went out. Some of it went on online gambling. She was sentenced last July to three and a half years in prison.

What gets us about that case is not the fraud itself, it is how ordinary the gaps were. There was a second person meant to sign off payments, but they were only checking the dollar amount, not whether the account number matched the supplier. Invoices were not always sighted before payments went out. Reconciliations lagged. None of that sounds dramatic on its own. Put together, and left to run for two years, it added up to a million dollars gone.

If one person can raise, approve and reconcile the same transaction with nobody else really looking, the business is relying entirely on that person's character. That is not a system. It is a bet.

Why this is a systems' problem, not a people problem

This is not really a story about a dishonest employee. Plenty of organisations have the exact same setup she was operating in, and most of the people in those seats never do anything wrong with it. The problem is the system does not know that in advance. A financial systems audit, done properly, is not there to catch bad people. It is there to check whether the structure around the money would hold up regardless of who is sitting in the seat.

What a systems' breakdown costs

On the operational side, the money is the headline, but it is not the whole cost. Once a business system failure like this surface, someone must go back through years of transactions and work out what happened, which eats weeks of management and board time that should have gone somewhere else. Funders start asking harder questions. Staff morale takes a hit, especially in a small charity where everyone knows everyone. And the controls that should have gone in calmly, well in advance, end up bolted on in a rush, mid-crisis, which is the worst time to design anything properly. For a charity specifically, the reputational damage outlasts the financial one by a long way. Donors remember.

Watch out for these warning signs

None of these need an accounting background to spot, and any board or business owner can check for them directly:

  • One person raises, approves and reconciles the same transaction, and nobody else routinely looks at that combination.
  • Whoever signs off payments is checking the amount but not who it is going to.
  • Reconciliations happen eventually instead of monthly, so it is worth asking when the bank reconciliation was last done. If nobody can answer quickly, that is worth following up on.
  • Payments get approved without anyone sighting the invoice.
  • Only one person understands how a process works, and there is no backup if they are away.

Building financial systems that hold up

None of this needs to be expensive, which is the bit people do not expect. Segregation of duties does not mean a big finance team. Even a small trust can split who raises, who approves and who reconciles, even if approving is just a board member doing a quick check once a month. A proper monthly reconciliation rhythm, and a simple rule that nothing gets paid without the invoice being looked at, closes most of the gap this particular case walked straight through.

For organisations where a full financial systems audit genuinely is not proportionate to their size, even a lighter independent review, or a trustee spot-checking transactions every so often, does most of the same job for a fraction of the cost. A periodic financial system health check, even an informal one, is often enough to catch what a once-a-year audit will not.

The Porirua case was not caught by an audit, it was caught after the fact. That is really the point we want to land. The system should be built to catch this kind of thing on its own, long before anyone has to.

Want a second opinion on your own systems?

If any of this has you wondering how your own business ororganisation would hold up, get in touch. A business systems review does not need to bea big undertaking to be worthwhile, and it is a great deal cheaper before something goes wrong than after.

You can read the Serious Fraud Office's full case study here.

Share this post

Advisory