BankChangeGuard
← All posts

An Internal-Controls Checklist for a Small Bookkeeping Firm

If you keep the books and pay vendors for clients on QuickBooks Online, a handful of basic internal controls prevent most of the expensive problems: payment fraud, duplicate or wrong payments, and the uncomfortable moment when a client asks how something got approved and you cannot show them. You do not need an audit department. This is a practical checklist for a small firm, with the reasoning behind each item. It is informational, not legal or accounting advice.

Why a small firm needs controls at all

It is tempting to think internal controls are a big-company concern. They are not. A solo or small bookkeeping firm often holds the two most dangerous keys a business has: access to the accounting system and the ability to move money to vendors. That is exactly the surface that both attackers and honest mistakes exploit. Clients are starting to ask how you protect it, and so are their cyber-insurers. A short, written set of controls is most of the protection, and it is the thing you can point to when someone asks.

The checklist

1. Separate who changes a payee from who releases the payment. The person who can edit a vendor's bank details should not be the only person who can send that vendor money. This is the single most important control, because it breaks the one-step path from a fraudulent change request to a completed payment. Even in a two-person shop, split "set up or change a vendor" from "approve or release the run." A solo bookkeeper can lean on the client as the second set of eyes for approvals.

2. Verify every vendor bank-change request out-of-band. When a vendor says their bank account changed, confirm it by calling a number you already had on file, never the number or reply-to in the email, and keep a record of what you checked. This stops the most expensive single loss a bookkeeper faces. (More on the patterns in the vendor-impersonation post, and the QBO steps in the verification how-to.)

3. Set an approval threshold and write it down. Decide a dollar amount above which a payment needs a second approver, and put it in a one-page procedure. Undocumented judgment is not a control; a written rule that anyone can follow is.

4. Give everyone their own login, and turn on MFA. No shared QuickBooks Online credentials. Each person has their own user with the access they actually need, multi-factor authentication is on, and access is removed the day someone leaves. Your QBO login and your email are the two keys to the kingdom; protect both.

5. Keep a real audit trail. Maintain a contemporaneous record of who did what and when, in something more durable than a memo field. A note you can edit later, with no record of who wrote it, is not evidence. (See what counts as a defensible record.)

6. Reconcile every month. Reconcile bank and credit-card accounts monthly, without exception. Unreconciled accounts are where both honest errors and quiet fraud hide; reconciliation is the routine that surfaces them.

7. Write the process down and back it up. Document your procedures so they survive a staff change or a sick week, and keep your records backed up. A control that lives only in one person's head fails the moment that person is unavailable.

You do not have to implement all seven at once. Start with the first two, which cover the highest-loss scenarios, and add the rest over a few weeks.

Where this fits with Nacha Phase 2

A line of context, since clients ask: Nacha's Phase 2 fraud-monitoring rule, now in effect, expects firms that originate ACH (including through QuickBooks Online Bill Pay) to run a documented, risk-based process for catching payments initiated by fraud. The rule does not mandate specific steps or certify any tool. The controls above, plus the records that show you follow them, are how a small firm demonstrates a reasonable process. Informational only; confirm specifics with your bank and CPA.

FAQ

I'm a solo bookkeeper, can I really separate duties?

Partly, and that is enough. You can route approvals to the client for sign-off, or document a deliberate second look before releasing anything over your threshold. The goal is not a big team; it is removing the single, unchecked path from a change request to a sent payment.

What is the single highest-impact control?

Out-of-band verification of vendor bank-change requests, with a kept record. It addresses the most expensive single loss a bookkeeper is exposed to, and it costs nothing to do by hand.

Do I need software for any of this?

No. The whole checklist works manually. Software only helps with the parts that are easy to let slide, like keeping a tamper-evident record of each vendor bank-change. BankChangeGuard automates that one step for QuickBooks Online shops; it does not move money, approve payments, or make anyone "Nacha-compliant," and the decision to release a payment stays with you and your bank.