Designing Approval and Document-Retention Systems for SMEs
Approval and retention systems fail in smaller businesses for opposite reasons. Approval is usually designed too elaborately to survive contact with a small team. Retention is usually designed too casually to survive contact with a reviewer.
Approval: proportionate, not elaborate
The objective is narrow and worth stating precisely: no single person should be able to initiate, approve and record the same transaction without any independent check. In a team of six that rarely means layers of sign-off, which will be bypassed within a month. It means a defined threshold above which a second person approves, and a specific set of high-risk changes that always require verification regardless of value.
Three changes account for a disproportionate share of loss in small businesses: supplier banking-detail changes, payroll additions and amendments, and the creation of new suppliers. Each is a low-volume, high-consequence event, and each is a standard route for both external fraud and internal misappropriation.
A workable matrix
- Routine operating payments below a set threshold — one approver, with the full run reviewed in aggregate monthly rather than line by line.
- Payments above that threshold — two approvers, one of whom did not capture the transaction.
- Any change to supplier or employee banking details — independently verified against a previously known contact, never against details supplied in the request itself. This single control defeats the most common invoice-redirection fraud.
- New supplier or employee creation — approved separately from, and before, the first payment to them.
- Journals affecting a closed period — approved with a documented reason, or not permitted at all.
Five rules, each expressible in a sentence. A matrix that cannot be described to a new employee in five minutes will not be followed.
Retention: design to the binding clock
Retention should be built to the seven-year Companies Act obligation under sections 24 and 25 rather than the five-year tax period under section 29 of the Tax Administration Act, because the longer requirement governs where both apply — the position set out under missing source documents and audit exposure.
Two refinements matter. The tax clock runs from the date the return was submitted rather than the year-end, so late filings extend the obligation. And section 32 requires records relevant to an audit, investigation, objection or appeal to be kept until that matter concludes — which means any destruction schedule needs a hold mechanism tied to open matters, or the policy itself becomes the risk.
The design question is retrievability rather than storage. Section 30 requires records to be kept in an orderly fashion, and the practical test is whether a specific document from four years ago can be located within a verification response window without a reconstruction exercise. Filing by period and counterparty achieves this; filing by whoever happened to receive the document does not.
Why the assurance threshold shapes the design
What the evidence must withstand depends on the company's public interest score, calculated under the Companies Regulations from turnover, third-party liabilities, average employee numbers and the number of holders of a beneficial interest in its securities.
Broadly: a score of 350 or more requires an audit. Between 100 and 349 the requirement depends on whether the annual financial statements were independently compiled — internally compiled statements attract an audit, independently compiled ones an independent review. Below 100 an independent review generally applies, with a possible exemption where the company is owner-managed, meaning every shareholder is also a director.
The design consequence is that a business approaching a threshold should build its evidence standard for the tier it is entering, not the one it is leaving. The score moves with headcount and turnover, so a growing business can cross into an audit requirement in a year in which nothing about its record-keeping changed — and discover it after the year has closed, when the evidence for that year is already whatever it is.
Sector considerations
Headcount is a component of the score, which has a particular effect on labour-intensive models. A construction business with substantial project-based labour, or an agricultural operation with large seasonal workforces, can accumulate public interest score points from employee numbers alone without any change in turnover — and may find itself in a higher assurance tier than a more profitable but leaner business.
Dispersed operations also make the approval matrix harder to enforce, because purchasing happens away from the finance function. In those environments the threshold-based rules matter less than the absolute rules: banking-detail verification and new-supplier approval should apply everywhere, without a value threshold, precisely because the sites where they are hardest to enforce are the sites where they are most needed.
Making it hold
Systems fail on maintenance rather than design. Three practices keep them alive: review the matrix annually against actual payment patterns rather than assuming last year's thresholds still make sense; test the retention system by asking someone to retrieve three specific documents from three years ago and timing it; and recalculate the public interest score each year before year-end rather than after, while there is still time to act on the answer.