"I'm not sure."
If there's one phrase I listen out for in a conversation with a founder, it's that one.
Founders are usually sure of most things within their control — almost all, I dare say. Some are legit control freaks and others aren't, but they all love to have a high degree of control or surety over operations, over risks, over finance. So when a founder isn't sure of something, it signals a significantly higher degree of discomfort, stress, distrust or worry. That's what keeps them on their toes, and it's what saps restful sleep from them.
More often than you'd expect, the thing they're not sure about is their own cash.
The Most Boring Control Failure Is the Most Common One
The control failure I see most often isn't dramatic. It's a lack of oversight over bank reconciliation and cash management.
That covers more ground than it sounds: petty cash, corporate and personal credit cards, banking controls (eg. who holds the token, who has which access rights, whether there's any maker-checker arrangement at all), and the overall controls over how cash flows into and out of the business.
Cash is the lifeblood of any business. Running one without controls and oversight over cash is akin to running around, oblivious of a bleeding artery.
It's boring because you'd think these are pretty basic controls. Indeed they are. But it's precisely because they're boring that they are the most overlooked, and the most critical, controls for ANY business — not just an SME.
What It Looks Like When a Big Company Does It
Think about this from the perspective of an MNC for a moment.
The number of controls they have over the cash process is insane. (You can think of controls as gates, or locks.) Before any transaction can take place, it first goes through a procurement process involving KYC checks (know your customer, or in this case vendor), legal and financial due diligence, followed by multiple quotations, then internal budget checks, then multiple levels of sign-off from a cross-functional team — procurement, legal, supply chain, finance, and the business or budget owner.
Sometimes it feels like going through airport security, where your passport gets man-handled at least three to five times between entering the departure gates and reaching your seat.
However, there is one upside to all that seeming inconvenience: scrutiny. Scrutiny by multiple eyes, from multiple independent parties, to cut the risk of fraud or error to the absolute minimum.
Take note that these controls don't prevent fraud or error 100%. Nothing does. But they do perform a detective and corrective role that reduces how often it happens.
Preventive, Detective, Corrective
Preventive, detective, corrective is a mantra I learnt during my accounting degree, and it has stuck with me ever since — especially during my audit days at KPMG.
To someone who's never worked in finance, it can be explained with a simple analogy.
Imagine you are back in your primary school days. Before you leave for school, your mother says, "please don't forget to bring your water bottle!" As you begin to close the door behind you, your mom spots your water bottle on the floor, which you must have left behind while you were putting on your shoes. Your mom catches the door with her hand and says, "here! You almost forgot your water bottle again!", puts it in the side pocket of your bag, and pinches your cheek as a little reminder not to do it again.
Your mom has just played all three types of control. First preventing (the reminder), then detecting (spotting the bottle on the floor), and finally correcting (putting it in the right place for you, with the pinch on your cheek).
A business works exactly the same way.
Where I Start
Early in an engagement, I focus on securing financial controls first, followed by data integrity.
Financial controls over banking and cash management keep the risks of fraud or error to a minimum. Approval flows and matrices, sign-offs and evidence of review are critical in understanding how diligently a company takes its compliance. From an audit perspective, strong internal controls are a good sign of corporate governance, and this is the message I always share with founders, even if they are at a nascent stage of growth.
Data integrity means ensuring the data that flows from other departments into one central place is clean and ready for insight generation. Sometimes there isn't an existing data warehouse, and it has to be built. The good thing is that SMEs don't need a sexy ERP system to make this work. Multiple databases can be stitched together with simple, low-cost tools, especially in the age of AI, so there's no need to pay for high-end productivity suites such as Tableau or Anaplan. The controls over data integrity ensure that data is collected, sanitised, and in the right format for dashboarding or basic analysis.
Without effective controls and clean data, Finance is useless to the business, because the numbers cannot be trusted. So these two come first in every engagement.
The One Founders Push Back On
Maker-checker is the control founders push back on most. (One person prepares the payment; a different person checks and approves it.)
The pushback usually comes from very new businesses that don't have enough staff to even execute a maker-checker arrangement — think of a founder who wears both the Finance and the HR hat, without the budget yet for an in-house accountant.
Where a business does have the staffing but is reluctant anyway, I emphasise the risk of fraud and human error, which can happen to anyone. It isn't an accusation. It's simply how people work.
Where staffing is a real constraint, I suggest instituting a redundancy check instead — for example, building a skill via AI that does a first pass over the transactions and flags discrepancies and errors before the founder approves. It mimics an extra pair of "eyes", which is most of what maker-checker is there to provide.
Where I Deliberately Stop
I'm practical, and I'm always concerned about the cost versus benefit of implementing controls.
If the risk you're trying to prevent has a maximum financial or reputational damage of, let's say, $10,000, then the time and effort your team spends reducing that risk should be but a fraction of the monetary risk.
This is where copying an MNC goes wrong. If a control requires multiple stakeholders to spend hours each on detailed KYC reviews, third-party due diligence and getting three or more quotes — including the turnaround time for queries between vendor and procurement, and then the legal and finance discussions — the cost of the control itself may run to thousands per transaction. That's not feasible for an SME. It may well be necessary for an MNC, because they have the financial capacity to absorb those man-hours, and oftentimes the financial or reputational damage if anything goes wrong is ten times higher than an SME's.
So the question is never "what would a big company do?" It's "what is this risk actually worth, and what is it worth spending to reduce it?"
Back to "I'm Not Sure"
When I hear a founder say "I'm not sure", I pick it up as a call to address that lack of clarity and confidence — to restore something like the peace and calm they had before.
I do so with data, trends and intelligence, collected and processed to deliver insights and courses of action which mitigate risks and allow founders to weigh their options.
That part comes from my S2 (intelligence officer) training. I never give the commander the answer directly, even if it's obvious to me, but lay out the options carefully before him so that he can choose based on his personal considerations, his experience and his gut.
Controls and clean data are what make that possible. They don't make the decision for a founder. They make sure that when the founder does decide, they're sure of what they're looking at.
And that, more than anything, is what lets them sleep at night.
If there's something in your business you're not sure about, that's what the first conversation is for.