The Minimum Viable Control Environment: Cash Controls for a Startup With No Finance Team
Founders tell me controls are for later — for when there is a finance team, an audit, a board that asks. In practice the duplicate payment, the supplier email announcing new bank details, and the contractor still on payroll three months after leaving all arrive before the finance team does. This is the smallest set of cash controls I put into a company that is too small to have anyone whose job this is: what each one is for, what it costs, and where founders push back.
I trained as an auditor at KPMG, which meant five years reading control matrices written for companies with thousands of employees, followed by fifteen years in companies where the entire finance function was, for long stretches, me. The useful discovery from doing both is that the principles scale down far better than the paperwork does. What a large company achieves with a forty-page policy, a ten-person company can achieve with five rules and one page — provided the five are the right ones and nobody adds a sixth too early.
The founder objection is always the same, and it is usually phrased as a statement about trust: we are eight people, we all know each other, nobody here is going to steal. That is probably true, and it is beside the point. Almost none of the money I have watched small companies lose was taken by an insider. It went out through a duplicate invoice paid by two people who each thought they were the only one handling it; through an email from a supplier's hijacked mailbox announcing a new bank account; through a subscription that renewed for a full year at a tier nobody used; through a contractor whose invoice kept getting approved by habit long after the work had stopped. Each item was small. At one company they added up to most of a month of runway — found during the reconciliation audit I described in the first ninety days of an engagement, because until then nobody had been positioned to notice.
A control is not a statement about whether you trust someone. It is a decision about what happens by default when that person is tired, travelling, or looking at the wrong tab.
What "control environment" means at eight people
In audit language, the control environment is everything that determines whether the numbers a company produces can be relied on: who can commit money, who can move it, who checks, and what happens when the check fails. In a large company that is a department. In a small one it is a handful of defaults set once in the bank, the card platform and the payroll tool, plus one page saying who does what. The question is never whether to have controls — every company has them, in the sense that something happens by default when an invoice arrives. The question is whether anyone chose the default.
The test I apply is short. If the founder were unreachable for two weeks, could money leave the company, and would anyone know? If the answer to the first question is no, the company stops paying its bills the moment the founder boards a long flight. If the answer to the second is no, the company has a problem it has not met yet. A working control environment lets money move without the founder and makes every movement visible to someone who did not initiate it. Five controls get a ten-person company there.
The five controls
1. Two people between an invoice and a payment
The oldest idea in the discipline is segregation of duties: the person who approves a purchase is not the person who pays it, and the person who can add a new payee is not the person who approves invoices to that payee. In a corporation this takes three departments. In a startup it takes two people and a setting. Most business banks and every serious payment platform can require a second approver above a threshold — the founder approves and someone else releases, or the reverse. Below the threshold the budget owner pays alone, because a control that touches every twenty-dollar payment gets switched off within a month.
The exact threshold matters less than the fact that one exists. Set it where roughly nine payments in ten go through untouched and the tenth is the kind you would want to see anyway. A three-line approval matrix — who approves what, up to how much, and who releases — is the whole policy. When someone proposes a five-level approval chain for a company of ten, I ask what the fourth level would catch that the second did not. There has never been a good answer.
2. Bank details change by phone, never by email
Business email compromise is the most common way I have seen a small company lose a five-figure sum, and the mechanism is dull. An email arrives from a supplier — frequently from the supplier's real mailbox, which has been quietly taken over — explaining that they have changed banks and asking that the next invoice be paid to the new account. Everything about it looks right: the thread history, the signature, the invoice number. Someone updates the payee, and the supplier calls a month later asking where their money is. By then it is gone.
The control costs one phone call. Any change to a payee's bank details is confirmed by calling a number the company already had on file — from the contract, from an earlier invoice, never from the email announcing the change — and whoever makes the call notes who they spoke to. New payees get the same call before the first payment. That is the entire rule, and it blocks the single largest category of loss I have encountered at companies of this size. It also runs in the other direction: send your own bank details to customers through a channel you control, and tell them you will never change those details by email.
3. Every card has an owner and a limit
A shared card number stored in the team password vault is the most common way spend becomes untraceable. Nobody knows which of the fourteen subscriptions on the statement is still used, and the annual renewal for the design suite went through last week at a tier bought for a team that no longer exists. The fix is structural rather than disciplinary: one card per person, a virtual card per vendor for recurring charges, a monthly limit on each that matches what the tool actually costs, and a register — a spreadsheet is fine — listing every subscription with its owner, renewal date and cost.
This is also the cheapest cost review a company can run. The first time a client builds the register, the exercise usually pays for itself the same week: duplicated tools, seats for people who have left, plans one tier above usage. The limit on each card is what keeps it that way. The surprise renewal simply declines and the owner has to ask for it, which is the moment the question "do we still need this" finally gets asked.
4. Payroll is reconciled by someone who did not run it
Payroll is the largest payment a startup makes and the one least often checked, because the tool runs it and the tool is trusted. The control is a monthly reconciliation done by someone other than whoever ran it: the number of people paid equals the number of people employed; every new starter, leaver and pay change ties to a written document — an offer letter, an amendment, a termination date; and total payroll agrees to what left the bank. At ten people this takes fifteen minutes. The phantom employee of audit folklore is rare at this size. The contractor who kept invoicing for two months after the project ended, and whose invoices kept being approved because they always had been, is not rare at all.
The same reconciliation is what makes the headcount plan honest. The committed-payroll figure a founder quotes to investors is only as good as the payroll register behind it; if the register and the org chart disagree, the runway number is wrong in a direction nobody has checked.
5. The bank is reconciled monthly, and someone reads the exceptions
The bank reconciliation is the master control, the one that catches whatever the other four missed. Every transaction in the bank account is matched to an entry in the ledger; whatever does not match is listed, explained, and cleared within a defined period. Most companies I meet do the matching, or their bookkeeper does. Far fewer have anyone reading the list of items that did not match — which is where the duplicate payment, the unrecognised debit and the customer payment that never arrived actually show up. Matching is mechanical. Reading the exceptions is the control.
The rule I set is that any unexplained item older than thirty days goes to the founder by name, in writing. At a healthy company the list is often empty, but its existence changes the behaviour of everyone upstream, because they know the item will surface with their name attached.
Everything above fits on a single page: who can add or change a payee, who approves spend and up to what amount, who releases payments, who owns each card and its limit, who reconciles payroll and the bank, and who receives the exceptions. The founder signs it, it lives next to the cap table, and it gets rewritten when headcount doubles or when the first person who is not a founder is given payment authority. If it no longer fits on one page, it has been over-built.
What it costs, and what it does not
Setting this up is a day or two of work, most of it configuration in tools the company already pays for: the bank's approval rules, the card platform's virtual cards and limits, the payroll tool's audit export. Running it is two to three hours a month, most of which is the bank reconciliation that should be happening regardless. When someone proposes a spend-management platform to a ten-person company, the question is which of the five controls it delivers that the bank and a spreadsheet do not. The honest answer is usually convenience, which is worth paying for later and not yet.
What it does not cost is speed. The claim that controls slow a startup down is true of the wrong controls and false of these. A threshold set correctly leaves most payments untouched; the phone call to confirm bank details takes five minutes and happens a few times a year; the card limit only bites when something unexpected happens, which is the point. The founder who spends a Saturday untangling a card statement before a raise has paid far more in time than the controls would have cost.
The failure on the other side is worth naming, because I am prone to it myself. The audit instinct is to install the corporate framework — approval chains, policy manuals, quarterly attestations — into a company of eight. The result is predictable: it is ignored within a quarter, and an ignored control is worse than none, because it creates the appearance of a check nobody is performing. The discipline is to choose the five that matter and resist the sixth until the company has grown into needing it.
When to add the next layer
The minimum set is designed for a company where the founder still sees most of what happens. It stops being enough at recognisable moments. The first is when someone who is not a founder is given authority to approve spend: the matrix acquires a second line, and the founder moves from approver to reviewer. The second is the first institutional round, which usually brings a shareholders' agreement with reserved matters — spend above a stated amount, new debt, hires above a salary level — that require board or investor consent. A company that already has thresholds and a written matrix turns that into a routine; one that does not turns it into a monthly scramble. The third is headcount somewhere past twenty-five, where the founder no longer recognises every name on the payroll and the payroll reconciliation moves from formality to necessity.
Two situations sit outside the minimum altogether. A company that holds or moves customers' money — a marketplace, anything with payments inside the product — needs a control environment designed for that from the first day, because the money at risk is not its own. And a company with subsidiaries or several currencies has intercompany and treasury questions a one-page matrix does not answer. Both are visible well in advance, and both are the point at which finance leadership stops being optional.
What this is actually for
Investors reading a data room check whether the financials reconcile to the bank and whether the cap table reconciles to the underlying documents, and they check early because it tells them how the company is run. The five controls above are the reason the answer is yes. They are also why, when the founder is on a plane for two weeks, suppliers still get paid, nothing leaves the account unseen, and the question "how did that get paid" always has an answer with a name on it.
That is what a control environment is for at any size. At eight people it fits on one page, costs a couple of hours a month, and gets cheaper the earlier it is built — every month it is postponed adds another month of transactions someone will eventually have to reconstruct.