A cash internal controls checklist is the working list of procedures a business uses to keep money from being stolen, miscounted, or moved without authorization. The controls that matter fall into a small number of categories: separating who does what, locking down the ways cash comes in and goes out, reconciling the books independently, restricting who can touch the financial system, meeting the IRS reporting rules that apply to large cash payments, and carrying insurance for the losses that slip through anyway. Work through the sections below and treat any item you can’t tick off as an open exposure.
Segregate Incompatible Duties
Every other control on the list depends on this one. Three functions have to sit with different people: authorizing a transaction, handling the cash or payment instrument, and recording the entry in the books.1Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet When one person controls two of them, they can invent a transaction, take the money, and hide it in the ledger. Authorization means approving a purchase order or signing a payment. Custody means physically receiving cash, holding checkbooks, or logging into the bank portal. Record keeping means entering the transaction into your accounting system.
Small offices push back that they don’t have the staff. The fix is usually to pull the owner or an outside bookkeeper into one of the three roles. A part-time outside accountant reviewing bank statements and reconciliations creates independence that a three-person office can’t produce on its own. The goal is a structure where at least two people would have to collude to steal.
Put authorization limits in writing. A manager might approve expenses up to $500, a director between $500 and $10,000, and anything above that requires two signatures. Every employee with signing authority should acknowledge the limits in writing so nobody can later claim they didn’t know.
Controls Over Cash Receipts
Two people should open mail containing checks and prepare a log listing the date, payer, and amount of each one. That log is your independent record for comparing against the deposit slip. If the two numbers don’t match, something went wrong between the mailroom and the bank.
Deposit cash and checks daily. Overnight cash on-site creates unnecessary exposure and may conflict with insurance policy terms. Over-the-counter payments should use pre-numbered receipt books, and someone should account for the full number sequence daily. Gaps mean a receipt may have been pulled to suppress a transaction.
The person recording a receipt in accounts receivable should not be the person preparing the bank deposit.1Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet For ACH and card settlements, the control shifts to timely matching: reconcile bank activity against the AR ledger daily, and chase any discrepancy right away.
Remote Deposit Capture
Scanning checks from a desktop scanner or mobile app is faster than driving to the bank, but it introduces duplicate-deposit and altered-check risks. Federal regulators expect businesses using remote deposit capture to implement controls around image quality, duplicate detection, and physical handling of original checks after scanning.2Federal Reserve. Risk Management of Remote Deposit Capture Your bank’s remote deposit agreement will specify how long you must keep the original paper check before destruction and the security requirements for the scanning system. Endorse or mark scanned checks immediately so they can’t be redeposited, and restrict scanning software access to authorized personnel.
Controls Over Cash Disbursements
Most fraud prevention work happens on the outflow side, because disbursement schemes tend to involve larger amounts than receipt-side theft. Every disbursement needs three matching documents before payment goes out: a purchase order, a receiving report confirming delivery, and an approved vendor invoice. When those three agree on quantity, price, and vendor, you have confirmed the business ordered the goods, received them, and was billed correctly.
Checks must be pre-numbered, and the accounting system needs to track every number in sequence, voids included. Blank check stock stays in a locked location with access limited to authorized personnel. The person who prepares a check should never sign it; otherwise they can create a fictitious invoice, cut a check to a shell company, and sign it themselves. Above a documented threshold, require two signatures.
ACH, Wires, and Vendor Bank Changes
Electronic payments move faster than checks and are harder to claw back, so they need stricter handling. The person entering payment details should not be the person releasing the funds. For any change to a vendor’s bank account details, verify by calling a phone number you already have on file. Never use contact information from the email requesting the change. Business email compromise schemes have caused over $55 billion in losses by exploiting exactly that shortcut.3Federal Bureau of Investigation. Business Email Compromise: The $55 Billion Scam
Positive Pay
Positive pay is a bank service that catches forged or altered checks before they clear. You send the bank a file of every check you issue with the check number, amount, and payee name, and the bank compares presented checks against the list. Anything that doesn’t match becomes an exception item you review and either pay or return.4Office of the Comptroller of the Currency. Check Fraud: A Guide to Avoiding Losses Most banks offer it as standard treasury management, and the monthly fee is trivial next to a single forged five-figure check clearing.
ACH Debit Blocks and Filters
An ACH debit block names the companies authorized to pull money from your account and rejects everything else automatically. A filter is more flexible: it flags unauthorized debits for review rather than rejecting outright. If you don’t initiate many ACH payments, a full block is simpler. If you deal with several vendors on recurring debits, a filter gives daily visibility without disrupting legitimate transactions.
Petty Cash
For small routine expenses where a check is impractical, use an imprest petty cash fund. The fund starts at a fixed amount, say $200 or $500, and a single custodian manages it. Every disbursement needs a signed voucher with a receipt attached. When the fund runs low, the custodian submits vouchers for reimbursement and the fund returns to its original balance. Cash on hand plus outstanding vouchers should always equal the fixed amount. An independent person should perform a surprise count from time to time to verify it.
Payroll Controls
Payroll fraud is one of the most common forms of occupational theft because it’s repetitive and easy to lose in the noise of regular pay cycles. Ghost employees, inflated hours, and unauthorized pay rate changes all exploit weak controls.
Four functions should sit with different people: employees complete their own timesheets, a supervisor approves them, a payroll specialist enters the data, and someone independent reviews the output.1Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet Whoever adds new employees to the payroll system should not process pay runs. That combination is exactly how ghost employees get created. Review pay rates and job classifications periodically, and reconcile each pay run against budgeted labor costs before funds release.
Independent Bank Reconciliation
All the preventive controls above are verified after the fact through the bank reconciliation, and the person doing it has to be independent of anyone who handles cash, processes disbursements, or records transactions.1Office of Justice Programs. Internal Controls and Separation of Duties Guide Sheet Without that independence, the reconciler can simply reconcile around their own theft.
Complete it monthly at least, and don’t let it drift. The longer you wait, the harder discrepancies are to trace and the more time a fraudster has to cover tracks. The reviewer should go beyond matching totals and actively look for red flags:
- Checks to unfamiliar vendors or employees, a common sign of shell-company fraud or unauthorized reimbursements
- Electronic transfers without matching documentation; every outgoing transfer should tie back to an approved invoice or payment request
- Round-dollar disbursements, since legitimate invoices rarely land on perfectly round numbers
- Missing check numbers, which suggest checks were issued and pulled from the records
- Checks clearing for amounts that don’t match vendor history, which can indicate alteration
A senior manager who isn’t involved in daily cash processing should review and sign off on the completed reconciliation. That sign-off means they’ve examined supporting documentation for large or unusual items. The step gets skipped under time pressure, but it’s the control that catches a negligent or complicit reconciler.
System Access and Technology Controls
Every employee accessing the financial system needs a unique user ID and a strong password. Shared logins destroy the audit trail. Enforce password rotation and disable accounts the day employees leave.
Access follows least privilege: each person gets only what the job requires. A sales representative has no business posting journal entries or opening the wire transfer module. Review access rights at least quarterly and after every role change, because permissions accumulate as people move between positions without losing old access.
Banking portals and payment platforms should require multi-factor authentication on every login. Federal banking regulators treat MFA as a baseline expectation for high-risk financial activity, not an optional extra.5Federal Reserve. SR 21-14 – Authentication and Access to Financial Institution Services and Systems MFA blocks unauthorized access even when a password gets phished.
Back up financial data regularly and keep the backups offsite or in a secure cloud. Ransomware attacks that encrypt the accounting system are a routine threat for businesses of every size, and a clean recent backup is the difference between paying a ransom and restoring operations in hours. Someone independent of accounting, either in IT or a security role, should review system access logs periodically for unauthorized login attempts, after-hours access, or attempts to reach restricted modules.
Reporting Cash Payments Over $10,000
Any business that receives more than $10,000 in cash in a single transaction, or in two or more related transactions, must file IRS Form 8300 within 15 days.6eCFR. 26 CFR 1.6050I-1 – Returns Relating to Cash in Excess of $10,000 The controls need a specific step to flag these transactions before the deadline runs.
Cash for Form 8300 purposes goes beyond paper currency. It covers coins and currency of any country, plus cashier’s checks, bank drafts, traveler’s checks, and money orders with a face value of $10,000 or less when received in certain retail transactions or when you know the buyer is trying to avoid reporting.7Internal Revenue Service. IRS Form 8300 Reference Guide Personal checks and wire transfers are not cash for this purpose. Designated reporting transactions that pull in the broader definition include retail sales of consumer durables like vehicles and boats, collectibles such as art and antiques, and travel or entertainment packages above $10,000.
When payments accumulate, you file once the running total crosses $10,000 within a 12-month period. The 15-day clock starts from the payment that pushes the total past the threshold.6eCFR. 26 CFR 1.6050I-1 – Returns Relating to Cash in Excess of $10,000 You also must send a written statement to the person named in the filing by January 31 of the following year. Penalties for failing to file escalate fast, and intentional disregard has no annual cap.8Internal Revenue Service. 4.26.10 Form 8300 History and Law
Fidelity Bonds and Crime Insurance
Controls reduce the odds of theft but don’t eliminate them. A fidelity bond or commercial crime policy covers the business financially when an employee steals anyway. These policies typically cover embezzlement, forgery, and misappropriation of company funds.
If your business sponsors a 401(k) or other employee benefit plan, bonding isn’t optional. Federal law requires every person who handles plan funds to be bonded for at least 10% of the funds handled, with a $1,000 minimum and, in most cases, a $500,000 maximum.9Office of the Law Revision Counsel. 29 USC 1112 – Bonding Plans holding employer securities have a higher cap of $1,000,000. The bond has to be in place at the start of each plan year, obtained through a surety approved by the Department of the Treasury, and reported on your Form 5500. Failing to maintain it is itself a fiduciary breach, and plan fiduciaries become personally liable for losses the bond would have covered.
Even without a retirement plan, a commercial crime policy is worth carrying. Cost is modest relative to the coverage, and some policies also cover computer fraud, funds transfer fraud, and social engineering losses like business email compromise.
An Anonymous Reporting Channel
Research from the Association of Certified Fraud Examiners consistently shows tips are the most common way occupational fraud gets detected, ahead of audits, management review, and any single internal control. The practical implication is that businesses which make reporting easy catch fraud faster and lose less money.
An anonymous channel, whether a phone hotline, a web portal, or a locked suggestion box, removes the fear of retaliation that keeps witnesses silent. Public companies are already required to have procedures for anonymous complaints about accounting and auditing matters under federal securities law. Private businesses have no mandate but every practical reason to do the same. What matters is that employees know it exists, trust that it is anonymous, and believe reports will be investigated. Pair it with a written anti-fraud policy stating prohibited conduct and consequences, and train employees annually on what fraud looks like and how to report it.
Record Retention
Controls only work if the underlying records still exist when someone needs them. The IRS requires records supporting any item of income, deduction, or credit to be kept until the statute of limitations on that return expires.10Internal Revenue Service. How Long Should I Keep Records For most businesses that’s three years from the filing date. Underreporting income by more than 25% of gross income extends the window to six years. A loss claim from worthless securities or bad debt runs seven years. Never filing, or filing fraudulently, has no limit.
Employment tax records follow a separate rule: keep them at least four years from the date the tax becomes due or is paid, whichever is later.10Internal Revenue Service. How Long Should I Keep Records That covers payroll registers, timesheets, and records of wages paid. Insurance carriers and lenders may require longer retention, so check those obligations before destroying anything.