Startup risk & access controls: Identify critical activities with owners and limit access to what’s needed; Record who approves payments, checks invoices, and reviews bank movements; Check if the company is covered by the Privacy Act 1988 (Cth) and APPs
Image: Startup Operations Guide

Cash Controls

Startup risk and access controls

Map critical dependencies, review account access, check payment steps and prepare incident contacts for a young company.

Begin with the work a young company cannot afford to lose, the people and accounts that control it, and the decisions needed if something fails. Give each critical activity an owner, limit access to what people need, make payment checks visible and prepare the first incident contacts. Revisit these controls when people, systems or customer commitments change.

Find where work could stop

Choose activities whose interruption would quickly affect customers, payments or essential records. For each, identify the knowledge, account, supplier or approval needed to continue, then ask what would happen if one of those were unavailable tomorrow.

Record the activity, its owner, the likely consequence and a workable alternative. A colleague named as cover may still lack the instructions, access or authority to act. Prioritise gaps that threaten a current commitment, and give each fix an owner.

Set a proportionate control baseline

Write down the main risks to money, information and essential records, along with the measures already in place to reduce them. Internal controls are intended to reduce loss and error and provide some assurance that books and records are valid.

Use short procedures for higher-risk activities, particularly those involving cash or physical assets. Make clear who follows each procedure and how the team can tell whether it was followed.

Controls can take different forms; choose checks that fit the risk and the company's capacity rather than relying on an unwritten expectation. Smaller organisations may have limited scope to separate duties, so identify where a practical review can reduce exposure.

Match access to the job

List accounts that can change business settings, move money, reach sensitive records or lock others out. Compare permissions with each person's current duties, and remove access no longer needed after a role change or departure.

Keep a simple access register recording each account, who can use it, the work need and the permission level. Review it when roles change or people leave, and choose any other review interval according to the risk of the account.

Use individual accounts where the service allows them, and enable multi-factor authentication wherever possible. Start with important accounts.

Give administrator access for a specific need. Someone who reads a document or handles a routine request may not need to change settings or grant permissions.

Plan how an authorised person would regain control if the usual administrator were unavailable. The available roles and recovery options depend on the service.

Pros and Cons of Using Shared vs Individual Accounts

Pros of Individual Accounts
Better accountability, easier tracking, supports MFA
Cons of Individual Accounts
Higher administrative overhead, more login management
Pros of Shared Accounts
Simpler setup, fewer logins to manage
Cons of Shared Accounts
No individual accountability, harder to trace actions, risk of password sharing

Map access to customer information

For personal information, note what the company holds, where it is stored and who can access it. This can include contact details, transaction records and booking information, whether held in digital systems or physical files.

The map helps identify accounts and records whose access should be limited to people with a work-related need. Record why each type of information is collected and how long it is retained.

Check whether payment card details are held by the company or its payment processor, rather than assuming they are stored in one place. Check the relevant agreement too, as payment processor and data-hosting agreements may impose privacy obligations.

Check whether the company is covered by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. APP coverage includes businesses with annual turnover above $3 million, health service providers regardless of turnover, businesses that trade in personal information and businesses that provide services to government.

A turnover below $3 million alone does not establish that the company is outside privacy obligations. Even where the Privacy Act does not apply, contractual obligations may apply and reasonable data protection remains good practice.

For an entity with APP 11 obligations, reasonable steps must be taken to protect personal information from misuse, interference, loss and unauthorised access. Information no longer needed must be securely destroyed or de-identified.

The Notifiable Data Breaches (NDB) Scheme applies to entities that already have Privacy Act security obligations. Where a breach is likely to cause serious harm, covered entities must notify affected individuals and the Office of the Australian Information Commissioner (OAIC).

Remove information that is no longer needed in accordance with the company's retention arrangements.

Check requests before releasing payments

Record who may approve an expense, who checks the invoice and payee, who releases the payment and who reviews the bank movement. Assign consequential steps to different people where practical.

In a smaller team, arrange a review by someone other than the person whose work is being checked. Give the reviewer access to the supporting record.

Verify a request to change supplier bank details through a contact route already known to the business or found independently. Do not rely on a number in the change request.

Agree in advance who can handle an absent approver or an urgent exception. Keep the reason and subsequent review visible.

Handling Payment Approval Requests Safely

  1. Request submitted by employeeInclude invoice, PO, and purpose
  2. Invoice verified by finance teamCheck payee name, bank details, amount
  3. Approval by designated approverUse multi-factor authentication
  4. Payment released with audit trailRecord date, time, and reviewer

Make small-team checks visible

Give reviewers read-only access to relevant records where the system allows it. Avoid giving them permission to change the underlying settings or payment.

Include bank statement reconciliation in the control routine. Keep evidence of approvals and checks with the relevant records.

Where a system can help confirm transaction accuracy, consider using that feature. Check that the feature is used as part of the control routine.

Prepare the first incident contacts

List who receives a report, who takes over if they are unavailable and who can make operational decisions. Note which external contacts may be needed.

The first call will differ for a cyber incident, suspected payment fraud, a service outage or an emergency affecting people's safety. If the company is covered by the NDB Scheme, record who will handle any required notification to affected individuals and the OAIC.

Keep a protected copy reachable if the usual network or shared drive is down. Make sure responders know how to find it.

The list supports an incident plan; it does not settle containment, customer communication or recovery decisions by itself.

Keep essential contacts reachable

A network outage can affect phones, wi-fi and EFTPOS, so avoid making a single communication route the only way to reach essential contacts. Know who the relevant service providers are.

Keep hard copies of key contact details, including colleagues, technical support, vendors and clients. Make sure relevant staff know where to find them and what to do if the network is unavailable.

For an emergency affecting people's safety, treat safety as the priority and follow directions from emergency personnel.

Check the controls when work changes

Walk through a recent role change, a proposed payment and a plausible interruption. Can the team identify the owner, authorised decision-maker, supporting record and next contact?

Assign any stale permission, missing contact or unclear approval to someone who can fix it. Repeat the check after a hire, departure, new critical service or material change in how money moves.

The board, where the company has one, has a role in assessing, monitoring and mitigating risk. It can use the control review to ask whether important procedures are being followed and whether a risk has changed, rather than treating the written controls as a one-off exercise.

In this guide

  1. Identifying single-person dependencies in a young companyFind work that depends on one person's knowledge, access or authority, and check whether a proposed cover could act.
  2. Separating approval and payment responsibilities where practicalSplit purchase approval, payment checks and release where possible, with a visible review when a small team combines roles.
  3. Reviewing administrative access to critical accountsCheck who can administer critical accounts, whether each permission is still needed and how controlled recovery would work.
  4. Preparing an incident contact list before a disruptionBuild an incident contact list with first responders, alternates, contact triggers and an accessible fallback copy.

More from Cash Controls

Cash Controls

Building a cash visibility routine

Build a repeatable startup cash check using current balances, dated receipts and payments, variance review and clear follow-up owners.