Virtual CFO Services
Financial Controls for Startups: What to Set Up Before You Grow Past 20 People
Lekha Editorial Team
CA-reviewed · Published
Most startup financial fraud and errors don't happen because someone is dishonest. They happen because there are no controls — a single person can authorise their own expense, transfer large amounts without a second approval, or pay a vendor invoice with no verification. Controls prevent mistakes as much as they prevent fraud.
The Minimum Control Framework for a 10-20 Person Startup
Segregation of duties: the person who initiates a payment should not be the same person who approves it. At minimum: the CEO/founder approves expenses; a separate person (finance manager, CFO, or another founder) executes the bank transfer. In a 5-person startup, this may mean the founding CEO approves and the co-founder clicks 'pay'. In a 15-person startup, it means a finance executive initiates and the CFO or CEO approves.
Dual-authority bank transfers: set up your business bank account (most Indian banks offer this for current accounts) to require 2 authorised signatories for any transfer above a threshold (typically ₹50,000–₹2 lakh). Below the threshold, one signatory can execute. This prevents any single employee from making large transfers without a second approval.
Expense approval workflow: every expense above a threshold requires pre-approval from a manager. Most companies use a tiered approval structure: operational expenses below ₹5,000 don't need approval; ₹5,000–₹50,000 needs manager approval; above ₹50,000 needs CFO or CEO approval; above ₹5 lakh needs board awareness (through the monthly report). Tools: Zoho Expense, Fyle, or Happay for automated approval workflows.
Vendor Payment Controls
Vendor verification: before any new vendor is added to your payment system, verify their details — PAN, bank account, registered address. Fraudulent invoices (phantom vendors, invoice manipulation) are one of the most common financial crimes at small companies. A simple verification step (confirm the vendor's bank account by calling the vendor's published phone number, not the phone number on the invoice) eliminates most of this risk.
Invoice matching: for significant recurring purchases, implement a three-way match: purchase order (what was ordered) + goods receipt/service confirmation (what was received) + invoice (what is being billed) should all match before payment. For a company without formal POs, at minimum require a service confirmation email from the relevant business owner before paying any invoice above ₹25,000.
Payment frequency and batching: paying vendors twice weekly (rather than ad hoc when invoices arrive) creates a predictable rhythm that is easier to monitor, harder to manipulate (a fraudulent payment stands out in a structured batch), and more manageable for cash flow forecasting.
Banking and System Controls
Internet banking access: restrict admin access to the company's internet banking to the minimum number of people necessary. Log and review all login activity. Disable international transfers unless required, and require additional authentication for large transactions. Review the list of authorised signatories quarterly and remove any former employees immediately.
Accounting system access: in Zoho Books or Tally, create role-based access — accounting staff can enter transactions but cannot approve them or modify past entries; managers can approve but cannot delete entries; only the CFO or a designated administrator can change system settings or modify locked periods. Audit trails for all changes should be enabled.
Credit card and prepaid card controls: issue individual prepaid cards (Razorpay Prepaid, Happay) with individual limits for employees who regularly make business purchases. This is better than sharing a single company credit card where individual transactions are harder to attribute. Monthly reconciliation of every card transaction against expense reports.
Monthly bank reconciliation: the CA or finance manager should reconcile the bank statement to the accounting records every month, without exception. Any unreconciled items should be investigated within 5 business days.
Key takeaway
Financial controls are not bureaucracy — they're risk management. The 2 hours spent setting up dual-signatory bank access, a tiered expense approval workflow, and monthly reconciliation discipline prevent incidents that cost 100x more to resolve. Do it before you need it.
Frequently asked questions
At what size should a startup implement formal financial controls?
From day one — but at different levels of formality. A 3-person company needs: dual-signatory bank access, a basic expense approval hierarchy (CEO approves all significant spend), and monthly bank reconciliation. A 20-person company additionally needs: a formal expense policy, tiered approval limits by role, vendor verification procedures, and periodic internal control reviews. Controls should grow with the company; the cost of controls should never exceed the cost of the risks they prevent.
What are the most common financial frauds at Indian startups?
The most common issues are: expense fraud (employees claiming personal expenses as business expenses, inflating expense claims), vendor fraud (payments to ghost vendors, inflated invoices from related parties), payroll fraud (ghost employees on the payroll), and petty cash misappropriation. Most of these are prevented by: requiring documentation for all expense claims, implementing approval workflows, doing vendor verification before payment, and auditing payroll headcount against HR records quarterly.
Do startups need an internal audit function?
Not formally until you're larger (typically Series B+ or when required by the Companies Act due to crossing prescribed thresholds). However, every company benefits from periodic informal internal reviews — the CFO quarterly reviewing expense reports, the CEO doing spot-checks on vendor payments, or an external CA doing a half-day control review annually. The Investment Committee approval requirement under the Companies Act for related-party transactions above certain thresholds is effectively a mandatory internal control requirement regardless of company size.
How should a startup handle petty cash?
Minimise petty cash. Move as many payments as possible to the formal banking system (NEFT, IMPS, UPI, prepaid cards) where there's a digital trail. For unavoidable small cash expenses: maintain a petty cash float of ₹5,000–₹15,000 maximum, require receipts for every cash disbursement, have the petty cash custodian (not the CFO) balance the cash against receipts weekly, and replenish through a formal bank transfer with the CFO's approval. The goal is to have the petty cash box as infrequently used as possible.
What should a startup do if it discovers a financial fraud?
Immediately: preserve all evidence (don't delete emails, systems access logs, or financial records). Engage your legal counsel before taking any action (including terminating the employee) — due process matters both legally and for evidence preservation. Engage a forensic accountant to scope the fraud and establish the full extent of the loss. Notify your board and investors promptly (they need to know, and concealment can be a bigger problem than the fraud itself). File a complaint with the police if the loss is significant and prosecution is warranted.
Related articles
What Does a Virtual CFO Do? Roles, Responsibilities and What to Expect
Virtual CFO Services
Setting Up Accounting for an Indian Startup: Systems, Chart of Accounts and the Right First Steps
Startup Advisory
Annual Compliance Requirements for Private Limited Companies in India: The Complete Checklist
Startup Advisory