During an audit, whether internal or statutory, bank signing authorities are among the classic controls: the auditor checks that the people authorised to operate the accounts match the reality of the organisation, that changes are traced, and that the company can prove it. Cash being the company’s most liquid asset, controlling who can commit it is a pillar of any anti-fraud framework, and one of the easiest gaps for an auditor to detect.
Why do auditors care about bank signing authorities?
Three reasons come up every time:
- Fraud risk: a poorly controlled signing authority is the ability to commit the company’s cash unchecked. Separation of authorities (ceilings, dual signature) sits at the heart of internal control.
- An easy test: comparing the personnel register with the mandates on file at the banks is simple, factual, and often fruitful.
- Traceability: an undocumented signatory change makes it impossible to establish who could commit the company at a given date, which weakens the whole audit trail on payments.
What questions do auditors ask?
Here are the typical questions of a signing-authority review. Each one looks simple; it is the response time that separates a smooth control from a finding.
- Who can sign what, on each account, at the closing date? The full map: entity, bank, account, signatory, ceiling, signing rule.
- Do the mandates on file at your banks match your internal referential? The auditor crosses what you believe with what the bank actually holds.
- Have departed employees been revoked, and when? The most frequent gap: a leaver whose authority is still active at the bank.
- Who changed what, and when? The history of authority changes, dated and attributed.
- Where are the proofs of dispatch to the banks? An updated mandate without an acknowledgement does not prove the bank took it into account.
- Are the internal delegations consistent with the bank mandates? The two levels must match exactly.
- Is there a periodic review of signing authorities? A documented recertification is the proof that the framework is alive.
What does an auditor consider a finding?
- A departed signatory whose authority is still active at the bank.
- A mandate that cannot be found, or whose latest version does not match the bank’s.
- Ceilings or signing rules inconsistent across comparable entities, with no justification.
- Tracking in a spreadsheet, with no change history and no access control.
- No proof of dispatch or bank confirmation for the latest updates.
- No documented periodic review.
How to prepare for a signing-authority audit?
- Upstream: keep a single referential of entities, accounts, banks, signatories and signing rules; trace every change; archive mandates and proofs of dispatch; handle departures without delay; document a periodic review.
- During the audit: be able to produce, within minutes, the map of authorities at a given date, the history of one signatory, and the proof of every update. The perceived quality of your whole internal control often rides on that speed.
Answering in seconds instead of three days
The difficulty is never answering an auditor’s question: it is answering fast, with proof, without mobilising the team for days. When signing authorities live in a single referential backed by an immutable audit trail, every question above becomes a lookup or an export: who can sign what, who changed what and when, where the proof of dispatch is. That is exactly what Kable does: turning the audit question that used to trigger three days of digging into a documented answer in seconds.