When a business finds money missing, the first question is always who. It is usually the wrong question. In most cases nobody took anything — the process simply allowed a cost to happen and never asked anyone to justify it.
That distinction matters, because the two problems have completely different answers. Dishonesty is a people problem. A leak that recurs every month for four years is a design problem, and no amount of trustworthy staff will close it.
Why control frameworks fail in owner-run businesses
Not because owners do not care. Because of three things that are true of almost every growing Indian company.
The owner is the control
In the early years the promoter sees every payment, knows every customer, and remembers every price. That is a genuinely effective control — until turnover triples and he cannot. The control does not get replaced; it just stops covering most of the business, and nobody notices the moment it stopped.
Segregation of duties is impossible at small scale
The textbook says the person who orders should not be the person who receives, approves and pays. In a team of nine, that is not available. So the principle is abandoned entirely — when what was needed was a compensating control, not the ideal one.
The SOP was written for a certificate
Many businesses have a manual, prepared once, for a bank or a customer audit or a certification. It sits in a folder. It does not describe how the work is actually done, and everyone knows it, which teaches everyone in the company that written procedures are only for show.
What separates a control that works
Four properties. A control that lacks any one of them is a policy, not a control.
- It happens as part of the work, not after it. A check that requires someone to remember to do it will fail in a busy month — which is exactly when it is needed.
- It leaves evidence. If you cannot show, six months later, that the control operated in March, it did not operate in March as far as anyone can prove.
- It has an owner by name. Not a department. A department cannot be asked why something was not done.
- It produces exceptions, not confirmations. A report that says everything is fine is read by nobody. A report that lists the eleven things outside limits gets acted on.
The single most useful test. Pick any control you believe you have. Ask for the evidence it operated on a specific date four months ago. The answer tells you, in about two minutes, whether you have a control or a belief.
The ones worth having first
You do not need a full framework to start. A small number of controls cover most of the exposure in a typical manufacturing or trading business.
| Area | The control that matters most |
|---|---|
| Pricing | A rate below the approved floor cannot be invoiced without a recorded approval at a named level |
| Purchasing | Three-way match — purchase order, goods received note, invoice — enforced by the system, not by a person |
| Credit | Limits and terms per customer, enforced at order entry rather than reviewed at month end |
| Payments | No payment without an approved, matched invoice; bank changes to a vendor master verified independently of email |
| Inventory | Perpetual records with cycle counts, and a written-off list somebody signs |
| Master data | Changes to price, vendor, customer and item masters logged, with the log reviewed by someone who did not make the change |
The last row is the one most companies skip and the one that does the most work. Almost every recurring leak traces back to a master record that was changed once and never reviewed.
Compensating controls when segregation is not possible
A small team cannot segregate everything. It can do this instead:
- Review after the fact, by someone independent. If the same person raises and approves, a weekly review of everything above a threshold by the owner or an independent reviewer restores most of the effect.
- Make the exception visible rather than blocking it. Where an override is operationally necessary, log it and report it. A person who knows every override is listed behaves differently from one who does not.
- Rotate the task. A role that has never changed hands in eleven years is a risk, regardless of the person.
- Mandatory leave. Unglamorous, and it works. Most long-running process failures surface when the person who runs the process is away for two weeks.
Writing an SOP people actually follow
Short. One process per document. Written in the language the work is done in. Naming roles rather than individuals. Stating what to do when the normal path is not available — because the exception is where control fails, and an SOP that covers only the normal case is silent exactly when it is needed.
And dated, with an owner, and a review date. An SOP nobody has looked at for three years describes a company you no longer are.
What this is really for
Good controls are not about catching people. They are about making sure that a decision worth lakhs is taken by someone who knows it is worth lakhs.
Most of what leaks out of a business leaves through a door that a junior person was allowed to open, alone, without knowing what was on the other side. Closing that door is not a matter of trust. It is a matter of design.