Corporate Risk Mitigation • Treasury & Banking • India • 2026

Treasury & Banking Control Audit in India: Bank Mandates, Maker-Checker, Payment Files, Reconciliation, Online Access & Fraud Risk 2026

A board and CFO framework for testing how money moves through bank accounts, payment files, mandates, online credentials, reconciliations and emergency treasury exceptions.

AuthorityBank mandates, signatories, limits and delegation
PaymentsMaker-checker, file upload, beneficiary change and release
AccessTokens, credentials, privileged users and leavers
AssuranceBank reconciliation, dormant accounts and exception reporting

Treasury controls are the final barrier between an approved transaction and actual movement of money. Even strong procurement or payroll processes can be defeated if bank mandates are outdated, payment files can be altered after approval, online credentials are shared or one user can create and release payments without independent review.

A treasury audit therefore focuses on authority, access, beneficiary integrity, payment workflow, reconciliation and evidence of exceptional transactions.

Corporate standard: emergency payment capability is legitimate, but it should be limited, documented and independently reviewed after use.

1. Create a complete bank-account register

Maintain every operating, collection, payroll, escrow, deposit, virtual, foreign-currency and dormant account with bank, branch, account purpose, authorised signatories, online users, transaction limits and closing status. Accounts opened for old projects or entities should not remain outside central visibility.

Compare banking authority with the Delegation of Authority & Approval-Control Audit.

2. Bank mandates and signatories

Verify that board or authorised resolutions, bank records and current management structure agree. Former employees, retired directors or transferred personnel should not remain active signatories or online users. Transaction limits should reflect role and business requirement.

3. Maker-checker and segregation

Test whether the same person can create beneficiary, prepare payment, upload file and release funds. If system constraints prevent full segregation, compensating controls should include independent verification, daily review and restricted access.

4. Beneficiary creation and change

New or changed beneficiaries should be supported by verified source documents. Vendor bank changes are especially sensitive. Link treasury verification to the Accounts Payable Fraud & Payment Control Review.

5. Payment-file integrity

Determine whether payment files are generated from approved ERP data, whether they can be edited outside the system, whether approvers can see beneficiary and amount at release, and whether hash or control-total checks are used where available. Manual payment templates should be tightly controlled.

6. Online banking and token security

Review named users, token custody, password sharing, multi-factor authentication, device registration, IP restrictions where used, leaver revocation and dormant accounts. Shared credentials weaken accountability and should be eliminated where systems permit individual access.

7. Bank reconciliation

Reconciliations should be timely, independently reviewed and capable of explaining outstanding cheques, deposits in transit, bank charges, unidentified receipts and direct debits. Long-outstanding reconciling items can conceal error or misuse.

8. Dormant and low-use accounts

Dormant accounts should be formally identified, periodically reviewed and closed where no longer required. Low-use accounts can become control blind spots because they receive less routine scrutiny while remaining capable of movement.

9. Treasury analytics

  • payments outside normal business hours;
  • new beneficiary followed by immediate high-value transfer;
  • transactions just below approval limits;
  • multiple releases to same beneficiary in one day;
  • manual payments outside ERP workflow;
  • payments from dormant or unusual accounts;
  • frequent failed or reversed transactions;
  • unreconciled bank items ageing beyond policy;
  • users with incompatible maker/checker rights; and
  • payments released by emergency authority without later review.

10. Treasury risk matrix

Risk Indicator Control
Authority Outdated signatory or excessive limit Mandate refresh and board/DOA alignment
Access Shared credential or incompatible rights Named access and segregation
Payment Unverified beneficiary or editable file Independent verification and file integrity
Reconciliation Old unexplained bank item Timely closure and independent review

11. Evidence required

Bank account register, board/authority resolutions, bank mandates, user lists, transaction limits, payment files, beneficiary logs, bank statements, reconciliations, exception approvals, token records and system access reports should be included.

12. CFO and board deliverables

  • bank-account and signatory register;
  • online-access conflict report;
  • beneficiary-change exceptions;
  • manual/emergency payment schedule;
  • bank-reconciliation ageing;
  • dormant-account review;
  • payment-control heat map; and
  • 30/60/90-day treasury remediation plan.

13. 30/60/90-day remediation

0–30 days: revoke stale access, refresh signatory list, restrict shared credentials and review recent high-risk beneficiary changes.

31–60 days: strengthen file-generation controls, automate reconciliation ageing, close unnecessary accounts and align limits with delegation.

61–90 days: introduce periodic user recertification, treasury exception dashboards and independent testing of emergency payments.

14. Frequently asked questions

Is maker-checker enough?

No. Beneficiary integrity, access governance, file controls and reconciliation are also required.

Should dormant accounts be closed?

Where no business need remains, closure reduces risk. Any retained dormant account should remain visible and controlled.

Who should review treasury access?

Finance ownership should be supported by independent IT/control review where relevant, with management approval for material privileges.

Can emergency payments bypass all controls?

No. Emergency routes should still preserve authority, evidence and later independent review.

Authoritative references

Firm & Correspondence Information
Fastrack Legal Solutions LLP
Office: B1/32 Basement, Malviya Nagar, New Delhi – 110017
Telephone: +91 76976 71219
Email: advgovind@fastracklegalsolutions.com
Contact / Information Form: Submit Information / Documents
The particulars and form link above are provided solely for identification, correspondence and voluntary transmission of information. They do not constitute an advertisement, solicitation, invitation or inducement to engage legal services. Submission of the form does not by itself create an advocate-client relationship.
General corporate-risk information only. Banking, accounting and legal requirements depend on the company, mandate, institution and applicable law.

Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.

Leave a Comment

Your email address will not be published. Required fields are marked *