Treasury & Banking Control Audit in India: Bank Mandates, Maker-Checker, Payment Files, Reconciliation, Online Access & Fraud Risk 2026
A board and CFO framework for testing how money moves through bank accounts, payment files, mandates, online credentials, reconciliations and emergency treasury exceptions.
Treasury controls are the final barrier between an approved transaction and actual movement of money. Even strong procurement or payroll processes can be defeated if bank mandates are outdated, payment files can be altered after approval, online credentials are shared or one user can create and release payments without independent review.
A treasury audit therefore focuses on authority, access, beneficiary integrity, payment workflow, reconciliation and evidence of exceptional transactions.
1. Create a complete bank-account register
Maintain every operating, collection, payroll, escrow, deposit, virtual, foreign-currency and dormant account with bank, branch, account purpose, authorised signatories, online users, transaction limits and closing status. Accounts opened for old projects or entities should not remain outside central visibility.
Compare banking authority with the Delegation of Authority & Approval-Control Audit.
2. Bank mandates and signatories
Verify that board or authorised resolutions, bank records and current management structure agree. Former employees, retired directors or transferred personnel should not remain active signatories or online users. Transaction limits should reflect role and business requirement.
3. Maker-checker and segregation
Test whether the same person can create beneficiary, prepare payment, upload file and release funds. If system constraints prevent full segregation, compensating controls should include independent verification, daily review and restricted access.
4. Beneficiary creation and change
New or changed beneficiaries should be supported by verified source documents. Vendor bank changes are especially sensitive. Link treasury verification to the Accounts Payable Fraud & Payment Control Review.
5. Payment-file integrity
Determine whether payment files are generated from approved ERP data, whether they can be edited outside the system, whether approvers can see beneficiary and amount at release, and whether hash or control-total checks are used where available. Manual payment templates should be tightly controlled.
6. Online banking and token security
Review named users, token custody, password sharing, multi-factor authentication, device registration, IP restrictions where used, leaver revocation and dormant accounts. Shared credentials weaken accountability and should be eliminated where systems permit individual access.
7. Bank reconciliation
Reconciliations should be timely, independently reviewed and capable of explaining outstanding cheques, deposits in transit, bank charges, unidentified receipts and direct debits. Long-outstanding reconciling items can conceal error or misuse.
8. Dormant and low-use accounts
Dormant accounts should be formally identified, periodically reviewed and closed where no longer required. Low-use accounts can become control blind spots because they receive less routine scrutiny while remaining capable of movement.
9. Treasury analytics
- payments outside normal business hours;
- new beneficiary followed by immediate high-value transfer;
- transactions just below approval limits;
- multiple releases to same beneficiary in one day;
- manual payments outside ERP workflow;
- payments from dormant or unusual accounts;
- frequent failed or reversed transactions;
- unreconciled bank items ageing beyond policy;
- users with incompatible maker/checker rights; and
- payments released by emergency authority without later review.
10. Treasury risk matrix
| Risk | Indicator | Control |
|---|---|---|
| Authority | Outdated signatory or excessive limit | Mandate refresh and board/DOA alignment |
| Access | Shared credential or incompatible rights | Named access and segregation |
| Payment | Unverified beneficiary or editable file | Independent verification and file integrity |
| Reconciliation | Old unexplained bank item | Timely closure and independent review |
11. Evidence required
Bank account register, board/authority resolutions, bank mandates, user lists, transaction limits, payment files, beneficiary logs, bank statements, reconciliations, exception approvals, token records and system access reports should be included.
12. CFO and board deliverables
- bank-account and signatory register;
- online-access conflict report;
- beneficiary-change exceptions;
- manual/emergency payment schedule;
- bank-reconciliation ageing;
- dormant-account review;
- payment-control heat map; and
- 30/60/90-day treasury remediation plan.
13. 30/60/90-day remediation
0–30 days: revoke stale access, refresh signatory list, restrict shared credentials and review recent high-risk beneficiary changes.
31–60 days: strengthen file-generation controls, automate reconciliation ageing, close unnecessary accounts and align limits with delegation.
61–90 days: introduce periodic user recertification, treasury exception dashboards and independent testing of emergency payments.
14. Frequently asked questions
Is maker-checker enough?
No. Beneficiary integrity, access governance, file controls and reconciliation are also required.
Should dormant accounts be closed?
Where no business need remains, closure reduces risk. Any retained dormant account should remain visible and controlled.
Who should review treasury access?
Finance ownership should be supported by independent IT/control review where relevant, with management approval for material privileges.
Can emergency payments bypass all controls?
No. Emergency routes should still preserve authority, evidence and later independent review.
Authoritative references
Author: Adv. Govind Bali, Fastrack Legal Solutions LLP.