10.1 Treasury Policy Manuals, Internal Controls & Segregation of Duties

Key Takeaways

  • The Committee of Sponsoring Organizations (COSO) Enterprise Risk Management (ERM) framework integrates risk management with corporate strategy across five core components: Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, and Information, Communication & Reporting.
  • A Treasury Management Policy Manual (TMPM) is a board-approved governing document establishing strict operational boundaries, investment parameters, hedging mandates, and delegation of authority matrices across all corporate treasury activities.
  • Segregation of Duties (SoD) requires strict operational separation between Front Office trade execution, Middle Office risk oversight, Back Office confirmation and settlement, and Treasury Accounting reconciliation.
  • The Maker-Checker (Dual Authorization) principle mandates that no single individual possesses the system privileges or authority to both initiate and release electronic payments or modify critical bank account master records.
  • Internal and external audit evaluations classify control breakdowns into three distinct severity tiers: Control Deficiency, Significant Deficiency, and Material Weakness under Sarbanes-Oxley (SOX) Section 404 standards.
Last updated: August 2026

10.1 Treasury Policy Manuals, Internal Controls & Segregation of Duties

Corporate treasury departments manage the financial lifeblood of the enterprise—transacting billions of dollars in liquidity, managing multi-currency cash pools, issuing debt, executing complex derivative hedges, and safeguarding enterprise assets. Because treasury transactions involve high financial value, direct electronic access to commercial banking rails, and sophisticated capital markets instruments, robust enterprise financial risk management and internal controls are essential to prevent catastrophic operational loss, unauthorized trading, fraudulent disbursements, and regulatory non-compliance.


1. Enterprise Risk Management (ERM) in Corporate Treasury

Enterprise Risk Management (ERM) is a structured, comprehensive approach to identifying, assessing, responding to, and monitoring financial, operational, strategic, and reputational risks across the entire organization. In corporate treasury, ERM aligns the company's risk appetite with its day-to-day liquidity management and balance sheet strategies.

+---------------------------------------------------------------------------------------------------------+
|                                 COSO ERM INTEGRATED FRAMEWORK IN TREASURY                               |
|                                                                                                         |
|  [1. GOVERNANCE & CULTURE]                                                                              |
|  • Board of Directors oversight & Audit Committee governance                                            |
|  • Tone at the top, ethical values, and formal Treasury Management Policy Manual (TMPM)                |
|                                                                                                         |
|  [2. STRATEGY & OBJECTIVE-SETTING]                                                                      |
|  • Defining corporate risk appetite and tolerance thresholds (e.g., FX, interest rate, liquidity)       |
|  • Aligning capital structure and financing strategies with long-term corporate growth plans            |
|                                                                                                         |
|  [3. PERFORMANCE]                                                                                       |
|  • Identifying, assessing, and prioritizing treasury risks (credit, liquidity, market, operational)     |
|  • Implementing risk responses: Avoid, Mitigate (hedging/controls), Transfer (insurance), or Accept    |
|                                                                                                         |
|  [4. REVIEW & REVISION]                                                                                 |
|  • Evaluating control effectiveness, monitoring KPI/KRI dashboards, and auditing policy adherence       |
|  • Adapting treasury strategies to macroeconomic shifts, interest rate regimes, and regulatory changes  |
|                                                                                                         |
|  [5. INFORMATION, COMMUNICATION & REPORTING]                                                            |
|  • Real-time visibility via Treasury Management Systems (TMS) and Enterprise Resource Planning (ERP)    |
|  • Timely risk reporting to the CFO, Chief Risk Officer (CRO), and Board Audit Committee                |
+---------------------------------------------------------------------------------------------------------+

The Three Lines of Defense Model in Treasury Governance

To ensure comprehensive operational integrity and independent oversight, modern treasury governance adopts the Three Lines of Defense framework:

  1. First Line of Defense (Operational Management & Execution): Corporate treasury professionals, cash managers, and front-office traders who execute daily operations, maintain cash positions, initiate transactions, and enforce primary day-to-day internal controls.
  2. Second Line of Defense (Risk Management & Compliance): Enterprise Risk Management (ERM) teams, the Chief Risk Officer (CRO), Compliance Officers, and the Financial Risk Committee. They establish enterprise risk policies, set exposure limits, monitor compliance independently of front-office execution, and develop risk modeling frameworks.
  3. Third Line of Defense (Independent Internal Audit): Internal Audit provides objective, independent assurance to the Board Audit Committee and Senior Management regarding the design adequacy and operating effectiveness of treasury internal controls, governance processes, and policy adherence.
Loading diagram...
Three Lines of Defense in Corporate Treasury Governance

2. The Treasury Management Policy Manual (TMPM)

A Treasury Management Policy Manual (TMPM) is the foundational governance document approved by the Board of Directors that establishes operational boundaries, decision-making authority, risk limits, and permitted instruments across all corporate financial activities.

Core Chapters of the TMPM

TMPM ChapterPrimary ObjectiveKey Policy Mandates & Parameters
1. Cash & Liquidity ManagementEnsure enterprise liquidity and solvency under ordinary and stressed conditions.Minimum operating cash buffers, cash concentration topologies, target account balances, permitted short-term liquidity facilities, cash positioning cutoffs.
2. Short-Term Investment PolicySafeguard principal while maintaining liquidity and optimizing yield.Explicit list of eligible asset classes (e.g., U.S. Treasuries, prime commercial paper, government MMFs), minimum credit ratings (e.g., A-1/P-1), maximum Weighted Average Maturity (WAM $\le 60$ days), and single-issuer concentration caps (e.g., $\le 5%$ of portfolio).
3. Borrowing & Debt ManagementOptimize long-term capital structure and minimize weighted average cost of capital (WACC).Debt issuance approval thresholds, target leverage ratios (e.g., Debt/EBITDA $< 2.5\text{x}$), interest coverage limits, allowable debt structures (commercial paper, term loans, senior unsecured notes), refinancing horizon rules.
4. Foreign Exchange (FX) Risk PolicyMitigate earnings and cash flow volatility from currency fluctuations.Permitted hedging instruments (FX forwards, vanilla options, cross-currency swaps; outright prohibition of exotic/leveraged derivatives), mandatory hedge ratios (e.g., $70%–90%$ of forecasted 12-month exposures), hedge accounting qualification criteria (ASC 815).
5. Interest Rate Risk HedgingManage floating vs. fixed interest rate exposure across debt portfolios.Allowable fixed/floating debt mix (e.g., $60%$ fixed / $40%$ floating $\pm 10%$), interest rate swap execution mandates, tenor limits, counterparty eligibility.
6. Bank Account AdministrationControl enterprise bank account inventory and prevent unauthorized accounts.Centralized authority to open/close accounts, authorized signatory lists, annual FBAR reporting protocols, minimum required account security features (Positive Pay, ACH Debit Blocks).
7. Business Continuity & Disaster RecoveryEnsure continuous operational resilience during system or facility disasters.Recovery Time Objectives (RTO), Recovery Point Objectives (RPO), emergency payment authorization protocols, backup communication lines.

3. Policy Governance Lifecycle & Exception Management

Treasury policies must remain dynamic documents that evolve alongside changing business models, corporate acquisitions, macroeconomic conditions, and regulatory environments.

+---------------------------------------------------------------------------------------------------------+
|                                   TMPM POLICY GOVERNANCE LIFECYCLE                                      |
|                                                                                                         |
|  [1. Annual Policy Review]       Treasury conducts annual review against market/regulatory changes.     |
|           │                                                                                             |
|           v                                                                                             |
|  [2. Risk Committee Endorsement] Financial Risk Committee / CFO reviews proposed revisions.             |
|           │                                                                                             |
|           v                                                                                             |
|  [3. Board / Audit Approval]     Board Audit Committee formally votes and re-authorizes TMPM.           |
|           │                                                                                             |
|           v                                                                                             |
|  [4. Operational Execution]      Treasury configures TMS rules, system limits, and approval matrices.   |
|           │                                                                                             |
|           v                                                                                             |
|  [5. Exception Handling]         Formal logging, escalation, approval, and remediation of variances.    |
+---------------------------------------------------------------------------------------------------------+

Exception Management & Escalation Framework

No policy can foresee every market shock or strategic corporate event. When a temporary policy deviation is necessary (e.g., exceeding single-issuer investment limits during an M&A cash buildup or executing an off-market hedge tenor), a formal Exception Management Protocol must be followed:

  1. Written Request & Justification: The front office submits a formal Exception Request detailing the business rationale, quantitative exposure, specific policy clause violated, proposed duration, and compensating controls.
  2. Multi-Level Approval: Minor exceptions require dual sign-off from the Treasurer and Head of ERM; material exceptions (e.g., large limit breaches, unauthorized derivative types) require written pre-approval from the Chief Financial Officer (CFO) and immediate notification to the Chair of the Board Audit Committee.
  3. Exception Log & Expiration: All exceptions are recorded in a centralized Treasury Exception Register with strict, mandatory expiration dates (e.g., maximum 30 calendar days). Open exceptions must be presented quarterly to the Board Audit Committee.
  4. Remediation & Closure: Upon expiration, the exposure must be brought back into full compliance through asset liquidation, hedge restructuring, or permanent policy amendment.

4. Internal Controls & Segregation of Duties (SoD)

Segregation of Duties (SoD) is the fundamental internal control principle requiring that indispensable steps in a financial transaction lifecycle are divided among different individuals to prevent error, fraud, collusion, and unauthorized transactions.

The Four Segregated Treasury Functions

+---------------------------------------------------------------------------------------------------------+
|                                 FOUR-WAY SEGREGATION OF DUTIES IN TREASURY                              |
|                                                                                                         |
|  [ FRONT OFFICE ]                 [ MIDDLE OFFICE ]             [ BACK OFFICE ]         [ ACCOUNTING ]  |
|  • Deal Negotiation               • Independent Risk Oversight  • Trade Confirmation    • GL Postings   |
|  • Market Order Execution         • Limit Monitoring & Alerts   • Electronic Settlement • Bank Recs     |
|  • Cash Positioning               • Valuation & Stress Testing  • Wire Release Auth     • Hedge Acc.    |
|  • Payment Initiation (Maker)     • Exception Tracking          • Bank Callback Check   • Subledger     |
+---------------------------------------------------------------------------------------------------------+
  1. Front Office (Execution / Dealing Desk): Interacts with market counterparties, agrees to transaction terms (interest rate swaps, FX forwards, commercial paper issuances), establishes daily cash positioning, and initiates payment instructions in the Treasury Management System (TMS) or banking portals (The "Maker").
  2. Middle Office (Risk & Analytics): Operates independently from trading. Responsible for daily marked-to-market valuations, independent pricing verification, monitoring counterparty exposure limits, running Value at Risk (VaR) models, and reporting limit breaches.
  3. Back Office (Confirmation & Settlement Operations): Handles counterparty trade confirmations (matching economic terms via SWIFT MT300/MT320 or electronic confirmation platforms like DTCC/Markit), validates settlement instructions (Standard Settlement Instructions - SSIs), and performs secondary dual authorization/release of outbound funds transfers (The "Checker").
  4. Treasury Accounting (Financial Reporting & Reconciliation): Operates under corporate controllership. Posts journal entries, calculates hedge accounting effectiveness (ASC 815/IFRS 9), and performs daily/monthly bank reconciliations independent of treasury cash handling.

The Maker-Checker (Dual Authorization) Principle

Under no circumstances may a single individual possess the authority or system permissions to:

  • Initiate and release an electronic funds transfer (Wire, ACH, RTP).
  • Create or edit a vendor bank account master record and authorize payments to that vendor.
  • Execute a financial derivative trade and confirm/settle that trade.
  • Open a bank account and act as the sole authorized signatory with unchecked release limits.
Loading diagram...
Dual Authorization (Maker-Checker) Electronic Payment Control Workflow

5. System Access Privilege Controls & Audit Trails

Modern treasury operations rely on enterprise systems (TMS, ERP, online banking portals, FX dealing platforms like FXall/360T, and SWIFT gateways). Information technology general controls (ITGC) and logical access privileges form the technical foundation of treasury internal controls:

  • Role-Based Access Control (RBAC): System permissions are granted strictly according to formalized job roles rather than individual requests. Cash analysts receive data entry/initiation rights; treasury managers receive approval/release rights; accounting staff receive read-only ledger access.
  • Principle of Least Privilege: Users are granted only the minimum access levels required to perform their daily job duties. Broad administrative rights are strictly segregated.
  • Dual Administrator Privileges: Modifying user entitlements, creating new user accounts, or editing approval routing matrices in a TMS or banking portal requires dual administrator sign-off (Administrator A proposes changes; Administrator B approves changes).
  • User Access Reviews (UAR): Formal, quarterly management reviews of all user access privileges across all banking portals and treasury systems. Immediate automated deactivation protocols for terminated or transferred employees prevent "orphan accounts" or permission creep.
  • Immutable Audit Trails: Systems must capture tamper-proof, timestamped logs of every user interaction, including login attempts, payment creations, approvals, limit overrides, changes to vendor/bank master data, and IP address origins.

6. Internal & External Audit: Walkthroughs & Deficiency Classifications

Both internal auditors and independent external auditors (e.g., PCAOB-registered public accounting firms) evaluate treasury controls through walkthroughs, Tests of Design (ToD), and Tests of Operating Effectiveness (ToE).

Auditing Methodologies in Treasury

  • Walkthroughs: Tracing a single transaction (e.g., a $50M foreign exchange forward contract) step-by-step from origination through confirmation, settlement, journal posting, and bank reconciliation to confirm control points exist.
  • Sample Testing (Operating Effectiveness): Selecting a statistically valid sample of wire transactions across the fiscal year to verify that 100% of payments had documented dual authorization, valid supporting documentation, and matching bank confirmations.

Control Deficiency Classification Framework (SOX / PCAOB Standards)

When auditors identify a control failure, it is classified into one of three standardized severity tiers:

Severity TierFormal DefinitionReporting & Escalation LevelFinancial Statement Impact
1. Control DeficiencyExists when the design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent or detect misstatements on a timely basis.Reported to Treasury Management and internal risk committees. Remediated within ordinary operational workflows.Remote or inconsequential risk of financial misstatement.
2. Significant DeficiencyA deficiency, or a combination of deficiencies, in internal control over financial reporting that is less severe than a material weakness, yet important enough to merit attention by those charged with governance.Formal written report to Senior Management (CFO/CEO) and the Board Audit Committee.Moderate risk; unlikely to cause a material financial misstatement but represents a serious control flaw.
3. Material WeaknessA deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the annual or interim financial statements will not be prevented or detected on a timely basis.Mandatory disclosure in SEC Form 10-K / 10-Q, resulting in an adverse audit opinion on ICFR under SOX 404. Immediate executive remediation plan required.High probability of material financial error, unauthorized transaction, or balance sheet misstatement.
Test Your Knowledge

Under the Three Lines of Defense governance framework for corporate treasury, which organizational group serves as the Second Line of Defense?

A
B
C
D
Test Your Knowledge

A corporate treasury department discovers that an employee was able to both initiate an outbound international wire transfer and perform the secondary electronic approval release in the banking portal due to misconfigured system roles. How should this control failure be characterized from an internal control perspective?

A
B
C
D
Test Your Knowledge

When a corporate treasury team needs to execute an emergency investment that temporarily exceeds the single-issuer concentration cap defined in the Board-approved Treasury Policy Manual, which procedure is required?

A
B
C
D
Test Your Knowledge

Under Sarbanes-Oxley (SOX) Section 404 and PCAOB audit standards, which condition defines a 'Material Weakness' in internal control over financial reporting?

A
B
C
D