11.3 Financial Controls
Key Takeaways
- Financial controls are policies, systems, and routines that protect assets, ensure reliable reporting, and promote compliance with authorized spending.
- Accounts payable (AP) systems should enforce approved vendors, matched invoices, authorized payment, and secure disbursement—not merely pay bills quickly.
- Checks and balances (segregation of duties, dual authorization, reconciliations) reduce fraud and error risk by ensuring no single person controls a full transaction cycle.
- Auditing principles include independence, evidence-based testing, risk-based focus, and clear reporting of findings to management and governance.
- Executives own the control environment: tone at the top, timely remediation of audit findings, and alignment of controls with operational reality and regulatory expectations.
Financial Controls
Quick Answer: Financial controls are the policies, procedures, systems, and oversight practices that safeguard assets, authorize transactions, ensure accurate financial information, and detect or prevent fraud and waste. On the FACHE Board of Governors exam (Finance F6), focus on accounts payable systems, checks and balances, and auditing principles—and how executives design a control environment that works in real healthcare operations.
Healthcare organizations move enormous cash through payroll, supplies, pharmaceuticals, construction, physician payments, and patient refunds. Even mission-driven nonprofits face fraud risk, billing error risk, and donor/bondholder expectations for stewardship. Controls are not bureaucracy for its own sake; they are how leaders prove reliability to boards, lenders, regulators, and the public.
The Control Environment
Before process detail, examiners and boards look for a control environment:
- Tone at the top — leaders do not override controls for convenience or favorites
- Clear policies — purchasing, contracting, travel, conflicts of interest, signature authority
- Competent people — finance and operations staff trained on systems and red flags
- Information systems — ERP, procurement, payroll, and revenue systems with access controls
- Monitoring — management review, internal audit, external audit, compliance review
Trap: Believing “we are a small hospital; everyone trusts each other” is a control strategy. Trust is valuable; segregation of duties is still required. Many healthcare fraud cases involve long-tenured, trusted employees.
Accounts Payable (AP) Systems
Accounts payable processes vendor invoices and other non-payroll disbursements. A sound AP system typically enforces a three-way match (or controlled exception process):
- Purchase order (PO) — what was authorized to buy, at what price/terms
- Receiving documentation — what actually arrived or what service was accepted
- Vendor invoice — what the vendor bills
Payment should issue only when these align within policy tolerances, with documented exceptions and dual review for mismatches.
AP control design elements:
| Control | Purpose |
|---|---|
| Approved vendor master | Reduces fictitious vendor fraud; supports tax reporting (e.g., 1099 processes) |
| Delegation of authority matrix | Limits who can approve purchases/payments by amount and type |
| Segregation: request vs approve vs receive vs pay | Prevents one person from creating and paying a fake invoice |
| Electronic payments with dual release | Protects ACH/wire fraud vectors |
| Invoice imaging and audit trail | Enables review and external audit evidence |
| Periodic vendor statement reconciliation | Catches missing checks, duplicates, and unrecorded liabilities |
| Duplicate payment detection | Same invoice number/amount/vendor flags |
Scenario — Rush check request. A department demands an emergency payment to a new supplier “today” outside procurement. Strong AP requires elevated approval, vendor setup controls, and post-payment review—not automatic bypass because operations are busy. Executives should design fast paths that remain controlled, not uncontrolled exceptions.
Healthcare-specific AP risks:
- High-volume medical-surgical supply and implant invoices with complex pricing
- Physician and contracted provider payments (must align with compliance/fair market value processes)
- Construction pay applications and retainage
- 340B, group purchasing organization (GPO), and rebate complexity (coordination with pharmacy and supply chain)
- Patient refunds (AP or related disbursement processes) as a fraud-prone area if poorly controlled
AP speed matters for vendor relationships and early-pay discounts, but accuracy and authorization outrank raw cycle-time vanity metrics.
Checks and Balances (Segregation of Duties and Related Controls)
Checks and balances ensure that critical steps in a transaction cycle are split so that errors and fraud require collusion to succeed. Classic segregation of duties (SoD) separates:
- Custody of assets (cash, inventory, check stock, payment token access)
- Recording in the books (journal entries, invoice entry)
- Authorization (approving purchases, write-offs, adjustments)
- Reconciliation (bank recs, inventory counts vs perpetual records)
Examples across the enterprise:
| Area | Weak design | Stronger design |
|---|---|---|
| Cash | Same person opens mail, posts receipts, and prepares bank rec | Split receipting, posting, and independent bank reconciliation |
| Payroll | Manager can add employees and approve their own pay changes without HR/payroll check | HR masters employees; managers approve time; payroll processes; audit samples |
| Inventory | Storeroom clerk orders, receives, and adjusts inventory alone | Separate requisition, receiving, and cycle-count adjustments with review |
| IT access | Shared logins to ERP payment module | Unique IDs, role-based access, periodic access reviews |
| Charity care / write-offs | Collector can both negotiate and fully write off large balances alone | Tiered write-off authority and secondary review |
Compensating controls are used when small teams cannot fully segregate: increased supervisory review, system-enforced workflows, surprise audits, and camera/physical controls. Compensating controls are not an excuse to ignore SoD forever as the organization grows.
Other balancing mechanisms:
- Dual signatures / dual electronic release above thresholds
- Budget vs actual review by cost-center leaders
- Capital authorization gates separate from operating spend
- Conflict-of-interest disclosures for purchasing and contracting
- Whistleblower / hotline channels protected from retaliation
Scenario — CFO override. A CFO directs AP to pay a vendor without a PO “because the CEO wants it done.” Even if the business need is real, repeated overrides destroy the control environment. The executive fix is a documented emergency purchase policy with post-audit, not cultural acceptance of override as normal.
Auditing Principles
Auditing provides independent assurance that controls and financial statements are reliable. Healthcare leaders encounter multiple audit types:
Internal audit
- Employed or co-sourced function reporting functionally to the audit committee (or board) and administratively to management
- Risk-based annual plan covering financial, operational, IT, and sometimes clinical-support processes
- Issues findings with management responses and tracks remediation
- Should be free to examine sensitive areas without management filtering of conclusions
External financial audit
- Independent CPA firm opines on financial statements (and often tests internal control over financial reporting to the extent required by standards and engagement terms)
- Critical for bond covenants, banks, boards, and public trust
- Management still owns the financial statements; auditors provide opinion, not a guarantee against all fraud
Compliance, coding, and program audits
- May include RAC/MAC-style payer audits, OIG risk areas, privacy, research billing, and charity care eligibility
- Findings can create repayment, penalties, and corporate integrity obligations
- Financial controls and compliance controls must connect—especially around revenue recognition and contractual adjustments
Core auditing principles executives should know:
- Independence and objectivity — auditors must not audit their own operational work
- Evidence — conclusions rest on testing and documentation, not anecdote
- Risk-based focus — higher risk and materiality get more attention
- Professional skepticism — “trust but verify,” especially where incentives or override exist
- Clear reporting — findings, risk rating, root cause, and accountable owners
- Follow-up — open findings without remediation are governance failures
Trap: Treating a clean external audit opinion as proof that operations have no waste or fraud. Financial statement audits sample; they are not a substitute for management monitoring, internal audit, or compliance programs.
Integrating Controls with Operations and Culture
Controls fail when they are so slow that staff create shadow systems (personal credit cards, off-system POs, manual workarounds). Fellows should demand:
- Controls proportionate to risk and dollar thresholds
- User-friendly procurement and AP tools
- Training for non-finance managers who approve invoices
- Metrics that balance cycle time and exception rates/duplicate payments
- Board audit committee engagement without micromanaging operations
Link to earlier finance topics: Reimbursement complexity increases revenue-side control needs (charge capture, contractual allowances, denials). Productivity pressure can tempt managers to cut corners on receiving or inventory counts—raising loss and safety risk. Strong executives hold both efficiency and control as non-negotiable.
Exam-ready summary: AP systems authorize and match spend before payment; checks and balances (especially segregation of duties) prevent single-person control of transaction cycles; auditing principles emphasize independence, evidence, risk focus, reporting, and remediation. The executive’s job is to maintain a control environment where overrides are rare, documented, and scrutinized—and where audit findings actually get fixed.
Which practice BEST reflects a strong accounts payable control design?
Segregation of duties in financial controls primarily aims to:
Which statement BEST reflects sound auditing principles for a healthcare organization?