Most finance teams treat the systems that produce their numbers as somebody else’s problem. That was defensible when the ledger was a book. It is not defensible now, when the figures in a set of financial statements are assembled, calculated and reported by software that very few people in the organisation fully understand.

The control environment moved and the audit followed

When a sales invoice is raised automatically, priced from a rate table, posted to the ledger without human intervention and consolidated by a scheduled job, the control that matters is not a signature. It is who can change the rate table, whether that change is logged, and whether anyone reviews the log.

This is why a systems audit is no longer a specialist add-on for large organisations. For any business with meaningful automation, it is where the real risk to the accounts now sits.

Four questions worth asking your own team

Who can change what? Access rights tend to accumulate. Staff move roles and keep old permissions; a finance clerk who once needed supplier maintenance rights still has them three years later. The combination of raising a supplier and approving its payment is the classic fraud exposure, and it is usually created by accident rather than design.

Would you know if data changed? Audit logging is often available and switched off, or switched on and never reviewed. A log nobody reads is not a control.

How do changes reach production? A customisation applied directly to a live system, untested, is how correct data becomes incorrect overnight. There should be a route from request to testing to deployment, and evidence that it was followed.

Could you recover? Backups exist almost everywhere. Tested restorations are rare. An untested backup is a belief, not a control — and the moment you discover which is a bad moment.

Spreadsheets deserve the same scrutiny

The most material calculations in many businesses happen in a spreadsheet nobody has version-controlled: the depreciation schedule, the impairment model, the consolidation, the tax computation. These sit outside the system, outside change control, and frequently outside anyone’s review.

They should be treated as part of the financial system, because that is exactly what they are.

Where to begin

Start with an access review. It costs little, requires no external tooling, and in our experience surfaces the largest number of genuine issues per hour spent. Everything else follows more easily once you know who can do what.

This article is general guidance and not advice on any particular set of facts. If you would like your systems reviewed as part of an audit or on their own, our team in Gaborone will be glad to help.