How smart controls can help CFOs shield revenue streams

post-title

Today’s dynamic and volatile environment means that CFOs cannot count on revenue to keep trending upwards. If the goal is sustainable growth and profitability, there is little choice but to pursue deliberate and sustained deployment of strong internal controls to protect revenue, prevent fraud and ensure financial integrity.

Revenue leakage is a threat – and it requires active management. Revenue assurance (RA) is a repetitive, active and self-improving mechanism that is driven by the CFO and supported by all the process owners. It employs data quality and process improvement methods to improve profits, revenues and cash flows without influencing demand. Telecom companies already run RA departments, and the concept can be extended to any other organisation.

The health of the balance sheet and the organisation counts on strong RA as a starting point. Proper RA, on its part, depends on effective internal controls.

Systems, policies and procedures implemented by an organisation to drive efficiency, accuracy, compliance and prevention of errors and losses, also provide a structured approach in monitoring and managing transactions. When they work, the organisation is safe. When they fail, then we expect revenue leakage, inefficiency and wastage, fraud, regulatory non-compliance, and customer dissatisfaction. In extreme cases, severe non-compliance may happen, leading to mug shots of CFOs and CEOs ending up in the evening news.

The foundation for a good control environment is leadership. The “tone at the top” is critical. The overall attitude, awareness and actions of the board and senior management regarding controls, and their importance define how well the employees and partners drive business controls.

Risk assessment – the process of identifying and analysing the risks that could affect the organisation’s revenue streams – is the next step. Elements such as product delivery, pricing, billing, collections and reporting all have risks. A structured analysis of these risks helps in defining the remit of revenue assurance control activities. 

Being a repetitive programme, it is important to have information, communication and monitoring mechanisms. Reporting of risks, quantification of revenue losses and other metrics helps to gauge how well the programme is doing.

Implement robust financial policies and procedures

To lay the correct environment for an effective RA programme, organisations should establish financial policies that clearly define roles and responsibilities in the revenue cycle. Such policies should minimally cover revenue recognition, invoicing, collections, refunds and discounts. The mantra of “document what is done, and do what is documented” rings true. All RA work will be guided by the financial policies and procedures.

Manual processes are inherently risky because they depend on humans, and humans are fallible. There is a need to ensure that to the extent possible, processes are automated. This promotes efficiency and control. Automated financial systems can significantly enhance internal controls in areas such as billing, revenue management and fraud detection. There is also opportunity in judicious use of artificial intelligence and machine learning to analyse transaction patterns and flag suspicious activities for further investigation. 

RA concepts can be applied wherever data is available. Some RA work is done on simple applications like spreadsheets and Python scripts. However, for businesses with large data sets, it might make sense to procure revenue assurance software.

Regular internal and external audits are also crucial in evaluating the effectiveness of internal controls and identifying potential weaknesses that merit RA attention. In a sense, the CFO should use audits as a trusted rear-view mirror (looking at the current and past control issues) and also an early warning system (identifying risks on the horizon).

Change and innovation inadvertently open loopholes. Therefore, properly executed audits are important in addressing risks which naturally emerge as businesses take advantage of opportunities.

Using data from various systems, RA teams also run their own audits and reconciliations, albeit on a shorter cycle. These second-level controls provide ongoing assurance that the operational teams in areas such as treasury and reporting are carrying out the first-level checks in a manner that is consistent and accurate.

Strengthen access controls and authorisation processes

Limiting access to financial systems and sensitive data is crucial in safeguarding revenue streams. Technology has made access easy, but it also contains risks. There are many horror stories of the technology stack wrecking business operations and leaving the corporate image in tatters. Therefore, controls such as access rights policies, passwords, intrusion detection and regular vulnerability patching must be in place. 

Organisations should implement strong password policies, multi-factor authentication, and role-based access controls to prevent unauthorised access. Approval workflows for financial transactions with the requisite levels of authority also help to place limits on sensitive transactions.

Strengthening internal controls to safeguard revenue streams is an ongoing process that requires a proactive approach, continuous monitoring, and adaptation to emerging risks in order to put in place and maintain robust financial policies. Use of technology can promote this. Encouraging ownership and applying a strict audit regime validates the control environment. Ultimately, a well-structured internal control framework fosters transparency, accountability, and fortifies the RA landscape.

Related articles

The making of a strategic CFO

CFO and executive coach Jay Atara outlines the vital transition from a numbers-focused finance director to an influential strategic partner. Drawing on deep industry experience and the rise of AI, he delivers a roadmap for finance leaders ready to step off their technical island and lead with commercial foresight.

How Car & General CFO Sam Njenga is keeping a 90-year-old business agile

Car & General is entering another period of reinvention after nine decades of surviving changing markets. For CFO Sam Njenga, staying relevant necessitates remaining close to customers, investing in people, embracing technology and being willing to rethink what comes next.

Top