Your Company Has an Approval Process. Why Does Everyone Know How to Bypass It?

by | Sep 9, 2026 | Lee and Hew | 0 comments

The Company Has Rules, but Employees Also Know the Shortcuts

Most businesses do not deliberately design weak approval processes. As a company grows, management introduces controls to ensure that purchases, payments, expenses, discounts, contracts and other important decisions receive appropriate review before they are completed. A purchase above S$10,000 may require director approval, a new supplier may need finance verification, and an employee expense may require supporting documents before reimbursement. On paper, the process can look excellent. The problem begins when employees also know exactly how to get around it. A purchase is divided into smaller amounts, an urgent payment is processed first and documented later, a manager gives approval through a casual message, or somebody asks finance to “just do it this time.” Eventually, the official approval process still exists, but employees have developed an unofficial process that is faster, easier and understood by almost everyone. For business owners and directors, that should raise an important question: if everybody knows how to bypass a control, is it really a control anymore?

Approval Processes Exist Because Businesses Cannot Depend on Trust Alone

Trust is essential in any organisation, but trust and internal controls serve different purposes. A business may have employees who have worked together for ten or twenty years and genuinely trust one another, yet it still benefits from appropriate approvals. Controls help reduce mistakes, identify unusual transactions, clarify authority and ensure important decisions receive a second pair of eyes. They can also protect honest employees by making responsibilities clear. If one person can create a supplier, change its bank details, approve an invoice and arrange payment without independent review, the company has created unnecessary exposure even if that employee is completely trustworthy. A good approval process therefore does not begin with the assumption that everyone is dishonest. It recognises that mistakes, misunderstandings, pressure and fraud can occur in any organisation, and that important transactions should not depend entirely on one person’s judgement.

The First Bypass Usually Sounds Completely Reasonable

Approval processes rarely collapse because an employee announces, “I am going to ignore company policy from now on.” The first exception usually sounds sensible. A supplier needs urgent payment before releasing an important delivery, but the director is travelling. Finance is told to make the payment and obtain approval afterwards. Nothing goes wrong. The next month, another urgent situation appears and the same shortcut is used. Soon, employees learn that describing something as urgent is enough to move around the normal process. What began as a reasonable exception gradually becomes an alternative procedure. This is why management should pay attention not only to whether exceptions occur but also to how frequently they occur, who authorises them and whether the same reasons keep appearing. An occasional exception may be necessary in a real business. A recurring exception is often evidence that the process and the way the company actually operates are no longer aligned.

“Just Approve First” Can Become a Dangerous Company Habit

One of the easiest ways to weaken a control is to reverse the order of events. The policy says approval should occur before the transaction, but operational pressure encourages employees to complete the transaction first and collect signatures later. Over time, approval becomes administrative housekeeping rather than genuine review. Imagine a manager receives 30 transactions at month-end that have already been paid and is asked to approve them retrospectively. The manager knows that rejecting a transaction will not recover money that has already left the bank, so the signature becomes largely symbolic. A control that was designed to prevent inappropriate expenditure has quietly transformed into a record showing that somebody eventually looked at it. Businesses should therefore distinguish between pre-approval, which can influence whether a transaction proceeds, and retrospective acknowledgement, which often cannot.

Approval by WhatsApp May Feel Efficient Until Nobody Can Explain the Decision

Modern businesses communicate quickly. Managers may use messaging applications to answer employees, discuss customers and make decisions while travelling. There is nothing inherently wrong with using convenient communication tools, but problems arise when important approvals become fragmented across informal channels. A manager replies “OK” to a message without seeing the complete supporting information. Months later, finance cannot determine what exactly was approved. Was the manager approving the supplier, the amount, the commercial terms or merely acknowledging the message? An effective approval process should leave enough evidence for another person to understand what decision was made and on what basis. Speed matters, but so does traceability. A business should not need to search through an employee’s personal message history to reconstruct why a significant transaction occurred.

The S$10,000 Limit Can Accidentally Teach Employees How to Avoid the Director

Approval thresholds are common because senior management should not need to approve every small purchase. Suppose company policy allows department managers to approve expenditure below S$10,000 while anything at or above S$10,000 requires director approval. The structure appears reasonable. Then finance notices an unusual pattern: S$9,800, S$9,600, S$9,950 and S$9,750 payments repeatedly appear from the same department or supplier. There may be legitimate explanations, but the pattern deserves attention. Employees may have discovered that keeping transactions below the threshold avoids additional scrutiny. In more concerning situations, one S$20,000 purchase could be deliberately divided into two smaller transactions. A control that looks only at individual transaction values may therefore miss the commercial reality that several transactions belong to one decision.

Splitting Transactions Is Not Always Fraud, but It Should Still Make Someone Ask Why

It is important not to jump from an unusual pattern to an accusation. Two invoices below an approval threshold may represent two genuinely separate purchases. A supplier may bill work in stages, or the timing of deliveries may explain multiple transactions. Strong governance is not about treating every employee as suspicious. It is about noticing patterns and asking reasonable questions. If several purchases repeatedly fall just below an approval limit, management should understand why. The explanation may be completely legitimate. If it is not, the company has identified a weakness before it becomes a larger problem. Controls are most useful when they encourage investigation rather than automatic conclusions.

Employees Often Bypass Controls Because the Official Process Is Too Slow

Management should also resist the temptation to blame employees immediately. If nearly everyone is bypassing the approval process, the process itself may be part of the problem. Perhaps every purchase above S$2,000 requires a director who is frequently unavailable. Maybe suppliers must wait five working days for approval while operations needs materials tomorrow. Perhaps the system requires six separate steps to approve routine expenditure. Employees under pressure to keep customers happy and operations moving will eventually find shortcuts. In this situation, stricter enforcement alone may not solve the underlying issue. Management should ask whether approval limits remain appropriate, whether authority can be delegated and whether routine low-risk transactions can follow a simpler path. A good control should protect the organisation without making normal business unnecessarily difficult.

A Control Nobody Can Follow Is Not Necessarily a Strong Control

Businesses sometimes confuse complexity with strength. A process with five signatures, three forms and two system approvals may look highly controlled, but if employees routinely work around it, the practical control environment can be weaker than a simpler system that everyone follows. Effective controls should be proportionate to the risk. Buying S$200 of ordinary office supplies should not necessarily require the same level of review as signing a S$200,000 contract. When every transaction is treated as high risk, managers become overwhelmed and approvals become mechanical. They may begin approving items without reading them because there are simply too many. A well-designed process concentrates attention where management judgement is most valuable rather than spreading that attention so thinly that every approval becomes a click.

Managers Can Become the Biggest Bypass Route

Employees are not always the ones weakening controls. Sometimes managers themselves create the exceptions. A senior executive may tell finance, “I already spoke to the CEO, just process it.” A department head may insist that a purchase is too urgent to wait. Because the instruction comes from someone senior, employees may feel uncomfortable questioning it. Over time, the organisation learns that hierarchy can override procedure. This is particularly dangerous because internal controls are strongest when senior management demonstrates that the rules apply to everyone. If leaders repeatedly bypass controls for convenience, employees receive a clear message that procedures are optional when someone important wants something done quickly. The tone of an organisation’s control environment therefore starts at the top.

“The Boss Said So” Should Not Be the Entire Audit Trail

There will be circumstances where senior management legitimately overrides a normal process. Businesses face emergencies, opportunities and unusual situations that policies cannot anticipate perfectly. The issue is not that management override must never occur. The issue is whether it is transparent, documented and reviewable. If a director authorises an exceptional payment, there should be enough information to show what was authorised and why the normal process was not followed. Otherwise, “the boss said so” becomes a convenient explanation that nobody can independently verify. A controlled organisation allows management flexibility while ensuring that flexibility does not become invisible.

Supplier Bank Detail Changes Deserve More Than a Quick Approval

One particularly sensitive area involves changes to supplier payment information. A finance employee receives an email apparently from a long-standing supplier saying that its bank account has changed. The invoice looks genuine, the email address looks familiar and the supplier is waiting for payment. If the company treats this as a routine data update, an employee may change the bank details and process the payment. But fraudulent payment diversion can exploit exactly this type of situation. A stronger process may require independent verification through a known contact or another trusted channel before bank details are changed. The principle is simple: some changes deserve additional scrutiny because the consequences of getting them wrong are substantial.

Two Approvals Are Useful Only When Two People Actually Review the Transaction

Companies sometimes assume that requiring two approvers automatically creates a strong control. That depends on what the approvers actually do. If the first person approves the payment because the second person will check it, while the second person assumes the first person already checked everything, the company has two signatures but potentially no meaningful review. The same problem occurs when senior managers receive hundreds of approval requests and click through them quickly. Segregation of duties is valuable because it introduces independent involvement, but independence only helps when each person understands what they are responsible for reviewing. Management should therefore define the purpose of approvals rather than merely counting how many names appear on the transaction.

Repeated Approvals Can Create Approval Fatigue

Approval fatigue is an underappreciated risk. A director who receives five significant transactions a week can reasonably examine them. A director who receives 300 routine requests may begin approving almost automatically. The company technically has strong controls because everything requires senior approval, but the practical quality of review has deteriorated. This is another reason approval thresholds should evolve with the business. As transaction volumes increase, management may need clearer delegation, automated checks and exception-based reporting. Senior leaders should spend their attention on transactions that genuinely require senior judgement rather than becoming the final click in every routine process.

Growing Businesses Often Outgrow Their Original Approval Rules

A company with ten employees may work perfectly well with the founder approving every significant expense. The founder understands every customer, supplier and project and can personally question unusual transactions. Five years later, the same company may have 100 employees, multiple departments and thousands of monthly transactions. If the founder still needs to approve everything, the process becomes a bottleneck. Employees begin searching for shortcuts because normal operations cannot wait. This is not necessarily evidence that the original control was poorly designed. It may simply mean the business has outgrown it. Internal controls should develop alongside the organisation rather than remaining frozen in the structure that worked when the company was much smaller.

System Access Can Quietly Bypass a Written Approval Process

A company may have an excellent policy document while its software tells a different story. The policy says only managers can approve purchases, but the accounting system gives several employees administrator rights. The policy requires independent approval for supplier creation, but one employee can create a supplier and process its invoices. Written controls are only effective when system permissions support them. As employees change roles, receive temporary access or leave the company, access rights can accumulate. Periodic reviews of user permissions can therefore be just as important as reviewing the approval policy itself. Management should know not only who is supposed to approve transactions but also who technically has the ability to create, modify, approve or delete them.

Temporary Access Has a Habit of Becoming Permanent

An employee goes on leave, so another employee receives temporary access to perform an important task. Three weeks later, the original employee returns, but nobody removes the additional permissions. Another temporary arrangement occurs six months later. Eventually, several people have access rights they no longer need. Nothing malicious has happened; the problem emerged through ordinary operational convenience. This illustrates how controls can weaken gradually rather than through one dramatic failure. Businesses should therefore include access reviews as part of routine governance, particularly when employees transfer departments, receive promotions, take on temporary responsibilities or leave the organisation.

The Most Dangerous Workaround May Be the One Everyone Thinks Is Normal

Some bypasses become so familiar that employees stop recognising them as exceptions. “Finance always does it this way.” “The director is busy, so we get the signature later.” “That supplier has been with us for years, so we don’t need to verify anything.” “The manager always approves these.” Once a workaround becomes part of company culture, new employees learn it from experienced colleagues and the unofficial process can become more influential than the written policy. This is why management cannot assess internal controls solely by reading procedure manuals. It needs to understand what employees actually do when a real transaction arrives on a busy Monday morning.

Internal Controls Should Be Tested Against Reality

A useful exercise is to select a transaction and follow it from beginning to end. Who requested the purchase? Who selected the supplier? Who approved the amount? Who received the goods or services? Who entered the invoice? Who could change supplier information? Who authorised payment? What evidence remains after the process is complete? Management may discover that the actual workflow differs considerably from the documented process. This type of walkthrough can reveal duplicated steps, missing approvals, excessive access and unofficial shortcuts. It also allows employees to explain why they work around certain requirements. Sometimes the review discovers risk; sometimes it discovers an opportunity to simplify an unnecessarily difficult process.

Exceptions Should Be Visible Rather Than Hidden

A strong approval system does not necessarily prohibit all exceptions. Instead, it makes them visible. If an emergency purchase bypasses the normal process, management can require the reason to be documented and the transaction to be included in an exception report. If a director overrides a standard approval, that action can be recorded. If a supplier’s bank details change, the system can flag the update for independent verification. Visibility changes behaviour because unusual actions no longer disappear into normal transaction volume. It also allows management to identify patterns. Ten isolated emergencies involving the same department may indicate that the company does not actually have ten emergencies; it may have one broken process.

Data Can Reveal What Individual Approvers Cannot See

A manager reviewing one S$9,800 payment may see nothing unusual. Someone analysing a full year of transactions may notice that the same department made 40 purchases between S$9,500 and S$9,999. Similarly, one weekend transaction may be reasonable, but repeated weekend payments by the same user could deserve attention. Modern accounting systems contain information that can help businesses identify patterns that are difficult to see during transaction-by-transaction approval. Management does not need to treat every unusual pattern as evidence of wrongdoing. The value lies in using data to decide where questions should be asked.

Internal Control Is Also About Protecting Good Employees

Controls are sometimes described as though their sole purpose is catching dishonest people. That misses an important benefit. Clear procedures protect employees from inappropriate pressure and ambiguous responsibility. If company policy requires independent verification before supplier bank details are changed, a finance employee can tell an impatient manager that the verification is required rather than personally deciding whether to take the risk. If approval limits are clear, employees know what they can authorise without worrying that management will later say they exceeded their authority. Good controls therefore create boundaries that allow people to work confidently.

Audit Services Singapore and Lee & Hew PAC: Controls Should Work Outside the Policy Manual

For businesses reviewing their governance and financial processes, the objective should not be to accumulate more signatures or produce a thicker policy manual. It should be to establish controls that work in everyday operations. Audit Services Singapore is the online presence of Lee & Hew Public Accounting Corporation (Lee & Hew PAC), a Singapore public accounting corporation providing professional services including audit, accounting, taxation, company secretarial, regulatory compliance and advisory support. For Lee & Hew PAC’s clients and the wider business community, a useful internal-control conversation should therefore go beyond asking whether an approval policy exists. The more revealing question is whether transactions actually follow that policy, whether exceptions are visible and whether management receives enough information to recognise when controls are being routinely bypassed.

Independent Review Can Challenge Familiar Workarounds

One reason longstanding weaknesses survive is that employees become accustomed to them. A process that looks unusual to an outsider may feel completely normal to someone who has followed it for ten years. Independent professional review can bring a different perspective by asking why particular steps exist, whether responsibilities are appropriately separated and whether the documented process reflects reality. This does not mean every workaround is automatically wrong. Some may reveal that an old procedure genuinely needs to be modernised. The value comes from distinguishing practical improvements from shortcuts that create unnecessary exposure.

The Solution Is Not Automatically More Approvals

When management discovers that controls are being bypassed, the instinct may be to add another approval. That can make matters worse. If employees already avoid a process because it is too slow, adding more steps can create even stronger incentives to work around it. A better response begins by understanding why the bypass occurs. Is the approval threshold unrealistic? Is the responsible manager unavailable? Is the system difficult to use? Are responsibilities unclear? Does the company lack an emergency procedure? Or are employees deliberately avoiding scrutiny? Different causes require different solutions. Effective control design balances risk, speed and accountability rather than assuming that more bureaucracy always means more protection.

Management Should Make the Correct Process the Easiest Process

The strongest control environment is one where following the rules is easier than avoiding them. Approvals should be accessible through appropriate systems, responsibilities should be clear and routine decisions should move quickly enough that employees do not need informal shortcuts. Higher-risk transactions can receive stronger scrutiny while low-risk activities remain efficient. When an exception is genuinely necessary, there should be a defined method for handling it rather than forcing employees to invent one. Good process design aligns operational reality with governance instead of making the two compete.

Directors Should Ask Questions That Go Beyond “Do We Have an Approval Policy?”

A director reviewing internal controls should not stop after seeing a written procedure. More useful questions include whether employees understand the process, how frequently exceptions occur, who can override approvals, whether system access matches documented authority, how supplier bank changes are verified and whether management reviews unusual transaction patterns. Directors can also ask what happens when an approver is on leave, whether retrospective approvals are common and how the business handles urgent payments. These questions reveal how the control functions under real operating conditions. The existence of a policy answers only the first question; its effectiveness depends on what happens after the policy leaves the page.

A Bypass Can Be a Warning About Fraud—or a Warning About Bad Process Design

When employees circumvent approvals, management should remain open to two very different possibilities. The first is that someone is intentionally avoiding scrutiny, which can indicate a serious control risk. The second is that legitimate employees are struggling with a process that no longer fits the business. Both matter. The first requires investigation and stronger safeguards; the second may require redesign and clearer delegation. Treating every bypass as misconduct can prevent employees from speaking honestly about broken processes. Treating every bypass as harmless convenience can allow genuine problems to grow. Good governance requires management to distinguish between the two through evidence and reasonable enquiry.

The Real Test Comes When the Company Is Under Pressure

Approval systems are easy to follow when there is plenty of time. Their real quality becomes visible when a major customer needs something urgently, a supplier threatens to stop delivery, the director is overseas or finance is trying to complete payments before a long weekend. If the process collapses every time the business experiences pressure, management should question whether it has designed a practical control. Strong controls should anticipate realistic operating situations and provide controlled ways to deal with them. The goal is not to make the business inflexible. It is to ensure that urgency does not automatically remove accountability.

Conclusion: A Control That Everyone Can Bypass Is Mostly a Suggestion

An approval process has value only when it influences what actually happens. A company can have detailed policies, sophisticated accounting software, multiple approvers and carefully defined authority limits, yet still operate with weak controls if employees know that urgent requests, informal messages, retrospective signatures or transaction splitting can circumvent the system. The problem may come from deliberate avoidance, poor process design, management behaviour or a company that has simply outgrown its original procedures. Whatever the cause, management should not be satisfied merely because the approval policy exists.

The Better Question Is “How Would Someone Get Around This?”

One of the most useful questions management can ask when reviewing a control is surprisingly simple: “If somebody wanted to bypass this process, how would they do it?” The answer may expose approval thresholds that can be manipulated, excessive system access, informal management overrides, weak supplier verification or processes so cumbersome that employees have created their own shortcuts. It may also reveal that certain controls are working exactly as intended. For businesses working with Lee & Hew Public Accounting Corporation (Lee & Hew PAC) through Audit Services Singapore, the broader lesson is that strong governance is not measured by how many policies a company can produce. It is measured by whether the organisation’s actual behaviour reflects the controls management believes are in place. When everyone knows the shortcut better than the official process, the shortcut has effectively become the process—and that is the point when management should start asking why.