The $2 Million Wire That Should Never Have Gone Through
A few months ago, I sat in a room while an audit team walked through a finding that stopped everyone’s coffee mid-sip. A $2 million wire transfer had gone out with a single approval. No second signature or dual control. The system didn’t flag it, nor did the approver question it. It sat there, quietly compliant on the surface, until an audit six months later pulled the thread.
No money was lost. Nothing malicious happened. And that is exactly why this story is worth telling, because it is not a story about fraud. It is about what happens when a well-designed control exists on paper and quietly stops existing in practice.
I have sat across the table from enough CFOs to know this is not rare. It is just rarely discussed.
A process failure, not a technology failure
The company in question had a documented approval matrix. It had segregation of duties written into policy and the framework was sound. What broke was discipline: a threshold that had gone stale, an exception that got logged and never reviewed, a “trusted” team member who skipped a step because time was short and nobody was watching closely enough.
That distinction matters, because the fix for a broken process is no more technology bolted on top of the same gaps. It is rebuilding the discipline first, then using technology to make sure it never quietly erodes again.
What a proper treasury approval process requires
Every payment above a certain threshold should move through the same process, regardless of company size:
- Transaction initiation, with full beneficiary and purpose detail captured up front
- First-level review against budget and documentation
- Threshold authorization through a documented, regularly reviewed approval matrix
- Dual-control verification, so the person who releases a payment is never the person who requested it
- Release and execution through an authenticated channel
- Reconciliation and audit trail, closed out by a team with no origination or approval access
Segregation of duties is the principle that holds this together. The initiator cannot approve. The approver cannot be released. The reconciler cannot touch either. When those boundaries blur, even briefly, that is the moment risk stops being theoretical.

Where AI earns its place
I want to be direct about this, because there is a lot of noise around AI in finance right now. AI does not fix a broken process. It has no opinion on whether your approval matrix is three years out of date. What it does is remove the conditions that let good controls quietly decay:
- It intelligently extracts payment data from invoices and supporting documents and auto-populates fields, cutting manual entry and the errors that come with it
- It validates vendor master data and detects anomalies before payment execution and catches duplicate invoices, duplicate payments, and unusual bank account changes
- It scores every transaction for risk in real time, instead of waiting for a quarterly sample
- It flags high-risk transactions for fraud and compliance concerns before they go further
- It orchestrates approval workflows based on policy, authority limits, and business rules to the right person automatically and escalates the moment an SLA is missed
- It checks cash availability before a payment is released
- It creates a complete audit trail and simplifies reconciliation
- It monitors 100% of transactions for compliance, not a sampled percentage
That last point is the one I keep coming back to. Most treasury failures are not sophisticated. They are the accumulation of small, unreviewed exceptions. AI’s real value is consistency at a scale no manual review can sustain.
Organizations rarely get targeted because someone is out to get them. They get exposed because their approval matrix has not been touched in years; their exception logs are read by no one, and their most trusted people are the ones most likely to skip a step out of habit.
AI does not replace judgment in treasury. It removes the noise and brings consistency to every stage of the process, so the judgment that matters gets applied where it counts.
I have been building some of this with Claude AI, and I am glad to walk anyone through what it really looks like in practice. If your approval matrix has not been reviewed this year, that conversation is worth having sooner rather than later.
