Collection Controls: Cash, ACH, Wire, and Form 8300

Internal controls for revenue collection are the checkpoints, approvals, and reviews a business uses to make sure every payment it earns lands in the company’s bank account and shows up correctly in the books. The working model is simple: split the job across enough people that no one person can both take money and hide the theft, create a paper trail the moment funds arrive, and have someone independent compare that trail to the bank each month. Everything else is detail.

The Two Types of Controls You Need

Every control in the revenue cycle either prevents a problem or detects one after the fact. A system that relies too heavily on one type leaves the gap the other was built to close.

Preventive controls act as gatekeepers. Requiring a manager to approve a customer’s credit limit before extending terms is preventive. So is restricting who can access the billing module in your accounting software. The design goal is to make the mistake or theft impossible in the first place.

Detective controls assume something has already slipped through. The classic example is the monthly bank reconciliation, where someone compares the ledger’s cash balance to the bank’s and investigates every discrepancy. Reviewing aged receivables, auditing write-offs, and sending balance confirmations to customers are all detective controls.

No system eliminates risk entirely. The practical question is whether a control’s cost is proportional to the exposure it addresses. At some point additional controls cost more than the losses they prevent, and that is the sensible stopping point.

Splitting the Job Across People

If one principle carries more weight than any other, it is segregation of duties. No single person should control enough of a transaction to both commit fraud and conceal it. In revenue collection, that means three functions belong in three different sets of hands:

  • Authorization. Approving transactions, such as setting credit terms, granting discounts, or writing off a balance as uncollectible.
  • Custody. Physically handling the asset, whether that means opening envelopes containing checks, managing a cash drawer, or preparing the bank deposit.
  • Recording. Entering the transaction into the accounting system, posting payments to customer accounts, or adjusting the general ledger.

When one employee handles both custody and recording, the door swings wide. That person can pocket a customer’s check and then write the receivable off as a bad debt, and no one else in the process sees the contradiction. Splitting the functions forces two people to collude for a scheme to work, and collusion is far less common than a single actor.

When You Don’t Have Enough Staff

Plenty of small businesses can’t fully separate these duties. Compensating controls aren’t as strong as true segregation, but they introduce enough oversight to make concealment difficult.

The most effective compensating control is direct owner involvement. If the same person handles both the deposit and the bookkeeping, the owner should personally compare the deposit slip to the list of payments received before anything goes to the bank. That independent review catches the most common manipulation, which is changing the deposit amount to divert funds.

The second is requiring an independent reviewer to approve every adjustment to a customer account, including returns, credits, and write-offs, before the adjustment posts. Adjustments are the favorite hiding place for embezzlement because they reduce what a customer supposedly owes without producing a cash trail. A second set of eyes on each one slows that down considerably.

System Access Controls

Segregation of duties doesn’t stop at physical tasks. User permissions in your accounting system must mirror the same separations. An employee who handles deposits shouldn’t be able to create journal entries, and the person recording payments shouldn’t be able to approve write-offs. Most modern platforms support role-based access, where each user gets permissions matching their specific job and nothing more. Temporary elevated access, when needed for a special task, should expire once the task is finished. An automatic audit trail logging who entered, modified, or deleted each transaction completes the picture.

Handling Payments as They Arrive

From the moment a payment enters the building, every second it sits unrecorded is a second it can disappear. Cash-handling controls exist to create an accountability trail immediately, so any missing funds leave a visible gap.

Checks Received in the Mail

Two people should be present when payment envelopes are opened. That shared accountability eliminates the chance for one person to quietly set a check aside. As each check comes out, it should be restrictively endorsed on the spot, stamped with “For Deposit Only” and the company’s bank account number. A restrictively endorsed check is useless to a thief because it can only be deposited into that account.

At the same time, the openers create a remittance list recording the payer’s name, amount, and form of payment, ideally on pre-numbered forms so every document is accounted for. That list becomes the baseline every downstream step must match. The total on it is the number the deposit slip must equal and the amount the accounting records must reflect.

The person who prepares the remittance list should not be the same person who prepares the bank deposit. Separating those two tasks prevents anyone from altering the deposit amount to divert funds. The remittance list goes directly to accounting for recording, while a different employee assembles the deposit and physically transfers funds to the bank.

Cash Taken in Person

Cash received over the counter carries even higher risk because currency is anonymous. Every cash transaction should generate a pre-numbered receipt, with one copy going to the customer and one staying on file. Pre-numbered receipts make it impossible to destroy a record without leaving a gap in the sequence.

At the end of each shift, the cashier counts the drawer and compares the total to the sum of receipts issued. Any overage or shortage gets documented immediately and reviewed by a supervisor. Consistent small shortages are often the first sign of skimming, and the pattern only becomes visible if every shift-end count is recorded and tracked.

Controls for ACH, Wire, and Card Payments

Physical checks and cash get most of the attention in traditional guidance, but most businesses now collect a large share of revenue electronically. Those payments create their own vulnerabilities.

Verifying ACH and Wire Instructions

Before initiating or accepting an ACH transfer, verify that the account on the other end is legitimate, active, and actually belongs to the party you’re doing business with. One standard method is a prenotification entry, a zero-dollar test transaction sent through the ACH network to confirm the routing and account numbers are valid. That confirms the account exists but doesn’t prove ownership, so many businesses follow up with micro-deposits, sending a few cents and asking the recipient to confirm the exact amounts. Under Nacha operating rules, businesses must obtain proper authorization before processing ACH transactions and retain evidence of that authorization.

Wire fraud through business email compromise has caused over $55 billion in reported losses since 2013, according to the FBI. The typical scheme involves a fraudster impersonating a vendor or executive by email and requesting a change to payment instructions. The most reliable defense is a callback procedure. Before acting on any request to change banking details, call the vendor or customer at a number you already have on file, not a number provided in the suspicious email, and ask them to confirm the details from their own records. It takes two minutes and prevents losses that average in the hundreds of thousands of dollars.

Reconciling Electronic Receipts

Every electronic payment should generate a confirmation or receipt that becomes part of the permanent record, just as a deposit slip does for physical funds. Those confirmations feed into the same reconciliation process as any other payment. Delays in matching electronic receipts to invoices create the same exposure as unrecorded cash: a window where funds can be misapplied without detection.

Catching What Slips Through

Once funds are deposited, detective controls take over. They verify that what reached the bank matches what the books say, that customer balances are accurate, and that no one is manipulating records to hide missing money.

The Monthly Bank Reconciliation

This is the single most important detective control in the revenue cycle. Someone with no involvement in handling cash, preparing deposits, or posting to the ledger compares the bank statement to the general ledger cash balance and to the original remittance list totals. Every discrepancy gets investigated. When the same person who handles deposits also reconciles the bank account, you’ve effectively disabled your alarm system.

Watching Accounts Receivable

Management should review the aged receivables report regularly, looking for unusual patterns: balances that suddenly spike, invoices that age well past normal terms, or customers who were historically prompt but now show chronic lateness. These patterns can signal ordinary collection problems. They can also signal a lapping scheme, where an employee steals one customer’s payment and covers the shortage by applying the next customer’s payment to the first account. The cycle repeats, and the aging report shows a characteristic pattern of balances that are always slightly behind.

The most effective tool against lapping is sending balance confirmations directly to customers, asking them to verify what they believe they owe. Because lapping depends on juggling which account looks current, an independent confirmation from the customer’s side exposes the mismatch. Customer complaints about incorrect balances or unexpected collection notices should always route to a supervisor independent of the collections staff, because those complaints are often the first external signal that something is wrong.

Approving Bad Debt Write-Offs

Write-offs of uncollectible accounts are a favorite concealment tool. An employee steals a payment, then writes off the receivable as uncollectible so the books balance. The authority to approve a write-off must rest with a manager independent of both the collections team and the person who records transactions. That manager should review documentation showing that genuine collection efforts were exhausted before signing off. Without this gate, write-offs become a cleanup tool for theft rather than a reflection of actual business losses.

Audit Trails

Your accounting system should maintain an automatic audit trail that records every entry, modification, and deletion along with the user and timestamp. This log can’t be a feature someone turns on and off. It needs to run continuously and be accessible only to supervisors or auditors. When something looks wrong in a reconciliation or aging review, the audit trail is where you go to trace what actually happened. Controls also degrade over time as staff turn over and workarounds develop, so periodic testing, whether by internal audit or outside review, is itself a control over the control system.

Legal Deadlines and Reporting You Can’t Skip

Three obligations at the edges of the revenue cycle carry real penalties if you miss them, and they are easy to overlook.

Form 8300 for Cash Over $10,000

Any business that receives more than $10,000 in cash in a single transaction, or in two or more related transactions, must file IRS Form 8300 within 15 days of the transaction. The civil penalty for failing to file starts at $250 per form and rises sharply if the IRS determines you intentionally ignored the requirement, jumping to the greater of $25,000 or the actual amount of cash received, up to $100,000. A willful failure to file is a felony, punishable by up to five years in prison and a fine of up to $25,000 for an individual or $100,000 for a corporation. If a business helps a customer structure transactions to stay below the threshold, both the business and the customer face additional penalties. The business must also send a written statement to each person named on the Form 8300 by January 31 of the following year, and failing to provide that statement carries its own penalty.

The One-Year Window to Report Bank Errors

Bank reconciliation carries a hard legal deadline that many businesses don’t know about until they’ve missed it. Under the Uniform Commercial Code, adopted in some form by every state, a business that fails to review its bank statements and report an unauthorized transaction loses the right to hold the bank responsible.

The absolute cutoff is one year. If you don’t discover and report an unauthorized signature or alteration on a check within one year after the statement was made available, you cannot assert that claim against the bank, regardless of whether the bank was also careless.

The deadline tightens when the same person commits fraud more than once. If a wrongdoer forges a check and you miss it, the bank can argue you had a reasonable period, no longer than 30 days, to catch that first forgery and notify them. Any later forgeries by the same person that the bank pays after that 30-day window are on you. The first forged check might have been a recoverable loss, but every one after the window becomes the company’s problem.

Unclaimed Credits and Record Retention

When a customer overpays or has a credit balance that goes unclaimed, state unclaimed-property laws eventually require the business to turn that money over to the state. The dormancy period is typically three to five years depending on the state and the property type, and most states have been shortening those windows. Businesses that don’t track unapplied credits risk penalties for failing to report and remit on time, and many states actively audit for compliance.

On retention, the IRS requires you to keep records as long as they’re needed to support the income or deductions on a return. The minimum for employment tax records is four years. For general business income records, the practical minimum is at least three years from the date you file the return, and longer if the IRS has reason to suspect a substantial understatement. Remittance lists, deposit slips, bank reconciliations, and write-off approvals all fall within this retention requirement. Destroying records too early doesn’t just create an audit problem. It destroys the evidence trail your internal controls were built to produce.