Service Area

Treasury and finance process optimization

Treasury process optimization tightens how payments are approved, who can act on bank accounts and how treasury decisions are governed. CFOs and controllers hire FIRMA Advisory after a fraud attempt, an audit finding or rapid growth. The outcome is fewer manual steps, clean bank mandates, documented controls and a treasury policy banks recognize.

When companies bring us in

Companies bring us in when a near miss, an audit or growth exposes gaps in how money leaves the business. These are the usual triggers.

  • A supplier bank detail change request turned out to be fraudulent.
  • Auditors flagged segregation of duties issues in payments.
  • Former employees still appear as signatories on bank mandates.
  • One person can create a supplier and release a payment to it.
  • A lender asks for the treasury policy, and none exists in writing.
  • Payment approvals depend on email chains and manual spreadsheets.

What we deliver

You receive a mapped process, a control set sized for your team and a clean set of bank mandates. The table shows each deliverable and its timing.

DeliverableWhat it containsTypical timing
Process and control mapEach payment and treasury process step by step, with control gaps marked.End of phase 1
Payment control frameworkApproval limits, call-back verification, dual authorization and system settings.End of phase 2
Mandate and signatory cleanupCurrent signatories per bank and account, the changes needed and the documents to file.Phase 2
Treasury policyLiquidity, counterparty, FX and investment rules, with delegations and reporting.Phase 3
Procedures and trainingWritten procedures and short training for the people who run them.Phase 3

How an engagement runs

Engagements run in three phases, from mapping to a control set your team operates. Bank mandate changes run in parallel because banks need time to process them.

  1. Mapping, weeks 1 to 2. We walk through every payment and treasury process with the people who run it. Gaps are ranked by risk and by the effort to fix them.
  2. Control design and mandate cleanup, weeks 2 to 6. We design the controls and system settings, then update mandates and signatories at each bank. Every change is documented for audit.
  3. Policy and embedding, weeks 6 to 9. The treasury policy is drafted and approved. Procedures are written, and the team is trained to run them.

What changes for the client

Outcomes are visible in system settings, bank records and audit results. These are the outcome types we report.

  • Signatories removed or updated across every bank and account.
  • Payment steps covered by dual authorization or call-back verification.
  • Segregation of duties conflicts identified and resolved.
  • Audit findings on treasury and payments closed.
  • Manual approval steps replaced by system workflows.
  • A board-approved treasury policy with clear delegations.

Why an independent former banker

Banks see payment fraud attempts and weak mandates across many clients. Federico Lleonart worked in cash management at J.P. Morgan and Barclays, where client mandates and payment controls are set up and reviewed.

Which payment fraud controls matter most?

Business email compromise and fake supplier bank detail changes remain common attack routes. The defense is procedural: verify every change by calling a known number, never the one in the email.

Dual authorization, payment limits and alerts on new beneficiaries close further gaps. Bank tools for this often exist but are left switched off.

Why does signatory hygiene matter?

Bank mandates often lag behind staff changes, especially across many entities and banks. A former employee with live signing rights is a real risk.

A single list of signatories per bank, reviewed on a schedule, prevents this. Mandate updates take time at banks, so the review must be regular.

What does segregation of duties look like in treasury?

No single person should create a supplier, enter its bank details and release payment to it. Small teams can still separate duties with system roles and second approvers.

What treasury policy does a bank credit team expect?

Credit teams look for written rules on liquidity buffers, counterparty limits, FX hedging and investments. They also want to see who can approve what.

A clear policy supports credit decisions and makes due diligence easier. It also gives auditors and boards a standard to test against.

FIRMA Advisory sells no software or banking products and takes no commissions. A senior consultant designs the controls with your team.

For consulting firms and private equity teams

Consulting firms bring us in as the treasury controls specialist on finance transformation, audit remediation or ERP programs. Private equity teams use us to standardize payment controls across portfolio companies, and our partner model explains how we work with your team.

Frequently asked questions

These are the questions CFOs and controllers ask before a controls review. Each answer is direct.

We are a small finance team. Can we really separate duties?

Yes, with the right setup. System roles, second approvers and bank-side controls let a small team separate the key steps. Where full separation is not possible, compensating controls such as independent review and alerts fill the gap. We size the controls to the team you have.

How much does it cost, and how is it structured?

Pricing depends on the number of entities, banks and payment flows in scope. Many clients start with a fixed scope controls review, then continue with implementation as a project. Periodic reviews of mandates and controls can run as a retainer. See engagement models and fees.

How long does a treasury controls review take?

A typical engagement runs 6 to 9 weeks from mapping to an approved policy and a trained team. Bank mandate changes can take longer, because each bank processes documents on its own timeline. We start those changes early so they do not hold up the rest.

Is the work remote or on site?

Process walkthroughs and control design run well by video, with screen sharing of systems and bank portals. Training sessions and workshops can be held on site where the team prefers it. On site time is agreed in the scope. Travel is billed at cost and approved in advance.

Which regions and languages do you cover?

We work with companies in the United States, Europe and Latin America. Federico Lleonart works in English, Spanish, Portuguese, Italian and French, so local finance teams and banks are engaged in their own language. Controls are designed to work across every entity in the group.

How do you handle confidentiality?

Engagements are confidential, and we never need payment rights. Process documents, mandate details and audit findings are used only for your engagement and never shared without your approval. Client names and findings are never published without explicit consent. Files can be shared through your own secure channels.
Related

Related services

Treasury systems and bank connectivity

Host-to-host, bank APIs and ISO 20022 implementation.

Explore

Treasury build-out

Build the treasury function step by step as the company scales.

Explore

CFO advisory services

A senior sounding board for facility and bank panel decisions.

Explore

Related insight: The outsourced payments controls checklist covers approvals, bank access and fraud controls.

Engage

Close the gaps before someone finds them.

Book a short call with a treasury consultant who has seen payment controls from the bank side. We will outline what a controls review would cover.