Dual authorisation that exists on paper but not at the desk
Approval matrices promise two signatures. Fieldwork often finds the second stamp applied after the payment left the bank.
Dual authorisation fails in quiet ways. The second approver may be travelling, so a colleague initials the form later. Or the banking portal requires two tokens, yet both tokens sit with people who routinely share a desk and complete each other's steps.
During Approval Chain Reviews we compare timestamps across the paper trail and the bank export. When the second approval lands after release, the control did not operate — regardless of how tidy the signatures look.
Practical fixes include rotating token custody, requiring sequential system approvals with hard stops, and sampling a handful of high-value payments each month for timestamp integrity. Training alone rarely closes the gap if the workflow still rewards speed over sequence.