The controls that run before anything else
Nineteen named rules, evaluated on every task, with every result logged — including the ones that passed.
Every task passes one preflight function before it runs. Three severities, and the difference matters:
BLOCK — something is wrong, the task fails. Period closed · unbalanced entry · duplicate payment (same vendor, amount and reference within 30 days) · insufficient balance · approval limit · segregation of duties · vendor bank details changed in the last 7 days · missing W-9 · suppressed recipient · missing unsubscribe link · ad spend cap.
DEFER — nothing is wrong, it is simply not the moment. The task re-queues with a visible resume time: a filing window, a payment-run day, a bank feed that has not caught up. Silently failing these is how products train people to ignore their own alerts.
WARN — logged for the approver. Unusual amount (three standard deviations from that payee's history) · round numbers · after-hours posting · missing receipt · a coding that disagrees with history. This is the near-free fraud layer.
The vendor bank-change rule is the highest-value one here. A supplier's bank details changing days before a payment is the shape of nearly every successful invoice fraud. It is a hard block with an out-of-band confirmation, not a warning — a warning gets clicked through.
Every evaluation is recorded, including the passes. "The control ran on this payment and found nothing" is the entry an auditor actually wants; a log that only records failures cannot prove a control was operating.