,

How to Audit Treasury: Cash, Debt, Investments and Hedging, With a 14-Test Program

Treasury is the function that holds the keys to the cash, and most internal audit plans visit it once every four or five years, usually after a bank has called about a wire nobody recognises. That cadence is wrong for a process where a single afternoon can move more money than the rest of the company handles in a quarter. Treasury runs five activities that each carry a different risk: it positions and forecasts cash so the company can pay its bills; it raises and manages debt under covenants that, if breached, hand control of the company’s dividends and growth to its lenders; it invests surplus cash with counterparties that can fail; it hedges currency, interest-rate and commodity exposures with derivatives that are easy to mis-designate and expensive to get wrong; and it owns the bank accounts, mandates and payment channels through which every fraudster in the AFP’s 2026 Payments Fraud and Control Survey tried to get in (76 percent of US organisations experienced attempted or actual payments fraud in 2025, and 74 percent were targeted by business email compromise). Treasury is also small, expert, and used to being trusted, which is why its controls are often a policy, a spreadsheet, and the treasurer’s judgment.

This guide is the internal auditor’s version of the corporate treasury audit: the five activities and where the risk concentrates in each, a starter risk and control matrix, a fourteen-test program with what to sample and what to reperform, the metrics an auditor rebuilds from source to see what the treasury dashboard is not saying, a worked engagement at Pennine Foods plc with every test’s result, the findings that recur with wording that lands, and scoping variants for a company with no treasury function, a multinational with an in-house bank, and a bank, where treasury means asset-liability management and a different guide applies. It sits beside the payment operations and wire transfer guide, which goes deeper on the channel through which treasury’s money actually leaves, and the cash management and bank reconciliation guide, which covers the accounting for it.

In this guide

Know the terrain: the five things treasury does and how each goes wrong

Cash and liquidity management is the daily work: positioning (how much is in which account this morning), forecasting (how much will be there in thirteen weeks), pooling or sweeping between accounts and entities, and funding the shortfalls or investing the surpluses. It goes wrong through forecast error that leaves the company borrowing expensively or sitting on idle cash, through pooling structures nobody documented, and through accounts nobody knows exist. Funding and debt is the structural work: the revolving credit facility, the term loans, the bonds or private placements, the leases that count as debt, and the covenants attached to all of them, usually leverage (net debt to EBITDA) and interest cover, tested quarterly or semi-annually on definitions in the facility agreement that rarely match the management accounts. It goes wrong through covenant calculations prepared by one person from the wrong definitions, through headroom that is smaller than the board believes, and through undrawn facilities that turn out to have conditions. Investments are the surplus-cash work: where cash sits overnight and for longer, with which counterparties, under what limits, and whether the instrument is what the policy allows. It goes wrong through concentration with one bank, through instruments that are less liquid than they look, and through a policy written for a rate environment that ended. Risk management is the hedging work: identifying currency, interest-rate and commodity exposures, deciding how much to hedge under the policy, executing derivatives, and accounting for them, which under IFRS 9 and ASC 815 requires formal designation and documentation at inception if hedge accounting is to be applied. It goes wrong through exposures nobody identified (a subsidiary buying in dollars that head office did not know about), through hedges executed outside the policy, through documentation done after the fact, and through derivatives that are speculative positions with a hedging name. And bank relationship and payment security is the custodial work: the bank accounts, the mandates and signatories, the payment channels (treasury management system to bank host-to-host, online banking, SWIFT, cheque), and the controls over who can instruct the bank to move money. It goes wrong through mandates that still carry people who left, through dual control that exists on paper and not in the system, and through payment channels the treasury team opened for convenience and nobody else knows about.

Planning inputs worth an hour each: the treasury policy and when the board last approved it; the bank account inventory with signatories, from the banks rather than from treasury; the facility agreements and the last four covenant certificates; the derivative register and the hedge documentation files; the counterparty exposure report; the cash forecast against actuals for the last twelve weeks; the treasury management system’s user list and role design; and the interfaces, meaning how payments reach the bank, how bank statements reach the ledger, and what reconciles the two. Then spend a morning in the treasury room watching the daily cash positioning and one payment run. Treasury walkthroughs are the most informative in the audit plan because the process is small enough to see whole, and the things that will become findings (the shared login, the spreadsheet covenant model, the mandate nobody updated) are visible in an hour.

The treasury risk map

#RiskWhere it livesError or fraud?
R1Unauthorised or fraudulent payments: wires, transfers or account changes instructed by someone without authority, or by a fraudster impersonating someone with itPayment channels, mandates, bank portalsFraud
R2Bank accounts and mandates not controlled: accounts opened without approval, signatories not removed on leaving, dormant accounts nobody reconcilesBank relationship managementEnabler of R1; error
R3Liquidity shortfall or idle cash: forecast error, pooling failures, facilities assumed available that are notCash management and forecastingError
R4Covenant breach or misreporting: calculations on the wrong definitions, headroom overstated, breaches not escalated, certificates signed without reviewDebt management and reportingError or misrepresentation
R5Counterparty and investment risk: concentration beyond policy, instruments outside policy, credit deterioration not monitoredInvestment managementError
R6Unidentified exposures: currency, interest-rate or commodity exposures not captured in the hedging programExposure identificationError
R7Hedging outside policy or speculation: derivatives executed without an underlying exposure, beyond limits, or with unauthorised counterpartiesDealingBoth
R8Hedge accounting failure: designation and documentation late or missing, effectiveness not assessed, ineffectiveness not recognisedAccounting for derivativesError (financial reporting)
R9Treasury system integrity: user access and role design allow one person to deal, confirm, settle and account; static data (bank details, counterparties) changed without approvalTreasury management systemEnabler of R1, R7
R10Key-person and continuity risk: a small team whose knowledge is undocumented, whose spreadsheets are uncontrolled, and whose absence stops paymentsOrganisationError

Use the map to argue scope. R1, R2 and R9 are the custody chain and are tested together through mandates, the payment channel and the system’s roles; they are the risks a board is most afraid of and the ones a treasury audit must answer first. R4 and R8 are the financial-reporting risks and are shared ground with the external auditor. R3, R5, R6 and R7 are the judgment risks, where the audit’s contribution is to rebuild the numbers from source and compare them with what treasury reports. R10 is usually the finding nobody asked for.

The starter RCM: ten controls that carry the function

CtrlControl (condensed)Type / frequencyAnswers risk
C1A board-approved treasury policy sets objectives, permitted instruments, counterparty limits, hedging ratios, delegation of authority and reporting; reviewed annually and after any change in the business or the rate environmentPreventive / annualAll
C2Bank accounts are opened and closed only with CFO approval; a complete inventory is maintained and confirmed with every bank annually; mandates and signatories are reviewed quarterly and updated within five business days of a leaverPreventive-detective / each event, quarterly, annualR2, R1
C3Every outgoing payment above a threshold requires input and release by different people in the payment system, with release limits by role; static-data changes (beneficiary bank details) require independent approval and a call-back to a known contactPreventive / each payment, each changeR1, R9
C4Payment channels are inventoried; only approved channels are open; online banking and treasury-system administrator rights are held outside the dealing team and reviewed quarterlyPreventive-detective / continuous, quarterlyR1, R9
C5A thirteen-week cash forecast is prepared weekly from operating inputs, compared with actuals, and variances over a tolerance are explained; facility availability and conditions are confirmed monthlyDetective / weekly, monthlyR3
C6Covenant calculations are prepared from the facility definitions on a controlled model, independently reviewed by financial control before the certificate is signed, with headroom reported to the board and a forecast covenant test for the next four quartersPreventive-detective / each test dateR4
C7Counterparty exposures (deposits, money market funds, derivative mark-to-market) are aggregated daily against policy limits and credit ratings; breaches are escalated the same dayDetective / dailyR5
C8Exposures are identified from a quarterly survey of all entities’ forecast currency, interest-rate and commodity flows; hedging is executed within policy ratios and limits; every deal is confirmed with the counterparty by someone other than the dealerPreventive-detective / quarterly, each dealR6, R7
C9Hedge designation and documentation are completed at inception in the form IFRS 9 or ASC 815 requires; effectiveness is assessed at each reporting date; ineffectiveness is recognised; the derivative register is reconciled to counterparty confirmations and the ledger monthlyPreventive-detective / inception, monthly, reporting dateR8, R7
C10Treasury procedures are documented; critical spreadsheets are controlled (version, access, formula review); at least two people can perform each daily process; bank statements are reconciled daily to the treasury system and monthly to the ledger by someone outside treasuryPreventive-detective / continuous, daily, monthlyR10, R1

This is a starter matrix. In a company with a treasury management system, C3, C4, C7 and much of C9 are configuration and get tested once as configuration plus a test of one per scenario; in a spreadsheet-run treasury they are people and get sampled, and the spreadsheets themselves become a control population under the end-user computing guide. Load the matrix into the RCM Workbench and rebuild it against the walkthrough, following the RCM template guide.

The 14-test program

Treasury populations are small and the transactions are large, so the program leans on full-population inspection and reperformance more than on attribute sampling; where samples appear, they follow the standard conventions and are recorded in the sampling memo. Obtain bank confirmations and counterparty confirmations directly, not through treasury.

  1. Policy and governance. Inspect the treasury policy, its approval, and the reporting the board or its committee actually receives. Attributes: policy current and approved within the year; every limit in the program below traceable to it; reporting shows breaches, not only positions; the treasurer’s delegation matches what the system enforces.
  2. Bank account inventory and mandates. Obtain from every bank, directly, the list of accounts and authorised signatories; compare with treasury’s inventory and with the HR leavers list. Attributes: every account approved and known; every signatory a current employee with the authority the delegation gives them; dormant accounts closed; annual confirmation performed. This test finds something at almost every company.
  3. Payment release and dual control. Inspect the payment system’s configuration and sample 25 outgoing payments above the dual-control threshold. Attributes: input and release by different users; release limits by role enforced in the system; no user holds both; urgent or manual payments follow the same rule; evidence retained.
  4. Beneficiary and static-data changes. Population: all changes to beneficiary bank details and counterparty static data in the period. Attributes: independent approval before effect; call-back to a number on file; change report reviewed. Accept no email confirmation as verification.
  5. Payment channel inventory and admin rights. List every way money can leave (treasury system, online banking portals, SWIFT or other network, cheques, cards). Attributes: each channel approved; administrator rights outside the dealing team; user lists reviewed quarterly; tokens and credentials of leavers revoked within the SLA; if the company is a SWIFT user, the annual attestation under the Customer Security Controls Framework (32 controls in v2026, 25 of them mandatory) is current and independently assessed.
  6. Cash forecasting. Obtain twelve weeks of forecasts and actuals. Attributes: forecast prepared weekly from operating inputs; variance analysed; tolerance breaches explained; the forecast drives funding decisions (evidence of a decision changed by it). Reperform one week from source.
  7. Facilities and availability. Inspect every facility agreement and the last drawdown notices. Attributes: undrawn amounts and conditions precedent understood and reported; maturity profile reported to the board; no facility relied on in the forecast that has a condition the company cannot currently meet.
  8. Covenant calculation reperformance. Reperform the last two covenant tests from the facility definitions and the audited or management accounts. Attributes: definitions applied as written (leases, adjustments, exceptional items, currency); independent review evidenced before the certificate; headroom reported accurately; forecast covenant tests prepared for the next four quarters.
  9. Investments and counterparty limits. Full population of deposits, funds and other investments at three dates, aggregated with derivative exposures by counterparty. Attributes: instruments permitted by policy; limits by counterparty and rating respected; breaches escalated; independent confirmation of balances from the counterparties.
  10. Exposure identification. Reperform the exposure survey for one quarter from the entities’ forecasts and purchase data. Attributes: all entities included; all currencies and commodities with material flows captured; the hedging program covers the exposures within the policy ratios; exposures the survey missed are quantified.
  11. Dealing and confirmation. Sample 25 derivative deals, or all if fewer. Attributes: underlying exposure identified before the deal; within policy limits and ratios; approved counterparty; confirmation matched by someone other than the dealer within one business day; settlement instructions from the static-data file, not from the confirmation.
  12. Hedge accounting. Sample 25 hedge relationships, or all. Attributes: designation and documentation at inception (hedged item, hedging instrument, risk, effectiveness method); effectiveness assessed at each reporting date; ineffectiveness recognised; discontinued hedges accounted for correctly; the derivative register reconciled to confirmations and the ledger.
  13. Treasury system access and role design. Pull actual roles. Attributes: deal, confirm, settle and account are separate; administrators outside treasury; static-data changes require a second user; the leavers list reconciled to the user list; logs retained and reviewed, following the segregation of duties guide.
  14. Reconciliations and continuity. All daily bank-to-treasury-system reconciliations for one month and all monthly ledger reconciliations for the year; the procedures manual; the spreadsheet inventory; the cover arrangement for each daily process. Attributes: reconciliations timely and performed outside treasury; items aged and cleared; procedures current; at least two people able to run each process; critical spreadsheets under version and access control.

The metrics the auditor rebuilds from source

Treasury reports to the board through a dashboard that treasury built, and the most valuable hours in the audit are the ones spent rebuilding six of its numbers from source documents and comparing. The table gives the six, how to rebuild each, and what a difference between your number and treasury’s usually means.

MetricRebuild fromWhat a difference usually means
Cash and available liquidityBank confirmations plus facility agreements less conditions and restricted balances (trapped cash, cash collateral, minimum balances)Liquidity reported gross of restrictions; a facility counted as available that has a condition the company cannot meet
Net debt and covenant headroomThe facility’s own definitions applied to the accounts, including leases, letters of credit and currency at the specified rateA definitional shortcut in the covenant model; headroom smaller than the board has been told
Counterparty exposureDeposits, fund holdings and derivative mark-to-market aggregated per legal counterparty group from confirmationsExposure reported by account rather than by group; a limit breached nobody noticed
Hedge coverage ratioHedges in the register against the exposure you rebuilt in test 10, by currency and by tenor bucketOver-hedging where exposures fell; unhedged flows at entities outside the survey
Forecast accuracyWeekly forecasts against actual closing balances for twelve weeks, by driverA forecast that is a budget in disguise; a driver (collections, capex) consistently wrong in one direction
Cost of carry and idle cashAverage balances by account against the marginal borrowing rate and the deposit rate actually earnedCash idle in non-interest accounts while the revolver is drawn; pooling that does not sweep

Worked example: Pennine Foods plc’s treasury audit

Pennine Foods plc is the 900-million-pound UK food manufacturer used in the UK Corporate Governance Code guide, with a December year-end and a first Provision 29 declaration built on 42 material controls in seven groups. Covenant compliance sat in the financial reporting group as a principal risk, which is what put treasury on the audit committee’s agenda: the function had not been audited in five years, and the committee wanted to know whether the controls the declaration relied on operated. Treasury at Pennine is four people (a group treasurer, a dealer, a treasury accountant and an analyst), a treasury management system installed in 2023 with host-to-host connections to three banks, 38 bank accounts across nine entities in a notional cash pool, a 180-million-pound revolving credit facility with leverage and interest-cover covenants tested at June and December, net debt of about 245 million pounds against a leverage covenant of 3.0 times, a rolling twelve-month currency hedging program (75 percent of forecast exposure in months one to six, 50 percent in months seven to twelve, executed with forwards designated as cash-flow hedges under IFRS 9) covering roughly 140 million euros and 60 million dollars of annual purchases, a partial wheat and dairy hedging program, and surplus cash in AAA money market funds under a counterparty limit of 25 percent per bank group. The audit was budgeted at 400 hours and took 430; the walkthrough took three days, and the covenant reperformance, which produced the finding the committee remembered, took two.

TestPopulation and sampleWhat it foundWhere it went
1. Policy and governancePolicy, board minutes, quarterly treasury reportsPolicy approved in 2022 and not since; the interest-rate section written for a near-zero rate environment; quarterly reports showed positions but not limit breaches.Finding, Medium
2. Bank accounts and mandatesConfirmations from all three relationship banks and two legacy banks41 accounts confirmed against 38 on the inventory (three legacy accounts at an acquired subsidiary, dormant, one with 62,000 pounds in it); eleven mandate signatories had left the company, two more than a year earlier.Finding, High
3. Payment release and dual controlSystem configuration; 25 payments above 100,000 poundsDual control operating in the treasury system; the dealer’s role permitted input and release of payments up to 250,000 pounds “for urgent settlements”, used 14 times in the year.Finding, High (with test 13)
4. Static-data changesAll 63 beneficiary changesFifty-one with call-back evidence; twelve approved on the strength of an emailed letter from the counterparty, all genuine on investigation.Finding, Medium
5. Payment channels and admin rightsChannel inventory; user lists; SWIFT attestationOne online banking portal at a subsidiary outside the treasury system, used for local payroll, with a single user and no dual control; administrator rights for the treasury system held by the treasury accountant. SWIFT attestation current and independently assessed.Finding, Medium
6. Cash forecastingTwelve weekly forecasts; one reperformedAverage absolute variance 14 percent in week one, driven by collections timing at two entities; no variance analysis performed.Finding, Low
7. FacilitiesThe facility agreement; drawdown notices; board packUndrawn amount reported correctly; a 20-million-pound accordion reported as available that required lender consent not yet sought.Observation, folded into test 8
8. Covenant reperformanceJune and December tests reperformed from the agreementLeverage reported at 2.4 times with 0.6 times headroom; the facility definition included lease liabilities that the model excluded, and reperformance gave 2.7 times. Interest cover correct. The model was a spreadsheet maintained by the treasury accountant with no independent review before the certificate was signed.Finding, High; the committee’s headline
9. Investments and counterparty limitsThree dates; confirmationsAll instruments permitted; exposure to one bank group reached 41 percent against the 25 percent limit on one date when a fund redemption settled early, with no escalation.Finding, Medium
10. Exposure identificationOne quarter’s survey reperformed from entity purchase dataTwo subsidiaries buying packaging in dollars, about 9 million dollars a year, were not in the survey and were unhedged; euro exposures agreed to the survey within 4 percent.Finding, Medium
11. Dealing and confirmation25 of 118 forwardsAll within limits and with approved counterparties; confirmations matched by the treasury accountant within a day; two deals executed a week before the exposure survey that justified them was completed.Observation
12. Hedge accounting25 of 40 hedge relationshipsSix designations documented after the deal date, three of them more than a month after; effectiveness assessed at each reporting date; ineffectiveness recognised. The auditors’ position on the six was that hedge accounting could not be applied from inception.Finding, Medium, shared with the external auditor
13. System access and rolesActual roles; leavers listDeal, confirm and settle separated; the dealer’s release limit (test 3); one former analyst’s account active four months after leaving, unused.Combined with test 3
14. Reconciliations and continuityOne month daily; twelve months ledger; procedures; spreadsheetsDaily reconciliations performed inside treasury by the treasury accountant, who also administered the system; the covenant model, the exposure survey and the counterparty report were uncontrolled spreadsheets; only the group treasurer could run the pooling process.Finding, Medium

The report carried ten findings, three High, and an overall rating of Needs Improvement, which the group treasurer disputed on the ground that nothing had gone wrong. Nothing had. The committee’s answer was the point of the engagement: the covenant headroom the board had been told was 0.6 times was 0.3 times, the number was produced by one person on a spreadsheet nobody reviewed, and the declaration under Provision 29 was going to say that the control operated. The mandate finding was fixed in a fortnight and the dealer’s release limit removed the same week; the covenant model moved to financial control with an independent review before every certificate; the two dollar-buying subsidiaries were added to the survey and hedged; the dormant accounts were closed; and the policy was rewritten for the rate environment and re-approved. Three things generalise. Confirm accounts and mandates with the banks, not with treasury, because the three accounts and eleven leavers were invisible from inside. Reperform the covenant test yourself from the facility agreement, because the definitions are the finding, and treasury has been reading them the same way for years. And treat the treasury spreadsheets as a control population, because at Pennine three of the four numbers the board relied on came from files nobody outside the team had opened.

The findings that recur, and wording that lands

Five findings account for most treasury reports, and each lands only in five-Cs form with a number the CFO can check. Mandates (“eleven of the 47 authorised signatories on the company’s bank mandates have left the company, two of them more than a year ago; the treasury policy requires removal within five business days”). Dual control (“the dealer’s role in the treasury system permits both input and release of payments up to 250,000 pounds; 14 payments were released this way in the year; the policy requires dual control above 25,000 pounds”). Covenant calculation (“the June leverage covenant was reported at 2.4 times against a 3.0 times limit; reperformed on the facility definition, which includes lease liabilities, it is 2.7 times; the model is a spreadsheet prepared and reviewed by one person”). Unidentified exposure (“two subsidiaries purchase about 9 million dollars of packaging a year outside the exposure survey; the hedging program does not cover it”). Hedge documentation (“six of 40 hedge relationships were designated after the deal date, three of them more than a month after; IFRS 9 requires documentation at inception for hedge accounting to apply”). Write the cause as the decision that produced the condition (a role designed for urgency; a model that never moved out of treasury; a survey sent to the entities that answered last time) and follow the root cause guide for the step in between.

Scoping variants: no treasury function, multinational, in-house bank, and banks

Company with no treasury function (the controller or the CFO does it): the custody chain is the whole audit, because segregation is structurally thin and the payment channel is usually an online banking portal; test mandates, dual control on the portal, beneficiary changes and the bank reconciliation performed by someone else, and treat debt covenants as a financial-reporting test if there is debt. Multinational with regional treasuries: add the intercompany layer (intercompany loans, transfer pricing on treasury services, withholding taxes, trapped cash in restricted jurisdictions) and test whether the group policy is actually enforced locally; the exposure survey and the bank-account inventory are where regional treasuries diverge from head office. In-house bank or payment factory: the treasury system is now a payment system for the whole group, so the program from the payment operations guide applies in full, with particular attention to the interfaces from the ERPs and to the in-house bank’s own ledger. Banks and insurers: “treasury” means asset-liability management, liquidity risk and interest-rate risk in the banking book, regulated activities with their own frameworks; this guide’s custody and payment tests still apply to a bank’s corporate treasury, but the substance is in the liquidity risk guide and the interest rate risk guide.

Where to go next

Audit treasury in the order the board fears it: custody first (accounts, mandates, channels, dual control), the numbers the board relies on second (liquidity, covenants, counterparty exposure, hedge coverage), and the judgment calls last. Rebuild rather than review, confirm with banks rather than with treasury, and put the spreadsheets in scope. The program above is a complete starting position; size it with the sampling grid, build the file like the model workpaper, and report it with the report template. The channel through which the money actually leaves is covered in depth in how to audit payment operations and wire transfers, and the accounting for what arrives and departs in how to audit cash management and bank reconciliations.

Related guides

Comments

Leave a Reply

Discover more from internalauditguide.com

Subscribe now to keep reading and get access to the full archive.

Continue reading