Internal Controls for Multi-Entity Finance Teams: What Changes at Entity Two
Internal controls for multi-entity finance teams change at the second entity, when approvals, access, and reconciliation need boundaries.

Executive summary
- A second entity changes who can approve, view, prepare, and review finance activity.
- Shared access and informal approvals create unclear accountability across the group.
- Lightweight controls should separate approval authority, entity access, and reconciliation ownership.
- Finance needs deliberate boundaries before convenience becomes the operating model.
The second entity exposes assumptions the first one could hide
A Finance Manager can run a single entity with broad access and still maintain reasonable control. They may approve routine spend, post entries, reconcile accounts, review payroll, and prepare the management pack because the transaction flow is visible.
Then the company opens a second entity.
The same person now has access to two ledgers, two bank environments, and two approval chains. A local manager may approve spend while group leadership assumes finance is reviewing it. Intercompany entries appear, but the person who books them may also confirm that both sides match.
The team may be unchanged, but the control question is not. The business now needs to decide who can act locally, who can see the group position, and who checks work that crosses entity boundaries.
The three internal controls multi-entity teams need at entity two
Who can approve what?
Approval authority needs to be defined by entity, threshold, and type of spend. A manager who can approve AED 30,000 in the UAE entity should not automatically carry the same authority into a KSA entity with different budgets or local obligations.
A simple matrix should identify who can request, approve, and release a payment; what changes above a set threshold; and which decisions require group review.
Approval is also separate from accounting review. As covered in approval workflows for finance teams, approved spend can still be coded incorrectly, posted in the wrong period, or reported without enough context.
Who can see which numbers?
At one entity, broad visibility may be practical. With two or more, access should reflect what each role needs to do.
A local Finance Manager may need full visibility into their entity but not payroll, customer, or bank detail in another company. Group finance needs the consolidated position and enough source detail to investigate exceptions without giving every local user access to every ledger.
Shared logins weaken that boundary and make it harder to prove who changed a mapping, approved a payment, or posted an adjustment. Role-based access by entity becomes a basic control.
Who checks the person who prepared the entry?
The second entity introduces intercompany charges, shared allocations, funding transfers, and consolidation adjustments. If one person prepares the entry, posts both sides, and reconciles the result, there is no independent check.
A lean team may not achieve perfect segregation of duties. It can still separate preparation from review in higher-risk areas. A founder, CFO, Group Controller, or external accountant can review bank reconciliations, manual journals, intercompany balances, and high-value payments.
The eventual split between local and group ownership is explored in Group Controller vs Entity Finance Manager. At entity two, the priority is assigning the review before the group role becomes a full-time hire.
The shortcuts that become control gaps
The earliest gaps often look like convenience.
One login is shared because setup takes time. Approvals happen in WhatsApp. Group reporting is built from ledger exports inside a spreadsheet owned by one person. Intercompany entries are remembered at month-end rather than tagged when they occur.
These choices remove the evidence needed to show who made the decision, which entity it applied to, and whether anyone reviewed the result.
The risk rises when one person becomes the only route through the process. If they are unavailable, nobody knows which version is current or which exceptions remain open. If an auditor, investor, or new CFO asks for the trail, finance has to reconstruct it from messages and memory.
A lightweight control structure is enough
A growing team does not need to copy the control environment of a listed company. It needs three written decisions.
First, define access by role and entity. List who can view, post, approve, and administer each ledger, bank account, payroll file, and reporting workspace. Remove shared credentials and review access when roles change.
Second, create a short approval matrix. Set thresholds by entity and payment type, identify when group approval is required, and separate payment preparation from release where possible.
Third, assign reconciliation ownership. Name the preparer and reviewer for bank reconciliations, intercompany balances, payroll, manual journals, and consolidation adjustments. When full segregation is impossible, document the compensating review and retain the evidence.
These controls should match the risk. A recurring subscription does not need the same review as a manual bank transfer, intercompany loan, or payroll adjustment. The objective is clear accountability, not more signatures.
The test before adding more process
For every material workflow, ask: can the same person initiate the activity, approve it, record it, and confirm it was correct?
If the answer is yes, decide which step needs a second owner. That decision may lead to a new hire later, but it should not wait for one.
Adding a second entity does not require enterprise controls. It does require the company to stop treating broad access, informal approvals, and self-review as harmless defaults.
To see role-based visibility across every entity, book a demo.



