How Bujeti digitises the Four-eyes principle in financial operations

How Bujeti digitises the Four-eyes principle in financial operations

Tobi Omoyeni

It's a Friday afternoon in August, and your vendor is calling for the third time this week. The invoice was approved two Fridays ago. The check has been signed. It's sitting in an envelope somewhere between the finance office and the post office, and nobody can tell you exactly where.

This isn't a story about a disorganised company. It's a story about a control that was built for a world without software, still running inside companies that have since bought every other piece of software imaginable. The treasurer pre-signed. The secretary filled in the details. The CFO reviewed. Someone had to call the bank for  authorisation, or uploaded a scanned signature into a corporate banking portal that still expects a physical form behind it. Four people, one payment, and days of lag baked into the process by design.

If this sounds familiar, you're not alone, and you're not doing anything wrong. You're running a control called the four-eyes principle, and it's one of the oldest, most defensible ideas in corporate finance. The problem was never the principle. It was the paper.


The control that money couldn't enforce on its own

Segregation of duties is not a bureaucratic habit. It's the answer to a specific, uncomfortable question: what stops one person from both moving company money and hiding that they moved it? No single individual should be able to initiate a payment and conceal it at the same time. That single sentence is the backbone of financial control in every serious organisation, from a Lagos-based NGO managing donor funds to a family business in Nairobi splitting authority between generations. It's not a rule imposed by one regulator in one country. It shows up in internal control frameworks used worldwide, and auditors across Africa's markets test for it every time they sign off on a set of accounts, because a business that can't prove this separation exists is a business that can't prove its numbers are trustworthy.

The classic version of this control, still standard across NGOs, professional services firms, family businesses, and public-sector-adjacent institutions today, looks like this:

  • A treasurer pre-authorises spend within a set limit, sometimes literally signing blank or partially completed authorisation forms in advance

  • A finance officer or admin fills in the payee, amount, and memo on the transfer voucher

  • A CFO or CEO reviews and gives final sign-off, often a physical second signature

  • The authorisation goes to the bank, whether hand-delivered, scanned into a portal, or read out over a call to a relationship manager, before the money actually moves

Every one of those steps exists for a reason. A paper authorisation, or a signature scanned into a form, is a static object. It has no way of enforcing "this must be authorised before the money moves" on its own. So organisations built a human relay to do what the instrument itself couldn't: pre-approve within limits, capture the transaction details, apply real judgment before release, and create a record. Four people, doing what a policy engine does today.


Where the paper version quietly breaks

Here's the part that rarely gets said out loud in finance meetings, because everyone's too used to the workaround to question it: the manual process has its own control weaknesses, and they're serious ones.

  • A pre-signed blank authorisation is a bearer instrument. It's a live approval waiting for someone to fill in a number, correct or otherwise.

  • Approval isn't real. It's a summary of a summary. The CFO or CEO signing off is trusting whatever finance ops told them, not looking at live transaction data.

  • Everything about it is slow, because physical signatures, bank visits, and manual reconciliation don't move at the speed of a decision.

  • The audit trail is a signature and a bank-stamped voucher, not a system of record.

  • It doesn't scale. Every legal entity, subsidiary, and country effectively needs its own manual relay, and its own relationship with a local bank branch.

  • Smaller organisations often can't even staff four distinct roles, so they collapse the control down to "the owner signs everything," which is precisely the failure mode segregation of duties was built to prevent.

The workaround, in other words, has become its own liability. That's the pain worth naming plainly to anyone who's inherited this process and assumed the friction was the cost of doing it right.


The reframe

Strip away the paperwork and look at what each role was actually standing in for, and a different picture emerges.

None of those four functions require a human relay to exist. They require a system that can hold a policy, capture a transaction, evaluate it against live data, and execute it with a record attached. That's the whole shift: Bujeti doesn't try to replicate the four-person workflow digitally. It replaces the workaround with the actual control, running natively and in real time.


How each role is mapped on Bujeti

This is where the theory gets concrete, and it's worth walking through role by role, because the translation is nearly one to one.

  • The Treasurer's pre-authorisation becomes a rules and policy engine: Spend limits, category restrictions, and approval thresholds get set once, in advance, and enforced automatically on every transaction that follows. Nobody is trusting a blank signature or a pre-approved limit to behave itself.

  • Finance ops filling in details becomes structured transaction initiation: Whether spend starts with a card swipe, a payment request, or an invoice, the data is captured natively at the point of initiation, not re-keyed later from a form that someone has to walk to a bank or upload manually.

  • CFO or CEO approval becomes multi-level, real-time approval workflows: Approvers sees live context before they sign off: budget remaining, vendor history, and how the transaction fits the policy. Not a verbal summary of what someone else already decided was fine.

  • The authorisation going to the bank becomes instant execution with an immutable audit trail: Payment settles same-day or instantly depending on the rail, and every step of the decision is logged. There's no signed voucher to physically file and reconcile weeks later.

The people don't disappear. The roles they played, initiating, approving, executing, still exist and still matter. What changes is that every one of those steps now runs against live data, with policy enforced automatically instead of trusted to whoever happens to be holding the pen, or the bank mandate, that day.


Why control, not speed, is the real headline

It would be easy to sell this as "manual approvals are slow, Bujeti is fast." That's true, but it undersells what's actually happening. The sharper claim is this: digitising the four-eyes principle doesn't just remove friction, it makes the control itself stronger.

A policy engine enforced on every transaction is a tighter control than a pre-signed blank authorisation ever was. Real-time approval against live budget and vendor data is a stronger check than a verbal summary. An immutable digital log is a more legible audit trail than a signature and a bank-stamped form. Speed is the benefit you notice first. Control integrity is the one that matters to a CFO who remembers exactly why the manual process existed in the first place, and who is still personally accountable for proving it works.

That distinction shows up concretely in a feature most SME finance tools quietly skip: flagging when the same person is both initiating and approving a transaction. That's not a nice-to-have. That's the exact failure mode segregation of duties exists to catch, made automatic instead of hoped for.


What this looks like when it's built right

A handful of things separate a genuinely digitised four-eyes control from a payments tool with an approval button bolted on:

  • Configurable approval chains that mirror real governance structures: A finance team should be able to set up "treasurer-equivalent pre-authorises limit, ops initiates, CFO approves above threshold, CEO approves above a higher threshold" as a named, reusable policy template, not something they hack together from generic permission tiers.

  • Named roles, not just permission levels: Letting a customer label roles the way they already think about them internally, Treasurer, Controller, Finance Officer, CFO, removes the translation cost when a finance leader is mapping an existing SOP onto new software.

  • Audit trail exports that speak the language of auditors: The artifact that replaces the signed voucher has to be at least as legible to an external auditor as the paper trail ever was, if not more so.

  • Automatic segregation-of-duties violation detection:  This is what turns a payments platform into an actual control system.


The control you already built, now enforced automatically

If your organisation is still running the treasurer, finance ops, CFO, CEO relay, hand-signing authorisations and walking them to the bank, you didn't inherit a broken process. You inherited a genuinely sound control that was doing the best it could with signatures and paper. The logic was always right. The instrument was the limitation.

Bujeti's policy engine, real-time approval workflows, and audit-ready trail exist to carry that same logic without the physical bottleneck. Your treasurer, finance ops, CFO, and CEO all still play their part. They just don't need a pen, a bank visit, or three days of waiting to do it.

If you're mapping your current sign-off process and wondering whether it can survive the move off paper intact, that's exactly the conversation worth having. Book a demo with Bujeti and walk through your actual approval chain, role by role, and see it running as policy instead of paperwork.

Real control. Zero headaches.

Join 1,000+ CFOs, accountants, and finance admins using Bujeti.

Real control. Zero headaches.

Join 1,000+ CFOs, accountants, and finance admins using Bujeti.

Real control. Zero headaches.

Join 1,000+ CFOs, accountants, and finance admins using Bujeti.

Plot 1B, Block 129, Jide Sawyerr Drive,
Lekki Phase 1, Lagos.

Talk to a product expert today.
For product inquiries, partnerships, or support, please email us at contact@bujeti.com or
call +234 916 641 5472.

© 2026 Bujeti Inc. All rights reserved. Bujeti and the Bujeti logo are trademarks of Bujeti Inc.

Plot 1B, Block 129, Jide Sawyerr Drive,
Lekki Phase 1, Lagos.

Talk to a product expert today.
For product inquiries, partnerships, or support, please email us at contact@bujeti.com or
call +234 916 641 5472.

© 2026 Bujeti Inc. All rights reserved. Bujeti and the Bujeti logo are trademarks of Bujeti Inc.