What an approval workflow is
An approval workflow is the rule that a document moves through defined statuses — draft, checked, approved/released — and that different people, with different rights, move it between them. A purchase requisition entered by a storekeeper is checked by the purchase officer and approved by a manager before it can become a purchase order. A quotation is approved before it goes to the customer; an order acceptance is approved before it drives production; a supplier bill is approved before it is paid. Until a document is released, it commits nothing — no stock moves, no money is owed, no promise is made.
That simple mechanism, applied consistently, is most of what accountants mean by internal controls: authorisation (nothing effective without sanction), segregation of duties (maker and checker are different people) and accountability (every action has a name and a timestamp). In a one-database ERP these controls are not a policy binder — they are how the software physically works, which is why this guide is as relevant to your auditor as to your operations head.
Why internal controls matter at SME scale
SMEs often assume internal controls are a big-company concern — the owner sees everything, so what is there to control? Three things, in practice. Error: most losses are not theft but honest mistakes — a wrong rate on a PO, a double-paid bill, an issue slip for the wrong item — and a second pair of eyes at the right gate catches them at the cheapest possible moment. Leakage and fraud: the classic SME frauds (a bill for goods never received, a supplier and an approver who are the same person in two roles) are structurally impossible when bills must match receipts and makers cannot approve their own documents. Audits: statutory auditors, GST officers, banks and — for automotive suppliers — customer quality auditors all ask the same question in different dialects: show me who approved this, and when. A system that answers in one click changes the tone of every audit.
There is also a quieter benefit: controls create trustworthy data. The reports and MIS a manufacturer runs are only as good as the documents beneath them, and documents that passed a check step are simply cleaner than documents typed straight into effectiveness.
The document status lifecycle
Every commercial document in Fast ERP — quotation, order acceptance, purchase requisition, purchase order, invoice, work order — carries a status that tells you exactly where it stands, and the status sequence is the workflow:
Two properties make the lifecycle an instrument of control rather than decoration. Statuses move forward through rights — who may check, who may approve is a matter of role, not habit. And every transition is recorded in the document's status history, so the path from draft to closed is reconstructable years later.
Maker-checker, document by document
Here is where the principle meets the day's work — the gates Fast ERP ships, and the risk each one controls:
| Document | Approval gate | Risk it controls |
|---|---|---|
| Quotation | Quotation approval before it reaches the customer | Under-priced commitments; margin given away in a hurry |
| Order acceptance | OA approval releases the order to production and planning | Producing against unconfirmed or uncreditworthy orders |
| Purchase requisition | Check and approve as separate steps | Unsanctioned demand entering the buying pipeline |
| Purchase order | Released PO is the only valid commitment to a supplier | Phone-call ordering; rates nobody sanctioned |
| Supplier bill | Bill approved against the PO and goods receipt | Paying for quantities never received or prices never agreed |
| Expenses | Expense approval before posting | Untracked spend accumulating below the radar |
| New party | Party approval before first transaction | Duplicate or incomplete records; unvetted counterparties |
| Stock movements | Issues, transfers and returns as authorised documents | Material leaving stores without a record |
Note the supplier-bill row: matching the bill to both the purchase order and the goods receipt before approval is the control accountants call three-way matching, and it is the single highest-value gate in the system for most SMEs — it makes the classic fake-bill and over-billing frauds structurally impossible and catches honest quantity disputes before money moves. The chain runs through the purchase module and lands in accounts already verified.
Could anyone in your company raise a PO alone today?
In a 30-minute demo we will configure a maker-checker chain on your own document flow — requisition to purchase order to bill — and show you the pending-approval queues and audit trail behind it.
Role-based menus: control by construction
Approvals only bind if rights are real, and rights in Fast ERP are enforced by the role-based menu: each role — sales, purchase, stores, production, quality, accounts, management — sees only the screens its work requires, and the approve actions appear only on approver roles. The storekeeper's menu simply does not contain PR approval; the question of whether he might approve his own requisition never arises. Segregation of duties stops being a policy people remember and becomes a property of the software.
The same mechanism scales controls with the company. A five-person shop may run one checker across documents; a fifty-person plant separates check and approve per department — both are configurations of the same role and rights masters, changeable as the organisation grows, with the admin screens themselves restricted to admin roles. Access is a master-data decision, made once and enforced everywhere.
Audit trails and status history
The third leg of internal control is memory. Fast ERP writes an audit trail on every insert, update and delete — who, what, when — and keeps a user activity log alongside it; documents additionally carry their status history, so each draft, check, approval, cancellation has a name and a timestamp attached. Nothing effective is anonymous.
What this buys, concretely: an error can be traced to its entry and fixed at the source instead of argued about; a statutory or customer audit answers "who authorised this?" in one click instead of one afternoon; and the quiet deterrent effect — everyone knows entries are attributed — improves behaviour without a single confrontation. Auditors call this an audit trail; operationally it is simply the end of "nobody knows who changed it".
Quality dispositions as controls
Approval gates govern commercial documents; inspection dispositions apply the same logic to material. Incoming lots are dispositioned at receipt inspection — accepted, rejected, or accepted under deviation — before they enter stores; in-process and pre-dispatch inspection gate your own output before it ships. A rejection is not a shrug: it can raise an NCR and an 8D that reference the originating receipt, so the disposition connects to a corrective action with an owner.
Viewed through the internal-controls lens, the quality module is the same maker-checker principle applied to goods instead of money: the person who made or bought the material is not the person who passes it. For automotive suppliers under IATF-16949 this is mandatory; for everyone else it is the control that keeps bad material from becoming bad product with your name on it.
Designing approvals that don't slow you down
The fear about approval workflows is bureaucracy, and badly designed ones earn it. The design rules that keep control without friction:
- Gate commitments, not keystrokes. Approve what moves money, stock or promises — quotations, orders, PRs, POs, bills, issues. Everything else can flow.
- One check for routine, two for consequence. A stationery PR does not need the chain a capital purchase needs; keep separate check and approve steps for the documents that warrant them.
- Make queues visible. Approvers should start the day from pending-approval screens — pending quotations, PRs, bills — with email/SMS alerts for what waits. Silent queues are how workflows get blamed for delay.
- Never approve outside the system. The moment a verbal "go ahead" substitutes for the on-screen approval, the record and the control both die. If the boss approves on the phone, the boss clicks when back at a screen.
- Review the gates yearly. As volumes grow, loosen where queues drag and tighten where incidents happened. Controls are a configuration, not a constitution.
Run this way, the workflow is faster than what it replaces: a ten-second on-screen approval against a signature chased across a factory — or against unwinding a commitment nobody sanctioned. Weak approval discipline is also one of the classic implementation mistakes — the gates exist and everyone is given rights to everything, which is control theatre. Configure the chain, and hold it.
How Fast ERP implements all of it
Everything in this guide is shipped behaviour in Fast ERP, not customisation: a status lifecycle on every document with recorded history; approval screens and pending queues for quotations, order acceptances, PR check-and-approve, purchase orders, supplier bills, expenses and new parties; the role-based menu enforcing segregation of duties; an audit trail on every write plus a user activity log; and inspection dispositions gating material at receipt, in-process and pre-dispatch. Because it all runs on one database, the controls and the operations are the same records — which is why the control evidence an auditor wants is always one click from the transaction it governs, and why the savings described in the cost-reduction guide hold once made.
Frequently asked questions
What is an approval workflow in an ERP?
It is the rule that a document moves through defined statuses — draft, checked, approved or released — and that different people, with different rights, move it between them. A purchase requisition entered by a storekeeper is checked by a purchase officer and approved by a manager before it can become a purchase order; a quotation, order, supplier bill or expense follows the same maker-checker pattern. Until a document is released, it drives nothing downstream — no stock, no money, no commitment.
What is the maker-checker principle?
The person who creates a document is never the only person who can make it effective. The maker enters; a different role checks and approves. This one rule catches typing errors, prevents unsanctioned commitments and removes the easiest fraud path — a single person creating and approving their own transactions. In an ERP it is enforced by rights, not memos: the approve action simply does not appear on the maker's menu.
Which documents should have approval gates?
Anything that commits money, stock or a promise: quotations (price commitment), order acceptances (delivery commitment), purchase requisitions and purchase orders (spend), supplier bills (payment), expenses, and material movements such as issues and transfers. Fast ERP ships approval screens for each — quotation approval, OA approval, PR check and approve as separate steps, supplier bill approval and expense approval — with pending queues so approvers see what waits on them.
What is an audit trail in an ERP and why does it matter?
An audit trail is the automatic record of who created or changed every record, and when. Combined with a per-document status history, it means every number in the system has an author and every approval has a name attached. It matters for three audiences: your own management tracing an error, statutory auditors verifying controls, and customers auditing your quality system. Fast ERP audit-trails every write and logs user activity as standard.
Do approval workflows slow a business down?
Badly designed ones do; well designed ones are faster than the alternative. The rules: gate what commits money or stock, not every keystroke; keep one check step for routine documents rather than three; give approvers pending queues and alerts so nothing waits silently; and let value limits route small items lightly. The comparison is not approval versus no approval — it is a ten-second on-screen approval versus chasing a signature, or worse, unwinding an unsanctioned commitment.
