Guide · 6 min read
Why WhatsApp and email approvals fail at audit time
WhatsApp and email approvals fail at audit because they cannot prove who approved, exactly what was approved, or that the record is complete. A thumbs-up in a group chat is not tied to an invoice, an amount or a sign-in, and it disappears with a lost phone. A proper trail keeps the request, the documents, named approvals and the payment together in one place.
Updated By the EzeFlow team
In short
- Chat approvals are fast, but they make a poor record.
- Auditors find five gaps: no proof of identity, no link to the invoice, lost chats, no segregation of duties and no defence against bank detail fraud.
- A proper trail ties each approval to a named, signed-in person, a specific request, its documents and a time.
- Moving off WhatsApp is mostly a policy decision and a cut-over date, not a big IT project.
Why do teams approve payments on WhatsApp?
Because it is fast and everyone already has it. A branch manager photographs an invoice, posts it in the finance group, and the MD replies "ok" from a meeting. The supplier is paid the same day.
There is nothing wrong with using chat to talk. The trouble starts when the chat becomes the only record that a payment was approved. Months later, at year-end, someone has to rebuild the story from screenshots, forwarded emails and memory.
The five gaps auditors find
1. No proof of who approved
A WhatsApp message shows a phone number, not a person. Phones are shared, a PA may carry the director's phone, and WhatsApp Web is often left open on an office computer. An email reply has the same weakness when mailboxes are shared or delegated. The auditor cannot tell whether the person with authority actually approved.
2. No link between the approval and the invoice
"Approved" replies to a message, not to a document. Was it the R18 400 invoice or the corrected R21 900 one sent an hour later? Was the quote approved, and the final invoice never looked at? When the amount changes after the "ok", nothing in the chat says so.
3. Deleted chats and lost phones
Messages get deleted, disappearing messages get switched on, phones are lost or replaced, backups fail and people leave the company with the history on their own device. An approval trail you cannot produce on request is not a trail.
4. No segregation of duties
In a group chat, anyone can say "ok". The person who asked for the payment can be the one who "approves" it, and then capture it at the bank as well. There is no rule saying how many people must agree, and nobody can see who has not yet approved.
5. No defence against bank detail fraud
Business email compromise works because invoices and bank details travel through the same channels as approvals. A fraudster who gets into a supplier's mailbox sends a real-looking invoice with new bank details. It is forwarded to the group, approved with a thumbs-up and paid. Nobody compared the account number with the supplier's usual one.
What does a proper approval trail look like?
A proper trail answers every audit question from one screen: what was paid, to whom, why, on whose request, with what evidence, approved by whom and when, and paid into which account.
| WhatsApp or email | Proper trail | |
|---|---|---|
| Who approved | A phone number or mailbox | A named person who signed in with their own details, ideally with two-factor sign-in |
| What was approved | A reply to a message | A specific request with the amount, supplier and documents attached |
| How many approvers | Whoever replied | A set number of different people, and the request is not approved until they have all signed off |
| Rejections and questions | Scattered through chats | Kept on the request, with the reason |
| Bank details | Typed from the invoice | Taken from a supplier master file, with every change recorded |
| Keeping the record | On personal phones | In one company system, searchable and exportable |
Rollout checklist: moving approvals off WhatsApp
- Agree a one-page policy: who requests, who approves, how many approvers, what evidence, who pays. Our payment approval process guide explains what to put in it.
- Pick a cut-over date. From that date, no request in the system means no payment.
- Set up branches and users. Give each person access only to the branches or companies they work in.
- Set the number of approvers and make sure nothing can be marked paid before it is fully approved.
- Turn on two-factor sign-in for everyone who approves or pays.
- Load your suppliers and verify their bank details by phone, on a number you already had.
- Bring in open items: capture what is waiting for payment so nothing is lost at the switch.
- Get people on the road set up on their phones before the cut-over date.
- Move questions onto the request. If someone asks about a payment in the group, answer "put it on the request".
- Review after the first month-end: how long approvals took, what got stuck and what should change.
How EzeFlow helps
EzeFlow gives each payment one home. Staff submit a request with the invoice attached, on the web or the Android app (on an iPhone, in the browser). You choose how many different people must approve, and the request shows "partially approved" until they have. With "enforce approvers" on, nobody can mark it paid before then.
Questions go on the request as reviewer and requester notes. @tag a colleague and they get access to that one payment, with the notification bell and email alerts telling people when something needs them. Rejections go back to the requester with the reason, and the audit log records sign-ins, approvals, edits and exports. For moving in, CSV import of payment requests is included on Professional and Enterprise.
Frequently asked questions
Is a WhatsApp approval legally valid?
South African law generally recognises electronic messages, under the Electronic Communications and Transactions Act, so the question is rarely whether a WhatsApp "yes" counts at all. The problem is proof: showing who sent it, exactly what it approved, and that the record is complete. That is where chats fall short at audit time. This is general information, not legal advice.
Can we still use WhatsApp for quick questions?
Yes, for talking. Just do not let the chat become the record. The request, the documents, the questions that matter and the approval should all live on the payment itself, so the answer is there when someone looks at it a year later.
What do auditors look for in payment approvals?
They pick a sample of payments and check that each one was requested, supported by an invoice and proof of delivery, approved by someone allowed to approve it, and paid to the right account for the approved amount. They also look for who changed supplier bank details and whether that was checked.
Does EzeFlow send WhatsApp messages?
No. EzeFlow does not connect to WhatsApp. It keeps questions on the payment as reviewer and requester notes, lets you @tag a colleague, shows new activity on a notification bell and sends email alerts. Staff on the road use the Android app, or the browser on an iPhone.
How do we get staff to stop approving in the WhatsApp group?
Set a date and a simple rule: from that date, no request in the system means no payment. Tell suppliers the same thing if they chase payments through staff.
Keep reading
More guides for finance teams
8 min read
How to set up a payment approval process in South Africa
Who may request, who approves, what evidence you keep, and how to prove it at audit time.
Read the guide7 min read
FNB bulk payments from a CSV file: a step-by-step guide
How the FNB Online Banking Enterprise payment import works and how to avoid rejected lines.
Read the guide8 min read
POPIA and payment records: what finance teams should keep
Supplier bank details, invoices and approvals are personal information. Handle them properly.
Read the guide