Skip to content
EzeFlow

Guide · 6 min read

Why WhatsApp and email approvals fail at audit time

WhatsApp and email approvals fail at audit because they cannot prove who approved, exactly what was approved, or that the record is complete. A thumbs-up in a group chat is not tied to an invoice, an amount or a sign-in, and it disappears with a lost phone. A proper trail keeps the request, the documents, named approvals and the payment together in one place.

Updated By the EzeFlow team

In short

  • Chat approvals are fast, but they make a poor record.
  • Auditors find five gaps: no proof of identity, no link to the invoice, lost chats, no segregation of duties and no defence against bank detail fraud.
  • A proper trail ties each approval to a named, signed-in person, a specific request, its documents and a time.
  • Moving off WhatsApp is mostly a policy decision and a cut-over date, not a big IT project.

Why do teams approve payments on WhatsApp?

Because it is fast and everyone already has it. A branch manager photographs an invoice, posts it in the finance group, and the MD replies "ok" from a meeting. The supplier is paid the same day.

There is nothing wrong with using chat to talk. The trouble starts when the chat becomes the only record that a payment was approved. Months later, at year-end, someone has to rebuild the story from screenshots, forwarded emails and memory.

The five gaps auditors find

1. No proof of who approved

A WhatsApp message shows a phone number, not a person. Phones are shared, a PA may carry the director's phone, and WhatsApp Web is often left open on an office computer. An email reply has the same weakness when mailboxes are shared or delegated. The auditor cannot tell whether the person with authority actually approved.

2. No link between the approval and the invoice

"Approved" replies to a message, not to a document. Was it the R18 400 invoice or the corrected R21 900 one sent an hour later? Was the quote approved, and the final invoice never looked at? When the amount changes after the "ok", nothing in the chat says so.

3. Deleted chats and lost phones

Messages get deleted, disappearing messages get switched on, phones are lost or replaced, backups fail and people leave the company with the history on their own device. An approval trail you cannot produce on request is not a trail.

4. No segregation of duties

In a group chat, anyone can say "ok". The person who asked for the payment can be the one who "approves" it, and then capture it at the bank as well. There is no rule saying how many people must agree, and nobody can see who has not yet approved.

5. No defence against bank detail fraud

Business email compromise works because invoices and bank details travel through the same channels as approvals. A fraudster who gets into a supplier's mailbox sends a real-looking invoice with new bank details. It is forwarded to the group, approved with a thumbs-up and paid. Nobody compared the account number with the supplier's usual one.

What does a proper approval trail look like?

A proper trail answers every audit question from one screen: what was paid, to whom, why, on whose request, with what evidence, approved by whom and when, and paid into which account.

WhatsApp or emailProper trail
Who approvedA phone number or mailboxA named person who signed in with their own details, ideally with two-factor sign-in
What was approvedA reply to a messageA specific request with the amount, supplier and documents attached
How many approversWhoever repliedA set number of different people, and the request is not approved until they have all signed off
Rejections and questionsScattered through chatsKept on the request, with the reason
Bank detailsTyped from the invoiceTaken from a supplier master file, with every change recorded
Keeping the recordOn personal phonesIn one company system, searchable and exportable

Rollout checklist: moving approvals off WhatsApp

  1. Agree a one-page policy: who requests, who approves, how many approvers, what evidence, who pays. Our payment approval process guide explains what to put in it.
  2. Pick a cut-over date. From that date, no request in the system means no payment.
  3. Set up branches and users. Give each person access only to the branches or companies they work in.
  4. Set the number of approvers and make sure nothing can be marked paid before it is fully approved.
  5. Turn on two-factor sign-in for everyone who approves or pays.
  6. Load your suppliers and verify their bank details by phone, on a number you already had.
  7. Bring in open items: capture what is waiting for payment so nothing is lost at the switch.
  8. Get people on the road set up on their phones before the cut-over date.
  9. Move questions onto the request. If someone asks about a payment in the group, answer "put it on the request".
  10. Review after the first month-end: how long approvals took, what got stuck and what should change.

How EzeFlow helps

EzeFlow gives each payment one home. Staff submit a request with the invoice attached, on the web or the Android app (on an iPhone, in the browser). You choose how many different people must approve, and the request shows "partially approved" until they have. With "enforce approvers" on, nobody can mark it paid before then.

Questions go on the request as reviewer and requester notes. @tag a colleague and they get access to that one payment, with the notification bell and email alerts telling people when something needs them. Rejections go back to the requester with the reason, and the audit log records sign-ins, approvals, edits and exports. For moving in, CSV import of payment requests is included on Professional and Enterprise.

Frequently asked questions

Is a WhatsApp approval legally valid?

South African law generally recognises electronic messages, under the Electronic Communications and Transactions Act, so the question is rarely whether a WhatsApp "yes" counts at all. The problem is proof: showing who sent it, exactly what it approved, and that the record is complete. That is where chats fall short at audit time. This is general information, not legal advice.

Can we still use WhatsApp for quick questions?

Yes, for talking. Just do not let the chat become the record. The request, the documents, the questions that matter and the approval should all live on the payment itself, so the answer is there when someone looks at it a year later.

What do auditors look for in payment approvals?

They pick a sample of payments and check that each one was requested, supported by an invoice and proof of delivery, approved by someone allowed to approve it, and paid to the right account for the approved amount. They also look for who changed supplier bank details and whether that was checked.

Does EzeFlow send WhatsApp messages?

No. EzeFlow does not connect to WhatsApp. It keeps questions on the payment as reviewer and requester notes, lets you @tag a colleague, shows new activity on a notification bell and sends email alerts. Staff on the road use the Android app, or the browser on an iPhone.

How do we get staff to stop approving in the WhatsApp group?

Set a date and a simple rule: from that date, no request in the system means no payment. Tell suppliers the same thing if they chase payments through staff.