I once wired $10 million bucks to the wrong company.

It was THE low point of my career.
What made it worse?
The party I’d accidentally sent the money to was TWEETING about it.

That’s right. Not only did I feel like a clown. They were telling the world I was a clown.
What started as a financial operations foot fault turned into a PR nightmare.
I remember going for a run that afternoon to blow off some steam. (Of course it was raining.) And I remember thinking… maybe I can drive Uber?
Luckily, the money was returned. No harm, no foul.
Well, kinda.
The investor we were wiring to had to wait an extra week, sure. But internally? Everyone suddenly treated finance like a live grenade.
And I felt like I was wearing a scarlet letter.

What caused it?
Pretty simple actually. A “template” was saved down in our SVB account with the wrong vendor name. Because it said the right party but had the wrong wiring details, the second and third approvers gave it the green light without much thought.
Instead of our investor getting a fat stack of cash, some random marketing agency we paid $500 to design our logo four years ago got it. F**K.
That’s when I realized: cash controls at startups are one of those “we’ll deal with it later” problems... until they’re not.
So I decided to write the playbook I wish I had back then.
Stage Zero: Do They Accept Venmo?
“Can we Venmo AWS for our cloud spend?”
At this stage, the founder’s personal credit card might double as the corporate card. Bank access is limited to one or two people. Every invoice is a fire drill.
Common Setup:
Paying vendors out of personal accounts (the term for this is commingling—it is frowned upon)
No system for tracking spend
No approval workflows
Risks:
Zero audit trail
High fraud risk
No clean separation between personal and business finances
What “Good” Looks Like:
Open a dedicated business banking account (Mercury is a great option)
Get a startup-friendly expense platform like Brex or Ramp
Separate spend types: Payroll, Travel, Marketing, Tech, Office, Subscriptions. Doesn’t have to be complicated. Just create a few logical categories.
Seed to Series A: The Scrappy Spreadsheet Era
“You do have a spreadsheet. You don’t have internal controls.”
Maybe you’ve got a part-time bookkeeper or a fractional CFO. Maybe you’re still approving $40K wires on Slack with a thumbs-up emoji (been there, done that).
Common Setup:
QuickBooks or Xero for accounting
No dual approval for payments
Vendor data lives in someone’s inbox
Risks:
Fake invoice scams
Fat-fingered wires
Zero visibility into burn until month-end
What “Good” Looks Like:
Set approval thresholds (e.g. anything >$5K needs a second set of eyes)
Implement read-only access for advisors
Use a spend platform like Airbase, Ramp, or Brex to enforce workflows
Enforce 2FA on all banking logins
Series B-C: Trust but Verify
“We’re not ‘early stage’ anymore, but payments still feel like a back alley handshake.”
You’ve hired a controller. Maybe a head of finance. But wires still move through Gmail threads and AP lives more in someone’s head than a workflow.
Common Setup:
NetSuite or Intacct recently in place
Expense tools like Airbase, Brex, Ramp, Bill.com partially enforced (except when the founder puts something on that annoying legacy Capital One credit card that just won’t seem to die off)
Key person risk: “If Michelle gets hit by a bus, no vendor gets paid this August”
Risks:
Wires to wrong vendors
No documentation
Can’t pass a Big Four audit without recreating the wheel
What “Good” Looks Like:
Use integrated AP software with audit trails
Monthly bank rec reviews with sign-off
Require documentation (POs, contracts) before payments
Hold up- What’s a PO, Anyway?
A Purchase Order (PO) is like a pre-approved “permission slip” for spend. It’s the handshake agreement before the actual contract.
It outlines:
What’s being purchased
How much it costs
When it’s delivered
Payment terms (e.g., Net 30)
The finance team uses it to match against the invoice later, ensuring that you’re paying for what you actually ordered—and that it was approved up front.
Pre-IPO / Crossover-Ready: The Fort Knox Framework
You’re explaining your controls to actual auditors, not just your board.
At this stage, compliance isn’t optional—it’s existential. Investors care. Auditors care. And your CFO’s ass is on the line.
Common Setup:
Full-stack finance org: Treasury, AP, Internal Audit specialists
SOC 1/SOC 2 reports on the wall (and in the data room)
Every dollar is logged, tagged, and signed off
Risks:
Reputational damage
Material weaknesses in your S-1 for an IPO
Internal churn if trust is broken (especially if you are a security or infrastructure company)
What “Great” Looks Like:
Documented treasury policies and vendor onboarding procedures
Scheduled, batched payment runs
Real-time cash tracking
The Wrong Access at the Wrong Time = Boom Goes the Dynamite
Here’s something that doesn’t get talked about enough: Role-based access isn’t just IT’s problem—it’s a finance imperative.
Startups move fast. People wear hats they shouldn’t. Suddenly your junior ops associate has full access to the bank portal “just to help out.”
Golden Rule: No one person should be able to create, approve, and send money. You want to split all of these up between different people.
Role Breakdown:
Initiators: Queue up payments (i.e., key it in)
Approvers: Validate legitimacy (i.e., second set of eyes)
Executors: Final authority to release funds (i.e., hit “send”)
Systems Checklist:
Who can initiate wires?
Who can approve, and at what limits?
Who can edit vendor info?
Who can add/remove users?
If your system doesn’t let you separate duties, your system sucks. Upgrade it before the upgrade chooses you.
Also, I couldn’t help myself:
When to Start Thinking About Procurement
Procurement sounds like a big company word. But the second multiple people can spend money: congrats you’re in it.

At first, you don’t need a full-blown department—you just need some (any!) procurement flows to keep spend from turning into chaos. That’s where small “p” procurement comes in: lightweight structure to avoid big mistakes.
Signs you’re ready:
You’ve got 10+ SaaS vendors and no idea who owns what
Renewal dates sneak up on you (and hit hard)
Legal is stuck reviewing random contracts in Slack
Security reviews are slowing down launches
Someone tries to buy a tool you already have (yep, it happens)
Starter kit:
Intake form for new tools (Zip, Google Forms)
Central contract repo (Dropbox, Notion, Ironclad, Tropic)
Simple checklist: Is this approved by Finance? Reviewed by Legal? Do we already pay for something similar?
Tools that help at this stage: Tropic, Vendr, Zip, Ramp
As you grow, you’ll graduate from small “p” to big “P” Procurement—think:
Formal RFPs (request for proposal - also, watch War Dogs)
Preferred vendor lists
Tools like Coupa or SAP Ariba
Dedicated sourcing and compliance headcount
TL;DR: Startups need structure, not bureaucracy. Under 200 people? Keep it lightweight. Over 500? Start building the real thing.
Oh, BTW - Watch Out for “Fake CFO”
When I became a CFO for the first time, my alter ego “Fake CJ” became a Slack celebrity. There was a whole channel dedicated to spoof attempts.
Scammers aren’t dumb. They scrape LinkedIn for new CFOs and blast phishing texts, fake DocuSigns, and shady Gmail threads.
Some highlights:
An employee almost bought $2K in CVS gift cards… for “me”
Multiple fake board wire requests
Spoofed DocuSigns that looked legit—especially when I was already expecting one
They exploit two social gaps:
The CFO doesn’t know what normal looks like yet (is that really how my CEO talks?)
The org doesn’t know what’s normal for the CFO to request (he / she is new - I better do what they asked)
Train your team. Normalize double-checking. Your reputation—and your wire balance—depends on it.
Final Word
I’ve talked to a lot of CFOs (on the pod, in boardrooms, over beers) and almost all of them have some version of a cash control “oops” moment.
Sometimes it’s a fat-fingered wire. Sometimes it’s a forgotten renewal. Sometimes it’s a vendor you swear someone approved… but no one remembers doing it.
It happens.
Controls aren’t about perfection. They’re about reducing your surface area for bad shit to happen.
And trust me… no one high-fives you for avoiding a screw-up. But they will remember the one you didn’t avoid.
In fact, it took me a while to work my way back into a few company lunch groups.








