
GST & Reporting
Accounting automation controls
Set review, approval, duplicate-import and change controls for automated accounting workflows, with clear owners and source records.
Set a clear boundary for each automated accounting workflow: what software may prepare or record, what a person must approve, and who resolves exceptions. A usable control lets the business trace a ledger entry back to its source and explain each decision along the way.
Map the route to the ledger
Follow each transaction from its source through any rule, approval and posting step. Name the source record, the person responsible, the destination entry and the evidence retained. A bank feed, supplier bill and sales integration may all create accounting records, but they need different checks.
| Decision | Control to define | Exception to surface |
|---|---|---|
| Suggested category | When is a suggestion reviewed before an entry is created? | Unclear purpose, account or GST treatment. |
| Supplier bill | Who approves the bill, and at what stage? | Missing evidence, changed supplier details or a decision outside delegated authority. |
| Integration import | How is a source event linked to its ledger result? | Missing, repeated or partly completed imports. |
| Rule or entry change | Who authorises the change and checks its effect? | No retrievable decision or no review of affected entries. |
Map the records each workflow may need to support, not just the ledger entry it creates. business.gov.au lists income and sales, business expenses, end-of-year records, asset or stock expenses, bank records, GST records where registered, and fuel tax credit records where claimed. It also lists employee and contractor records among the records businesses need to keep.
Set an evidence standard that makes records usable later: records must be in English or readily translatable into English. The Australian Taxation Office’s free record-keeping evaluation tool can help a business check which records it needs and how well it is keeping them.
Control Requirements by Transaction Type
- Decision
- Suggested category
- Control to Define
- When is a suggestion reviewed before an entry is created?
- Exception to Surface
- Unclear purpose, account or GST treatment
- Decision
- Supplier bill
- Control to Define
- Who approves the bill, and at what stage?
- Exception to Surface
- Missing evidence, changed supplier details or decision outside delegated authority
- Decision
- Integration import
- Control to Define
- How is a source event linked to its ledger result?
- Exception to Surface
- Missing, repeated or partly completed imports
- Decision
- Rule or entry change
- Control to Define
- Who authorises the change and checks its effect?
- Exception to Surface
- No retrievable decision or no review of affected entries
Decide what needs a person
Use the business’s delegated authority and risk assessment. Complete evidence and a narrow, repeatable transaction may justify a lighter review path. An unfamiliar supplier, changed bank details, unusual amount, missing document, uncertain GST treatment or closed reporting period is a sensible trigger for review. These are control suggestions, not statutory thresholds.
Keep purchase approval, bill review and payment authorisation distinct. The first permits the cost, the second checks what was charged and recorded, and the third releases money. If software uses one “Approve” button for several stages, document what that decision actually covers. For higher-risk payments, arrange an independent check where one person can otherwise create a supplier, approve a bill and release payment.
Make exceptions and retries visible
Give each exception an owner and a state such as awaiting evidence, awaiting approval, rejected, posted or corrected. Do not treat a connector’s success response as proof that the right entry reached the ledger.
Compare expected source items with destination entries using stable references, counts and relevant totals. Before retrying an uncertain import, check whether the first attempt posted. If a duplicate did post, identify the entry that represents the source transaction and make an approved, traceable correction.
Schedule reviews of workflow results so that exceptions are found while their causes are still easy to investigate. MYOB’s exceptions dashboard lets a user choose a period and run a review; it reports the number of exceptions found and provides reports to investigate them. MYOB notes that a long gap between reviews can make issues harder to find and fix.
Treat the review result as a work queue, not a pass-or-fail label. Assign each reported issue for investigation, record the correction or reason for no change, and retain that outcome with the review evidence. MYOB says an advisor can be invited into the file to help resolve out-of-balance issues.
Pros and Cons of Automated vs Manual Approvals
- Pros of Automation
- Faster processing, reduced human error, consistent application of rules
- Cons of Automation
- Risk of undetected errors, lack of oversight on exceptions, difficulty tracing decisions
- Pros of Manual Review
- Better detection of anomalies, clearer accountability, stronger audit trail
- Cons of Manual Review
- Slower processing, potential for inconsistency, higher labour cost
Build reliable integration inputs
For workflows that receive events from an external service, define how the incoming message is checked before it can trigger an accounting entry. Shopify’s webhook guidance says to verify the delivery’s HMAC signature and use its delivery ID to detect duplicates; the signature should be checked before trusting the payload. This gives the business a concrete way to distinguish an authentic event from a repeated delivery.
Ensuring Reliable Integration Inputs
- Verify HMAC signature of incoming webhookPrevents unauthorised or tampered data
- Use delivery ID to detect duplicatesAvoids double-posting transactions
- Check payload only after signature verificationEnsures authenticity before processing
- Log all verified events with traceable referenceSupports audit and reconciliation
Preserve decisions and review results
Connect the source document, proposed action, approver, decision, rule version and final ledger reference. If material details change after approval, seek a fresh decision. An activity log can show an edit without showing who authorised it or what they reviewed.
Check the configured product’s actual audit and export options. Reports vary by product and plan, and an integration may appear under a system identity. Where the software cannot retain approval context, keep a controlled decision record linked to the entry. Review exceptions and a sample of entries that passed automatically, especially after rules, suppliers or responsibilities change.
Australian businesses must keep records of transactions relating to tax, super and registrations. Digital or paper records are acceptable, and the ATO recommends digital record keeping where possible; paper copies generally do not also need to be kept unless a particular law or rule requires them.
Protect retained digital evidence against change, damage and loss. business.gov.au says digital records must be accessible, backed up and held on a device where the business controls the information; secure off-site storage, including cloud storage, may be used. These safeguards should apply to source records and the records that explain automated decisions.
If paper evidence is stored as an image, the ATO accepts it when it is a true and clear reproduction of the original and follows record-keeping rules. Once the image is saved, the original paper record need not be kept, unless a particular law or rule says otherwise. Include this requirement in the workflow’s evidence-handling instructions.
In this guide
- Reviewing suggested transaction categories before postingCheck the source record, existing entry, account and GST treatment before accepting a suggested transaction category.
- Choosing when a bill needs human approvalChoose human approval triggers for supplier bills using delegated authority, evidence, supplier changes and payment risk.
- Detecting duplicate imports after an integration retryTrace source event IDs, retry attempts and ledger entries to find and correct duplicate accounting imports.
- Recording who approved an automated accounting changeKeep a retrievable decision record showing who approved an automated accounting change, what changed and how it reached the ledger.



