Month-End Close and Software Access: Controls for Controllers

Month-end is when accounting systems see the most changes. These access and review controls help controllers protect job cost data without slowing the close.

3 min readBy Ironfield Cyber Team

Month-end close is the busiest and most sensitive time for a contractor's accounting team. Journal entries post, job costs are reconciled, retainage is adjusted, and work-in-progress schedules are produced. It is also when mistakes and fraud are hardest to spot, because everyone is moving fast and the system is full of legitimate changes.

A few straightforward access controls in your accounting and job cost software can protect that process without adding days to the close. This post is written for controllers and finance managers, not just IT staff.

Why month-end carries extra risk

During close, several things happen at once:

  • More users than usual have posting rights
  • Temporary access is granted to help with cutoff tasks
  • Adjusting entries are made late in the process
  • Vendor and payroll changes pile up
  • Reports are exported to spreadsheets and sent by email

Each of those is a place where an error or a bad actor could slip through. The controls below address them one at a time.

Control 1: Limit who can post to closed periods

Most construction accounting systems, including Sage and Viewpoint products, allow you to lock accounting periods or restrict posting to prior periods. Confirm which roles can reopen a period and keep that list short. Reopening should require a documented reason and a second person's approval.

Control 2: Separate entry from approval

The person who enters a journal entry should not be the person who approves it. In smaller companies where this is hard, have the controller or owner review a report of all manual journal entries each month, focusing on:

  • Entries posted after the period was supposedly complete
  • Round-dollar entries
  • Entries with vague descriptions
  • Entries that move cost between jobs

Control 3: Review temporary access

Many companies grant temporary rights during close and forget to remove them. Add a final step to your close checklist: remove any elevated rights that were granted for the close and confirm the user list matches the approved roles.

Control 4: Watch vendor and bank detail changes

Fraudsters know that finance teams are busy at month-end. Changes to vendor banking information, new vendors, and changes to employee direct deposit should be reviewed on a dedicated report. Confirm each one was verified using a known phone number, not contact information provided in the change request.

Control 5: Protect exported data

Close involves exporting job cost reports, aging reports, and bonding schedules. These contain sensitive information about margins and cash position. Store exports in a controlled location, not in personal email or downloads folders. Avoid sending them to personal accounts, and delete working copies when they are no longer needed.

A month-end security checklist

Add a short block to your close checklist:

  1. Run the user access report and compare it with the approved list.
  2. Review manual journal entries and period reopenings.
  3. Review vendor, bank, and payroll changes.
  4. Remove temporary rights granted for close.
  5. Confirm backups completed for the accounting database.
  6. Review integrations that push data to other systems.

Consider a hypothetical 120-person general contractor. Its controller could assign these six checks to different people, each taking ten to fifteen minutes. The review would add little time to close but create a regular, documented check that auditors, bonding agents, and insurers tend to value.

Do not forget integrations

Accounting systems often connect to project management, payroll, banking, and timekeeping software. Those connections run with their own credentials. Confirm that each integration account has only the access it needs, that its password or token has been rotated recently, and that the person who owns it is still with the company.

Document what you do

Documentation turns a good habit into evidence. Keep a simple record each month showing who ran the access review, what was found, and what was changed. If a lender, bonding company, or insurer asks about financial controls, you can show a track record instead of describing intentions.

Working with IT

Controllers and IT teams often speak different languages. Controllers know the business risk but not the technical settings, and IT knows the settings but not which entries matter. A short monthly conversation between the two can close that gap. Ask IT to run the user report, and ask what changes were made to accounting server permissions during the month.

Where Ironfield Cyber fits

Ironfield Cyber supports contractors who run Sage, Viewpoint, and related software, including access reviews, backups, and secure integrations. If your close process depends on a handful of people and a lot of trust, we can help you build lightweight controls that fit your team and your software.