Automating Multi-Step Approvals in Higher Ed
A higher education budget approval workflow moves a budget request through the reviewers a policy requires, while enforcing segregation of duties at every step. Automated approval workflows in education solve two problems at once: speed, so requests do not sit in an inbox, and control, so the same person cannot request and approve their own transaction. An approval management platform that only speeds up routing without enforcing segregation of duties has automated the wrong half of the problem.
Key takeaways
-
A multi-step approval is not automated just because it moves through a system instead of an inbox. It is automated well only when each step enforces a control an auditor would recognize, starting with segregation of duties between the person requesting and the person approving.
-
Federal internal control expectations under the Uniform Guidance point institutions to the COSO framework, and segregation of duties sits at the center of it: the same person should not be able to initiate, approve, and reconcile the same transaction.
-
The Single Audit threshold rose from $750,000 to $1,000,000 in federal expenditures, which sounds like relief, but it means the institutions that still cross it are, on average, larger and more complex, exactly the profile where a broken approval chain is hardest to spot manually.
Why a multi-step approval isn't the same as a slow approval
Most institutions did not design their budget approval process to be slow. They designed it to have enough reviewers that no single person could move money without someone else looking at it first. The slowness is a side effect of running that design through email and paper, not the point of the design itself. When an institution automates the approval process, the temptation is to optimize for speed alone, collapsing steps that felt redundant on paper. That instinct is backwards. The steps that felt redundant were often doing exactly the job an auditor expects them to do: making sure the person who wanted the purchase was not the same person who approved it.
The control auditors actually look for: segregation of duties
Under 2 CFR 200.303, institutions receiving federal awards must establish and maintain effective internal control, and the rule points institutions toward the COSO Internal Control-Integrated Framework or GAO's Standards for Internal Control in the Federal Government as the recognized standards for what that control should look like. At the center of that framework is segregation of duties: the principle that no one person should be able to initiate a transaction, approve it, and reconcile the resulting record. In a budget approval workflow, this means the requester's role, the approver's role, and the role that reconciles the spend against the budget cannot collapse into one person, no matter how convenient that would be for a department that just wants its purchase order issued faster.
A multi step approval workflow for a university is not bureaucracy for its own sake. It is segregation of duties made operational, and it is also how an institution satisfies the separate requirement under 2 CFR 200.302 that financial management systems provide accurate, current records identifying the source and application of funds for each award. An approval routing platform for higher education that lets an institution configure which roles can request, which can approve, and which can reconcile, and then enforces those boundaries automatically, is doing the actual control work. A tool that just routes a PDF faster is doing none of it.
Why the Single Audit threshold makes this a bigger deal than it used to be
Under 2 CFR 200.501, a non-federal entity that expends $1,000,000 or more in federal awards during its fiscal year must have a Single Audit, a threshold OMB raised from $750,000 in 2024. Fewer institutions cross the new threshold than crossed the old one, but the ones that still do are, almost by definition, running larger and more complex federal award portfolios, which means more departments, more budget lines, and more approval chains an auditor will sample when the Single Audit happens. A weak approval control that a small institution might absorb as a minor finding becomes a material weakness at the scale where a Single Audit is actually required, the same scale at which 2 CFR 200.320 requires formal competitive procurement rather than an informal purchase, doubling the number of control points an approval workflow has to get right. Auditors test this control against the OMB Compliance Supplement, which directs testing of internal control, segregation of duties among them, wherever a program is significant enough to be sampled.
What each approval step is actually protecting
|
Approval step |
Role |
Control it enforces |
|
Request submission |
Department requester |
Initiation is documented and attributed, not verbal or informal |
|
Budget owner approval |
Department budget owner, distinct from the requester |
The person with budget authority, not the person who wants the purchase, confirms funds are available |
|
Finance or controller review |
Finance office, distinct from both prior roles |
Independent verification against policy and account coding before the transaction posts |
|
Reconciliation |
A role distinct from requester and approver |
The actual spend is confirmed against the approved request, closing the loop segregation of duties requires |
A governed multi-step approval workflow
Roles are defined before the workflow is built, not inferred from who happens to be available
Requester, approver, and reconciler are distinct roles assigned to distinct people, with the system enforcing that one person cannot hold conflicting roles on the same request.
Routing follows the amount and the account, not a flat chain
A request routes to more or fewer approvers based on dollar thresholds and the funding source, so a small departmental purchase and a federally funded equipment purchase do not move through an identical, one-size-fits-all chain. A reallocation large enough to trigger prior sponsor approval under 2 CFR 200.308 routes to that external approval step automatically rather than depending on someone recognizing the threshold was crossed.
Every approval is timestamped and attributed
The system records who approved what and when, producing the evidence an auditor samples during a Single Audit without anyone reconstructing it after the fact.
Exceptions escalate instead of stalling
A request that a first-line approver cannot resolve routes automatically to the next authority rather than sitting unanswered in an inbox until someone remembers to follow up.
Segregation of duties is enforced by the system, not by policy alone
If a requester and an approver would be the same person under a specific request, the workflow blocks it and reroutes automatically, rather than relying on the individual to recognize the conflict and recuse themselves.
Reconciliation closes the loop against the original approval
The actual expenditure is matched back to what was approved, and any variance is flagged rather than absorbed silently into the next budget cycle.
Kissflow and the approval workflow stack
Kissflow is the governed execution layer at the edges of the budget approval stack. It does not replace the general ledger or the institution's ERP as the system of record for the budget itself. It replaces the email chain and the paper requisition form that currently carry a request through a chain of approvers with no enforced segregation of duties and no reliable timestamped record.
If your institution runs Banner, Workday, or Ellucian Colleague for financials, Kissflow does not compete with any of them for the ledger. It sits alongside them as the university approval workflow system that routes the request, enforces which roles can request, approve, and reconcile, and produces the audit trail those systems were not built to generate on their own.
The differentiation that matters to a CFO: when a new dollar threshold, a new funding source, or a new segregation of duties requirement emerges, the finance office updates the workflow directly, instead of waiting for an ERP configuration change that requires an IT project to implement a policy finance already decided.
Frequently asked questions
-
What is segregation of duties, in the context of a budget approval workflow?
It means the person who requests a purchase, the person who approves it, and the person who reconciles the actual spend against the budget are three distinct roles, so no single person can move money through the institution without independent review at each stage.
-
Does automating an approval process actually make it faster, or just move the paper online?
It only gets faster if the workflow routes based on defined rules, dollar thresholds and funding source, rather than a single flat chain every request follows regardless of size or risk. Routing rules, not digitization alone, are what create speed without weakening control. Approval management software that skips this step has automated the form, not the process.
-
Why does the Single Audit threshold matter to a budget approval process?
Institutions that cross the $1,000,000 federal expenditure threshold undergo a Single Audit, which samples internal controls including approval chains. A workflow that cannot demonstrate segregation of duties and a timestamped approval record is exposed exactly where that audit looks first.
-
Can a small department combine the requester and approver role if staffing is limited?
COSO's framework anticipates this and expects a compensating control, typically a documented supervisory review, when full segregation is not staffing-feasible. The compensating control still has to be built into the workflow, not left as an informal understanding.
-
Does Kissflow replace our ERP's approval functionality?
No. Kissflow is the workflow layer that enforces segregation of duties, routes based on threshold and funding source, and produces the audit trail. The ERP remains the system of record for the budget and the general ledger.
Request a 30-minute walkthrough to see how Kissflow automates multi-step budget approvals with segregation of duties enforced at every step. Book a demo today.