Operating guidelines
Harmonised Enterprise Treasury Voucher System — Federal Ministry of Finance
Issued for the use of accounting officers
Financial Regulations 2023

This system records the authority to spend public money, the vouchers raised against it, and the payments that settle them. Every step is attributed to the officer who took it and is kept permanently. Read the section for your own post; the rest explains what happens to your work before and after it reaches you.

1What this system is

HETVS carries expenditure from the vote to the bank. An Authority to Incur Expenditure (AIE) is raised against a budget line and approved; payment vouchers are raised against the approved AIE; each voucher is audited and passed; and the Central Pay Office turns passed vouchers into a payment mandate for the bank.

Nothing in the chain can exceed what stands above it. The vouchers on an AIE may not exceed the AIE, and the AIEs on a budget line may not exceed what has been released against that line. The system refuses the entry rather than recording an overdraw and leaving it to be found later.

2How money moves through it

Ten steps, each taken by a post that did not take the one before it:

  1. The vote is loaded. A Budget Officer records the appropriation and the amount released by warrant against each NCOA line.
  2. An AIE is raised. A Secretary enters the authority against a budget line and submits it.
  3. It is reviewed. The Head of Account checks it and passes it on, or returns it.
  4. It is approved and assigned. The Head of Other/Charges approves the AIE and assigns it to a preparer.
  5. Vouchers are raised. The Voter and Preparer raises payment vouchers against the approved AIE, naming the payee, the amount and the supporting documents.
  6. The voucher is audited. The Internal Auditor examines it before payment and clears or queries it.
  7. The voucher is passed. The Checking officer passes it for payment, or rejects it.
  8. A mandate is built. The Central Pay Office batches passed vouchers into a payment mandate and sends it for approval.
  9. The mandate is countersigned. The Head of Account approves it, or returns it with the reason.
  10. Payment is instructed. The Central Pay Office issues the approved mandate to the bank and records settlement.
Steps 6 and 7 are ordered by configuration. The system is delivered with audit before approval, so nothing is passed for payment that audit has not already seen. Where a ministry works the other way round, the order is changed once for the whole deployment — never per voucher.

3The posts, and what each one does

An account holds one workflow post. Two would let a single officer stand on both sides of a separation-of-duties gate, so the system does not allow it.

Post What it does
Authorising ExecutiveRaises AIEs for the organisation and submits them for review.
Head of DepartmentReviews submitted AIEs, signs the voucher as Officer Controlling Expenditure, and countersigns payment mandates.
Head of DepartmentApproves reviewed AIEs and assigns them for voucher preparation.
Voter and PreparerVotes the expenditure and raises payment vouchers against an approved AIE.
Internal Audit OfficerCarries out the pre-payment audit and maintains the audit position.
Checking OfficerChecks and passes vouchers for payment.
Central Pay OfficerBuilds payment mandates, issues approved ones to the bank, and records settlement.
External AuditorRead-only oversight across every organisation. Takes no part in the workflow.
Independent AuditorRead-only oversight across every organisation. Takes no part in the workflow.
AdministratorManages accounts, master data and system settings. Does not raise, approve or pay.

You see only your own organisation's records. Oversight auditors and the Administrator see across all of them.

4Rules the system will not let you break

These are refusals, not warnings. If one blocks you, the entry is wrong — or the step before yours has not been done.

  • A voucher may not exceed its AIE. The balance shown on the AIE is what is left to draw. A voucher that would take it past its ceiling is refused.
  • An AIE may not exceed what has been released. Commitment is measured against the warrant release, not the full-year appropriation.
  • Only a postable NCOA line takes an appropriation. The 8-character leaf codes are postable; the shorter codes are headings and cannot carry money (FR 2023, reg. 3136 — every voucher classified to an NCOA line item).
  • Every voucher is audited before payment, and audit is to be completed within two working days (FR 2023, reg. 1706(i)–(ii)).
  • A voucher unpaid after 90 days is no longer payable and must be re-raised (FR 2023, reg. 612(c)). The system warns from 14 days out and refuses payment after the limit.
  • A voucher cannot be mandated without a beneficiary account. The payee must have a bank account on record before the voucher can join a mandate.
  • A mandate cannot be issued to the bank until it has been approved, and the officer who built or submitted it may not be the one who approves it.
  • One post per account, and no officer may take two consecutive steps on the same record.

5Raising an Authority to Incur Expenditure

Secretary. Open AIE › Upload AIE and enter:

  • the budget line the expenditure falls under;
  • the amount authorised, which becomes the ceiling for every voucher raised against it;
  • the month and year the authority belongs to;
  • a payment description saying plainly what the money is for — it is printed on the AIE sheet and read by everyone downstream;
  • any supporting documents.

Submitting sends it to the Head of Account. A returned AIE comes back with the reason attached; correct it and submit again. Track everything you have raised from AIE › AIE Records, where you can filter by status, month, budget line or reference.

6Preparing a payment voucher

Voter and Preparer. Approved AIEs assigned to you appear under Payment Voucher › Prepare Payment Voucher. Open one and raise a voucher against it. You will need:

  • the payee, who must already exist with a bank account on record;
  • the gross amount, and any VAT, withholding tax or stamp duty to be deducted;
  • the description of what is being paid for;
  • the supporting documents — the invoice, the certificate, the award letter.

The AIE's remaining balance is shown as you work. Part payments against one authority are allowed (FR 2023, reg. 411(iii)); raise a separate voucher for each.

7Audit and approval

Internal Auditor. Your queue is Payment Voucher › Audit Payment Voucher, ordered oldest first. Clear the voucher, or query it with the reason — a query returns it to the preparer rather than rejecting it outright. The two-working-day limit is measured from when the voucher was raised, and your dashboard shows what is running out of time.

Checking officer. Cleared vouchers reach Payment Voucher › Vouchers Pending Review/Approval. Passing one makes it payable; rejecting it ends it, and it must be re-raised. Give a reason either way — it is kept with the record.

8Mandates and payment

Central Pay Office. Passed vouchers wait under Payment Voucher › Vouchers Pending Payment. Select those to settle and build a mandate; the system groups them by currency and produces the workbook to send to the bank, with each beneficiary's name, bank and account number.

A built mandate is a draft. Send it for approval, and it passes out of the pay office's hands until it is countersigned.

Head of Account. Mandates waiting on you appear under Payment Voucher › Mandates Pending Approval. Check the beneficiaries and amounts against the vouchers they came from, then approve, or return it with the reason. A returned mandate goes back to the pay office to be rebuilt.

The pay office cannot instruct payment of a batch it assembled on its own authority. A mandate may only be issued to the bank once it has been approved, and it cannot be approved by whoever built or submitted it. This is the last separation-of-duties gate before public money leaves the account.

Central Pay Office again. Once approved, issue the mandate to the bank. It becomes read-only at that point. Record settlement when the bank confirms it, which settles every voucher on the mandate at once.

The beneficiary details on a mandate are frozen when it is built, not read live afterwards. Re-exporting an issued mandate therefore reproduces exactly the instruction that left the building, which is what makes it reconcilable against the bank's own return. Record settlement against the mandate once the bank confirms it.

9Loading the vote

Budget Officer. No AIE can be raised against a line that has never been funded, so this is the first thing done in a fiscal year. Use Budget › Import from file for a whole vote, or Budget › Load appropriation for a single line.

The import takes an Excel or CSV file and shows you what it would do before anything is written — what will be created, what amended, and what is wrong with the reason. Download the blank template or the filled sample from the import page. Record both the appropriation and the amount released by warrant: it is the release, not the appropriation, that AIEs are measured against.

10Foreign missions

A mission's AIE ceiling is held in Naira, while its vouchers are raised in the local currency. Each voucher is converted at the CBN rate for the voucher's own date, and the Naira figure is what draws down the AIE — so the ceiling means the same thing in Abuja and at the mission.

If no rate is on file the voucher cannot be raised. Rates are maintained by the Administrator under Master Data Management › Exchange Rates. Mandates for a mission carry SWIFT/BIC and routing details that a domestic transfer does not need.

11Printed documents and verification

  • AIE Information sheet — the authority, its amount, what has been drawn and what is left.
  • Treasury Form F1 — the payment voucher as it is filed, with the signature blocks.
  • Payment mandate — the beneficiary schedule sent to the bank.

Every AIE and voucher carries a QR code. Scanning it opens a public page showing that record's identity, amount and current status — not the status when the sheet was printed. It exposes no bank details and no attachments. A code proves the document is genuine and shows where it now stands; it is not itself an approval, and a sheet printed before approval will say so when scanned.

12Reports

Reports lists the returns your post may run. Each can be read on screen or taken away as PDF, Excel or CSV — the figures are identical in all four, so the copy on paper and the copy being reconciled cannot disagree. The printed return names the officer who produced it and the time it was produced, and is valid without signature.

13Your account and sign-in

  • Your email address is your user name. Passwords are at least eight characters with an upper-case letter, a digit and a symbol.
  • Five failed attempts lock the account for fifteen minutes. It clears itself; no one needs to unlock it.
  • Posts that approve or disburse must carry two-factor authentication. Set it up under your name › Two-Factor Authentication using an authenticator app. Keep the ten recovery codes somewhere secure — they are shown once and are the only way back in if the device is lost.
  • An administrator can clear a second factor for a lost device, but cannot sign in as you and never sees your password.
  • Sign out when you leave a shared workstation, and do not tick remember this device on one.

14If something is wrong

  • A screen is empty. Check the fiscal year and the filters; a new year starts empty until the vote is loaded.
  • You cannot find a record. You see only your own organisation's. If it belongs to another, ask that organisation's officer.
  • The system refuses an entry. The message says which rule was broken; section 4 explains each one.
  • A figure looks wrong. Do not correct it by raising a second record. Query or reject the one in front of you so the correction is attributable, and let the officer who raised it re-enter it.
  • An officer has left or transferred. Ask an administrator to suspend the account. Suspension keeps the history; the workflow trail must continue to name whoever took each step.
Every state change is written to an append-only trail, with the officer, the time, and any comment. Nothing on it is edited or deleted, and administrators can read it in full. Work on the assumption that what you do here is permanently attributable — because it is.