Welcome CFO Techstack Community 👋

Last week we unpacked the biggest brag in this year's Awards submissions: growth without adding headcount. But leaner teams lean harder on their stack, and every new tool has to get past someone first.

For most CFOs, that someone is IT, the CTO or a technical risk team. When that relationship works, new tools get tested and rolled out quickly. When it doesn't, you get six-week security questionnaires, stalled pilots and a lot of quiet frustration on both sides.

This week we look at how good CFOs handle it: ticking every box security needs, without letting risk become the reason nothing changes. Read in full below.

Also this week, we've been working on something to make that conversation easier. The new CFO Techstack App Certification...

‍

David Tuck

Co-founder & CEO, Mayday

How the Best CFOs Say Yes to New Tools Without Losing IT

Something has changed in the last 6-12 months, and if you’ve tried to bring in a new app recently you’ve probably felt it.

Security and AI governance now sit much closer to the centre of app procurement. For some of you, that means limits on what you can trial. For others, it means providing nitty-gritty detail you've never needed before. That's not necessarily a bad thing, but it does mean more work to get an app signed off.

It's easy to feel like IT is making your life difficult. It's more useful to understand what's actually going on, and what you can do to move things along.

What is IT protecting?

Your IT & security teams are accountable if something goes wrong. A breach, even through a third-party app, lands on your customers, your board and possibly your regulators. When they push back, they're asking: what's the worst that could happen?

That usually comes down to three things:

  • What data the app can access. Financials and PII (customer and HR data) get the closest scrutiny.
  • Where your data goes and how it's protected. This covers storage, processing, who else can see it, and whether it trains AI models, plus security policies, disaster recovery, pen testing and encryption.
  • Whether a non-human can act on it. AI agents and MCP-style tools face a higher bar because they can change data, not just read it.

How strict you’ll be across the factors above is going to depend on your business and the tolerance you have for risk.

It’s also worth remembering that risk tolerance is going to vary both at an organisational level and at an individual level. Some are commercially minded, some are naturally cautious, and most are shaped by something that's gone wrong before. Knowing where your team sits helps you engage with them proactively.

How can I innovate my stack whilst managing risk?

It's a delicate balance, but the best teams do both. They:

  1. Ask the community first. Someone in The Stack Exchange has likely already been through it with the app you're considering. This can provide confidence before trialing it yourself.
  2. Encourage innovation, but set clear guardrails for the team. As one Stack Exchange member said, "encourage innovation in your team, but provide the guardrails. A culture of innovation without clear policies and boundaries will quickly ratchet up risk."
  3. Create cultures that take security seriously. Its important to ensure the team take security seriously, and don't view it as something that gets in the way. "Controls, security and risk are not viewed as roadblocks or things that have to be 'managed'".
  4. Do the thinking upfront (and they don’t do it alone). "Before building or buying, design the process and fully map the data flow. Try to understand the scale and nature of the security risks upfront". Bring IT in early so you can address security collaboratively and learn whilst you’re working together.
  5. Find ways to get to a conditional “yes”. If you’re in love with a specific app but they’re mid certification for ISO 27001 or SOC 2, talk to your IT & security team about whether they’d be willing to commit to a conditional approval with a deadline for a re-review.
  6. Work with the app. If you're really blocked, emerging apps are often open to modifying a feature (or strengthening security) if it unlocks a new customer.
  7. Invest in long-term testing. Use Xero SSO to avoid login management, and keep a demo Xero file with test data for trials. That way you and IT can see how apps behave without exposing real data.

How do I know which apps will meet requirements?

There’s a bit of leg work involved here. If you’ve got a framework of criteria that the app needs to meet then that might help you structure things.

  1. Start with what the app publishes. Often apps have security or trust pages which publish all of the data you might be after. Even newer apps which may not have ISO 27001 and SOC 2 are prioritising being transparent with security.
  2. Check there is real outside evidence. External resources like App Store reviews, the app map, How I Stacked It articles are from individuals giving their own independent perspectives on an app.
  3. Treat certification as the fast lane, not the only lane. ISO 27001 and SOC 2 mean an independent party has checked the app, which speeds up IT's review. But certification is expensive and slow. Many of the most interesting emerging apps aren't there yet, while still building on trusted foundations like Xero SSO and AWS.
  4. See if they're a 'CFO Techstack Certified App'. Here at CFO Techstack we’ve started doing the checks for you. From this week, you’ll see a certified tick against some of the apps in our app map. We’ve assessed these apps against criteria that matters to this community. Read more about CFO Techstack's App Certification.

In reality, getting an app signed off is probably going to take longer than you’d like. IT & security teams are working through genuinely difficult questions and finding ways to reduce friction when picking new apps will pay off.

How are you handling this in your team?

We’d love for you to come and share it in The Stack Exchange, this is the exact sort of thing this community is good at solving together.

‍

COMMUNITY INSIGHTS

🎤 How I stacked it

Taimoor Qasim, Program & Transformation Manager at RSGx
Finalists: Finance Team of the Year and Stack Transformation fo the Year for 2026 🏆

RSGx is a $500 million-plus infrastructure services business operating across 13 legal entities. Its finance stack is built around a composable, best-fit SaaS approach rather than a single ERP, designed to support the needs of a fast-growing, project-based business. 

‍

The best-fit SaaS approach is grounded in systematic assessment of what the business really needs from its systems and where specialist tools can provide the best fit.

For much of FY26, the RSGx ‘Finance and Business Systems’ team was in an ERP assessment and deployment phase, designed to consolidate its business functions and systems into a single system of record. But after reassessing its requirements, the team made the decision to pause the rollout. Rather than forcing the business into a monolithic ERP, RSGx is now deliberately building around a best-fit SaaS model, using specialist tools to address specific capability gaps and its own integration layer to connect them where needed.

Here are the apps RSGx runs across its 13 entities:

  1. Xero is the backbone of the finance function, running the general ledger, AP, AR and bank feeds across all 13 entities. The team is also trialling Syft on the side.
  2. Mayday handles intercompany reconciliation and month-end automation across RSGx's Xero organisations. It keeps intercompany work materially lighter, even as the entity count and complexity grow.
  3. AssetAccountant runs the fixed asset register, depreciation and lease management, replacing records previously kept in manual spreadsheets.
  4. ApprovalMax layers purchase and invoice approval workflows over Xero, keeping financial controls consistent across the group.
  5. KeyPay (by Employment Hero) processes payroll and compliance, with payroll journals feeding into Xero.
  6. Employment Hero is the core HRIS, covering employee records, onboarding and leave, and feeding people data into the wider stack.
  7. dataSights is the central data lake, bringing together data from Xero, Procore, BQE Core and other systems. Power BI sits on top for operational and executive reporting, and it's what the team relies on for decision-making.
  8. OpsCentral is RSGx's in-house application layer. It bridges the gaps where no native integration exists and replaces manual spreadsheets and ad-hoc cloud documents.
  9. Claude does the grunt work, wrangling data across the spreadsheets the team used to process by hand. Some repeatable practices are now built as Claude skills, but a finance professional still interprets the results.
  10. Spotlight provides management reporting, board packs and forecasting built on Xero data.
  11. Pipedrive manages leads and new business across the group, feeding sales forecasts into finance planning and reporting.
  12. Procore is the project management system, with timesheets, purchasing and budgets flowing through to finance.
  13. BQE Core manages time, billing and project financials for Consulting Engineering, feeding into the wider stack.

See RSGx's full stack.

If you want to showcase your stack contact jack.thiel@getmayday.com 

‍

GIVE ME HOPE

Harriet Header (400 x 100 px)-2

Reader's question:

"We are a 40-person startup and our founder wants to hire a CFO. I am the Head of Finance and I think it is too early. How do I have that conversation?"

Harriet's answer:

This comes up more often than people admit. It's usually less about whether you can do the job and more about a mismatch between how your founder pictures a CFO and what you're actually already doing.

Before you have the conversation, be honest with yourself about how you're operating today. Are you forward looking rather than backward looking? Are you pulling insight out of the numbers, not just reporting them? Can you explain the "so what" to people who don't live in a spreadsheet? Are you building relationships across the business rather than staying inside finance?

If the answer is yes to most of that, you are already doing the job. The title is the only thing missing.

Then look ahead. What's coming in the next six to eighteen months? Fundraising, international expansion, M&A? If you've handled similar challenges before, that's evidence, not just confidence.

I made a similar jump myself, from Financial Controller to VP of Finance at Arbolus, without anyone being brought in above me. What convinced people wasn't a title. It was the work landing consistently, month after month.

If you're already operating like a CFO and the next year looks like more of the same, the conversation is straightforward. Tell your founder you've got it covered and the budget is better spent elsewhere.

If there's a real gap, something coming that you haven't handled before, that's not a threat to your position. It might be the best opportunity in front of you. Be honest with yourself about whether that prospect excites you or just makes you defensive. If it excites you, say so. Ask for support to grow into it. Bringing in a coach or mentor alongside you is a reasonable ask, and often better for everyone than bringing in someone new at the top.

Either way, you don't need the title to prove you can do the job. Do the job first, and let the conversation follow.

Have a question you’d like answered? Submit your questions here. 

‍

EVENT

🏆 Meet the Global App Award Winners!

Happening this week!

Off the back of our inaugural CFO Techstack Awards, and Xero's own Global App Awards, we're bringing all the winning apps together in one place!

Mayday, Derive, Gojee, Ignition, ShiftCare, Pulsify and AhoyAhoy.

Learn about the 7-award winning apps in one short webinar. Then go deeper with those that are of interest.

App speed dating taken to another level.

The details:

  • Date: Wednesday 7th October
  • Time: 12pm Sydney / 12pm UK
  • Duration: 45 minutes

Two sessions to choose from depending on your timezone:

‍

THE STACK EXCHANGE

🧵 This week's top threads, from The Stack Exchange

The Stack Exchange is the place to connect with peers, stay on top of the latest apps and industry news, and work through the challenges that don't have an easy answer.

Take a look at what's being said:

Want to join the conversation? Sign up free here.

‍

NEW IN THE WORLD OF CFO SOFTWARE

🗞️ News from the stack-o-sphere

  • Airwallex: mapped the tasks of the finance team and shared their insights. Read more here.
  • ApprovalMax: published insights from a dataset of over 37 million approval decisions, sharing how Xero businesses control spend. Read more here.
  • ChatGPT: one of the most used AI tools among CFO Techstack finance teams just launched Dots. Their answer to personal assistants (or personal agents). Read more here.

‍

WHAT THE DATA SAYS

📊 Stat of the week

70%+ of Xero businesses use multi-step approval, averaging 2.4 sign-offs per workflow.

Source: approvalmax.com, article here.

‍

MORE OF THE GOOD STUFF

And lastly, our top picks!

🎧 Podcast: Finding and Getting your Perfect FD/CFO Role. Listen here.

📝 Article: Gartner Says CFOs Must Take a More Disciplined Approach to Finance AI Investment. Read here. 

😆 Joke: Knock knock. Who's there? Accrual. Accrual who? Accrual world is this month-end!

 

Why not forward this newsletter to someone you think would enjoy it?

‍

Ready to level up your stack?

Join The Stack Exchange and connect with 500+ finance leaders who are building world-class tech stacks. Share insights, solve problems, and discover the best apps for your needs.

Oops! Something went wrong while submitting the form.

5,000+ subscribers

Join the Slack community

500+ active members