Coupa documents standard and custom exports of original treasury files to sFTP, distinguishes bank files from account statements, and says some jobs select recent unexported files before marking them exported. That state still needs source identity, population reconciliation, secure delivery, target receipt, legal-entity assignment, retention, and downstream processing evidence.
Numerix describes pricing and valuation analytics across derivatives and risk workflows; treasury still needs to preserve instrument terms, model version, market-data snapshot, adjustments, purpose, and accountable review before using an output.
Coupa positions treasury, cash, payments, and spend workflows within a connected platform, and its current documentation exposes treasury cash-flow, account-balance, bank-file, and integration records. A procurement approval can authorize an obligation inside the enterprise; it does not by itself authorize a bank release, prove bank acceptance, establish settlement, or complete reconciliation.
PCI DSS supplies baseline technical and operational requirements for protecting payment account data. It does not apply to every treasury workflow or certify an entire treasury platform because one module supports card-related payments.
COSO's Internal Control—Integrated Framework treats control as a connected system serving operations, reporting, and compliance objectives. A payment approval, reconciliation rule, or automated journal can be one control activity without proving that the wider treasury control is designed or operating effectively.