Wise Hustlers — Digital Product & App Development Studio Logo
Get Consultation
By Wise Hustler Admin9/1/202611 min read

AFE and Capital Control: Why the Spreadsheet Always Fails at the Worst Possible Moment

AFE and Capital Control: Why the Spreadsheet Always Fails at the Worst Possible Moment

# AFE and Capital Control: Why the Spreadsheet Always Fails at the Worst Possible Moment

TL;DR: an AFE (Authorization for Expenditure) only works as a capital control if it is physically impossible to spend without going through it — and most spreadsheets, and even some poorly configured ERPs, always leave one alternative path open, usually a direct edit to the budget of a work breakdown structure (WBS) element.

What an AFE actually is

An AFE — Authorization for Expenditure — is the document and the process that define the scope, the estimated cost, and the approval chain of a capital project before any spending begins. In the oil and gas industry it typically covers drilling, completions, workovers, surface facility projects, or well abandonment, and it identifies the asset, structures the cost categories, and documents the assumptions behind the estimate.

An AFE has two functions that are worth separating:

1. A budgeting tool — it sets the authorized financial ceiling for a specific project.

2. A control mechanism — it forces any proposed spend above a threshold to be reviewed and approved before a single dollar is committed.

Once approved, the AFE becomes the baseline against which actual performance is measured: cost tracking, variance analysis, and — where there are working-interest partners in a joint venture — approval by each partner according to their share. This is the standard industry definition, documented by upstream-focused software vendors such as Quorum Software and Enverus (Quorum Software; Enverus).

None of this is news to anyone who has run a capital project in Angola, whether as an operator, an EPC contractor, or an oilfield services provider. The problem is not in the definition of the AFE. It's in what happens after it gets approved.

The blind spot: a control is only as strong as its weakest write path

Here is the central idea of this piece, and it is simpler than it sounds: a capital control is worth nothing if there is any path — however residual it looks — that lets someone change the budget without going through AFE approval.

Stated plainly, this sounds obvious. In practice, it is exactly the mistake that repeats itself, year after year, in capex audits across the energy industry. It's not a mistake of intent — nobody deliberately builds a back door. It's an architectural mistake: the control was built around the main path (the AFE form, the approval workflow, the capex tracking spreadsheet), but nobody systematically checked every other place where the budget number can be written.

A spreadsheet fails here almost by definition. A budget cell in a capex tracking spreadsheet is, structurally, identical to any other cell: it can be edited by anyone with the shared folder's password, with no record of who changed what, when, or why — unless someone has the discipline to keep a manual change log up to date, which does not happen consistently in any organization we've seen. The spreadsheet fails at exactly the moment it most needs to hold the line: during a quarter-end scramble, a tight vendor negotiation, or field pressure to "sort this out tomorrow."

A concrete example: editing a WBS element's budget directly

This is a real, verifiable failure mode that any engineering team that has ever built or implemented a capital project management system recognizes immediately. Wise Hustlers builds and operates its own energy-sector ERP, and this example comes out of that engineering.

In a typical project management system, the capital budget doesn't live only in the "AFE" object. It also lives, in parallel, in a work breakdown structure (WBS) element — the hierarchical decomposition of project scope into manageable work packages, each carrying its own cost code. It's the WBS, not the AFE itself, that normally receives the actual cost postings: vendor invoices, labor hours, material requisitions.

The failure happens like this: the approved AFE sets, say, $2 million for a "production line installation" work package. The project manager, under pressure to absorb an additional vendor cost that wasn't in the original scope, doesn't resubmit an AFE revision — which would require fresh approval, possibly from the investment committee, possibly from the joint venture partner. Instead, they go directly into the WBS element's maintenance screen and raise the budget value there, because that screen technically has write access and, in the system's design, isn't wired into the same validation engine that governs AFE revisions.

Nothing breaks immediately. The invoice gets paid. The actual-versus-budget cost report still looks "balanced" — because the budget went up too. Except now there is a committed capital value that never went through the approval committee, never got the JV partner's sign-off, and isn't reflected in the formal AFE that was signed. When year-end audit, or the operating partner, asks for reconciliation between the approved AFE and actual spend by WBS element, the gap shows up — but by then there's no decision left to make, only a justification to write.

This is the structural reason why "having an AFE" is not the same as "having capital control." The control only exists if every write path to the budget — the AFE form, the AFE revision screen, the WBS maintenance screen, batch imports, the API, direct database access — routes through the same mandatory validation: no approved AFE (or approved AFE revision) covering the value, and the write is rejected. Not flagged. Rejected.

Why this weighs more heavily in Angola than in other markets

In many markets, a capex control failure is mainly an internal audit and financial reporting problem. In Angola, this kind of trail — who approved what, when, and under which local content framework — also carries direct regulatory weight.

Local content and ANPG certification

Presidential Decree No. 271/20, of October 20, approved Angola's Local Content Legal Regime for the petroleum sector, requiring every entity that provides services or supplies goods to the petroleum sector — not only operators — to register and be certified by ANPG (the National Agency for Petroleum, Gas and Biofuels), with a legal deadline of 180 days after document submission (PwC Angola; CMS Law). The regime sets out three contracting categories — exclusivity, preference, and competition — depending on the service provider's shareholding structure, and requires petroleum sector companies to prepare a Local Content Plan for submission to ANPG.

This means a capital project in Angola isn't just managing "how much is spent." It's also managing "with whom, under which contracting regime, and within which approved local content plan." If a work package's budget can be changed outside the AFE, the link between actual spend and the vendor/regime authorized in the original plan breaks too — and that's exactly the kind of misalignment an ANPG compliance check, or a partner audit, will catch.

E-invoicing, SAF-T (AO), and the AGT

In parallel, Angola's General Tax Administration (AGT) is making electronic invoicing mandatory from January 1, 2026 for large taxpayers and companies that invoice State entities, extending to the remaining taxpayers under the General and Simplified regimes from January 1, 2027, under Decree No. 71/25 (EY Angola; Angola24Horas). Invoicing software must be AGT-certified, and submission of the SAF-T (AO) file from accounting records is planned for 2026, already covering 2025 data.

This reinforces the same argument from the tax side: if a capital cost was recorded through a path that bypasses the AFE, and that cost later generates an invoice, the trail between the expenditure authorization and the tax document breaks precisely at the moment the AGT — and the external auditor — most want to see it reconciled.

How to design an investment approval workflow with no back door

A well-designed investment approval workflow has three characteristics that, together, close the gap described above:

1. A single write point. The capital budget of a WBS element, or any equivalent cost object, can only be changed through the same validation engine that processes the original AFE and its revisions — never through a separate "administrative" maintenance screen, never through a batch import without the same check, and never through direct database access outside a controlled, logged correction process.

2. A threshold and approval matrix. Approval thresholds (who approves up to $100,000, who approves up to $1 million, at what point the investment committee or the JV partner is triggered) have to be encoded in the system itself, not just in a policy document nobody actually consults. Any AFE revision that crosses a threshold has to automatically restart the corresponding approval chain — never silently inherit the original approval.

3. An immutable audit trail and controlled reopening. Every change to the budget, approved or not, is logged with user, date, justification, and a reference to the AFE or revision that authorizes it. When a genuine posting error needs fixing — because these do happen, and the answer can't be "nothing can ever be corrected" — the fix goes through a formal, visible process, not a silent edit.

This is, in essence, enterprise automation work: mapping every data entry point of a critical process, identifying where a business rule is applied inconsistently, and closing that inconsistency at the system level instead of trying to patch it with one more internal memo. That is the scope of our enterprise automation service — not because the idea is new, but because implementing it seriously requires engineering discipline across every write path in the system, not just the most visible form.

AFE vs. operating budget control: where the difference matters

DimensionOperating expense (OPEX)Capital expenditure via AFE
Timing of approvalOften after the fact, within the annual budgetMandatory before the spend is committed
Level of detailAccount category, cost centerProject, well, asset, work package (WBS)
Mid-project revisionUsually not applicableRequires a formal AFE revision (AFE supplement)
JV partner approvalRarely applicableFrequently mandatory, by working-interest share
Link to regulatory complianceIndirectDirect — local content, ANPG plan, SAF-T tax trail
Risk if an alternative write path existsBudget variance visible in monthly reportsUnauthorized capital commitment, potentially only discovered at audit

FAQ

Is an AFE legally required in Angola, or is it just good capital management practice?

There is no Angolan law that specifically requires a document called an "AFE." It's a capital management practice consolidated across the international oil and gas industry. What is regulated in Angola is the framework around the expenditure — ANPG certification, local content, and increasingly the tax trail via SAF-T (AO) — so the discipline of a properly implemented AFE directly helps meet those obligations, even though the term "AFE" itself doesn't appear in the legislation.

Can a spreadsheet ever be enough to control capex on a small project?

For a single, low-value project with no JV partners, a well-disciplined spreadsheet can hold up for a while. The risk grows with the number of people who have write access, the number of concurrent projects, and the presence of external partners who require reconciliation. Once there's more than one approver or more than one person posting costs, the spreadsheet has no way to guarantee that nobody bypasses the process.

What is an "AFE revision" (AFE supplement) and when is it needed?

It's a formal submission to increase the scope or value of an already-approved AFE, typically required when actual cost exceeds a percentage threshold above the original estimate (for example, 10%). The revision goes through the same approval process as the original AFE — including, where applicable, the working-interest partners.

How does a system stop someone from editing the budget outside the AFE without making day-to-day work impossible?

The answer isn't to block every edit — it's to make sure any edit to the budget value, regardless of which screen it comes from, triggers the same AFE/AFE-revision validation before it's saved. From the user's point of view, the process can stay simple; what changes is that there's no longer a shortcut that skips the rule.

Sources