Segregation of Duties: A Practical Matrix for Small Teams
Occupational fraud costs the typical organization about 5% of its revenue every year, and the median case runs for 12 months before anyone notices. Those are the headline numbers from the ACFE Occupational Fraud 2026 report, based on 2,402 cases across 143 countries. Segregation of duties is the oldest and cheapest defense against that loss, and it is also the control that small and mid-sized companies most often skip, because they assume they do not have enough people to make it work.
They are wrong, but not entirely. A ten-person finance team cannot separate duties the way a Fortune 500 company does. What it can do is build a segregation of duties matrix that fits its size, close the handful of conflicts that actually matter, and cover the rest with compensating controls. This guide shows you how, step by step, with a matrix you can copy, a self-assessment scorecard and a 90-day rollout plan.
What segregation of duties actually means
Segregation of duties (often shortened to SoD, and sometimes called segregation of responsibilities) is a simple principle: no single person should control every step of a transaction that moves money or assets. If one person can create a vendor, approve an invoice, release the payment and reconcile the bank account, that person can steal from you and hide it. Not because they are dishonest, but because the system makes it possible and undetectable.
The principle is built into the COSO Internal Control Integrated Framework, the reference model most auditors use. In its 2013 version, COSO organizes internal control into five components and seventeen principles, and segregation of duties appears under control activities as something management should consider when it designs controls. For US public companies, Section 404 of the Sarbanes-Oxley Act turns that consideration into an annual assessment of internal control over financial reporting.
You do not need to be public, or audited, for the logic to apply. If you have money moving through your business and more than one person touching it, you already have a segregation of duties problem. The only question is whether you have designed the answer or left it to chance.
The four functions you need to keep apart
Every financial process can be broken down into four functions. The classic rule is that no one person should hold two of them for the same transaction:
- Authorization. Approving that a transaction should happen: a purchase, a payment, a new hire, a credit note.
- Custody. Physical or logical control of the asset: access to the bank portal, the cash box, the inventory, the payment file.
- Recording. Entering the transaction into the books or the system of record.
- Reconciliation. Checking that what was recorded matches what actually happened: bank reconciliations, inventory counts, vendor statement checks.
When one person holds authorization and custody, they can approve and take. When one person holds custody and recording, they can take and hide. When one person holds recording and reconciliation, they can hide and confirm the hiding. Each pair is a different risk, and the matrix you build later in this guide is just a structured way of seeing which pairs exist in your company.
Why segregation of duties matters more than most controls
Most companies treat internal control as an audit problem. It is actually an operating problem, and the numbers show why.
The ACFE 2026 data, as summarized by accounting firms that reviewed the full report, points to control weaknesses as the main enabler of fraud. A simple lack of internal controls was the primary weakness in 33% of cases, override of existing controls in 19%, and lack of management review in another 18%. Put together, nearly seven cases out of ten trace back to a control that was missing, bypassed, or never checked.
The same report shows how much controls reduce the damage when they exist. Organizations with management review saw median losses 55% lower than those without it. Proactive data monitoring was associated with a 53% reduction, and surprise audits with 50%. Organizations that trained both employees and managers on fraud reported a median loss of $84,000, compared with $150,000 for those that did not.
Fraud is not the only risk
It would be a mistake to frame segregation of duties purely as fraud prevention. In my experience, the more common cost is error. When one person does everything, nobody catches their mistakes: a duplicated payment, a wrong vendor bank account, an invoice booked to the wrong period. Those errors rarely make headlines, but they distort the numbers you use to run the business.
There is also a key-person risk. If the only person who knows how to release payments is on holiday, sick, or leaves, the process stops. Splitting duties forces you to document the process and train at least two people on it. That is resilience, not bureaucracy.
The segregation of duties matrix for small teams
A segregation of duties matrix is a table that lists your critical activities on one axis and your people or roles on the other, and marks who can do what. Its purpose is to make conflicts visible. Large companies maintain matrices with hundreds of rows inside governance software. A small company needs something much simpler: a spreadsheet with fifteen to thirty rows covering the processes where money actually moves.
Step 1: list the processes where money moves
Start with the processes, not the people. For most small and mid-sized companies, the list is short:
- Procure to pay: vendor creation, purchase orders, invoice approval, payment release.
- Order to cash: customer creation, credit limits, invoicing, credit notes, cash application.
- Payroll: employee master data, pay rate changes, payroll run, payment release.
- Treasury: bank account access, payment batches, bank reconciliations.
- Expenses: expense claims, approvals, reimbursements, corporate cards.
- Fixed assets and CapEx: purchase approval, asset register, disposals.
- General ledger: manual journal entries, period close, master data changes.
If you want a deeper view of any of these, we have covered the procure to pay process and its controls, the payroll process and the month end close in separate guides.
Step 2: break each process into activities
For each process, list the activities that map to the four functions. Here is what procure to pay typically looks like:
| Activity | Function |
|---|---|
| Create or change a vendor record, including bank details | Recording (master data) |
| Approve a purchase order | Authorization |
| Receive goods or confirm service delivery | Custody |
| Enter a supplier invoice | Recording |
| Approve an invoice for payment | Authorization |
| Prepare the payment batch | Recording |
| Release the payment in the bank portal | Custody |
| Reconcile the bank account | Reconciliation |
Do the same for every process on your list. It takes an afternoon, and it is the most valuable afternoon you will spend on internal control this year.
Step 3: map people to activities
Add a column for each person (or role, if your team is larger than fifteen people). Mark with an X every activity that person can perform. Be honest: the question is not what they are supposed to do, but what the system lets them do. If the accounting software gives the controller full admin rights, the controller can do everything, whether or not they ever do.
This is where most companies get their first surprise. In small teams, it is common to find one person with access to vendor master data, invoice entry, payment preparation and bank release. Nobody designed it that way. It accumulated, one convenience at a time.
Step 4: identify the conflicts
Now look for conflicting pairs. These are the combinations that matter most in almost every company:
- Vendor master data plus payment release. The person who can change a vendor's bank account should never be the person who can release payments. This is the single most common path to payment fraud and to business email compromise losses.
- Invoice approval plus payment release. Approval and payment by the same person removes the second pair of eyes on every outgoing euro or dollar.
- Payroll master data plus payroll run. Ghost employees and inflated rates live here.
- Customer credit notes plus cash application. The classic way to hide skimmed receivables.
- Manual journal entries plus period close approval. Anyone who can post and approve their own entries can reshape the financial statements.
- Bank release plus bank reconciliation. The person who moves the money should not be the person who confirms it moved correctly.
Mark each conflict in red. Your goal is not to eliminate every red cell. It is to know where they are and decide, for each one, whether to separate or compensate.
Step 5: separate where you can, compensate where you cannot
For each conflict, there are only two options. Either you split the activities between two people, or you keep them together and add a compensating control: a review, a report, a system restriction that catches what the missing separation would have prevented.
The next section explains how to choose.
Compensating controls: what to do when you do not have enough people
This is the part that most segregation of duties guides skip, because they are written for large companies. In a business with three people in finance, perfect separation is impossible. Compensating controls are how you get most of the protection without the headcount.
A compensating control works when it meets three conditions:
- It is performed by someone outside the conflict. Often the owner, the CEO or an external accountant.
- It is evidence based. The reviewer looks at a system report, not at a summary prepared by the person being reviewed.
- It has a fixed rhythm. Weekly or monthly, on a calendar, with a record that it happened.
Compensating controls that actually work
Here are the controls I see deliver the most protection for the least effort in small and mid-sized companies:
- Vendor bank detail change report. A system report listing every vendor bank account change in the period, reviewed weekly by someone who cannot change vendor data. Every change must be confirmed by a callback to a known phone number, not the one in the email requesting the change. Our guide to the vendor onboarding process goes deeper on this control.
- Dual approval in the bank portal. Almost every business banking platform allows two-person release above a threshold. It is free, and it closes the most expensive conflict in one setting.
- Owner review of the bank statement. The owner or CEO reads the full bank statement every month, line by line, directly from the bank, not from accounting. Thirty minutes a month.
- Payroll variance review. A monthly comparison of payroll totals and headcount against the prior month, reviewed by someone outside payroll, with every change explained.
- Journal entry log review. A list of manual journal entries above a threshold, reviewed monthly by the controller or an external accountant.
- Credit note report. Every credit note issued, with reason and approver, reviewed monthly by sales leadership.
Notice that most of these rely on reports the system already produces. The cost is not technology. It is discipline: someone must actually read the report, and leave a trace that they did.
When a compensating control is not enough
Some conflicts are too dangerous to compensate. If one person can create a vendor and release payments to it without any second approval in the bank, no monthly review will save you: the money is gone before the review happens. For these combinations, separation is non-negotiable, even if it means the owner has to approve payments from a phone every week.
A simple rule: if the conflict allows money to leave the company in a single step, separate it. If it allows an error or fraud to be hidden after the fact, a timely review can compensate.
Segregation of duties inside your software
Most segregation of duties failures today are not about people sharing desks. They are about software permissions. ERP systems, accounting platforms, payroll tools and banking portals each have their own roles, and nobody looks at them together.
Role design, not user design
Assign permissions to roles, not to individual users. Define a small set of roles (for example, accounts payable clerk, controller, payroll administrator, approver) and give each role only the permissions it needs. Then assign people to roles. When someone changes job, you change their role, not twenty individual checkboxes.
Workday segregation of duties is one of the most searched topics in this space for a reason: large platforms ship with powerful default roles that often combine conflicting permissions. The same is true for smaller accounting systems, where the first user is usually a full administrator and stays that way forever.
The admin problem
Every system has administrators who can do everything. In small companies, the administrator is often the same person who runs finance day to day. That is a conflict by definition. Options, in order of preference:
- Give admin rights to someone outside finance (often IT or the owner) who does not process transactions.
- If that is not possible, keep a separate admin account used only for configuration, with its activity logged and reviewed.
- At minimum, review the audit log of admin actions every month.
Access reviews
Permissions drift. People change roles, cover for colleagues, get temporary access that never gets removed. A quarterly access review, where each system owner confirms who has which role and removes what is not needed, is the control that keeps your matrix true over time. It takes an hour per system per quarter.
Automation and AI agents
A new version of the same problem is arriving with automation. If you connect an AI agent or an automation tool to your accounting system with a powerful API key, that agent now holds whatever permissions the key grants. An agent that can both create vendors and schedule payments is a segregation of duties conflict, even if no human ever touches it.
Treat automated identities like employees: give them a role, limit their permissions, log their actions and include them in access reviews. We have written about the broader risk of unsanctioned tools in our guide to shadow AI risk management. If you are planning to automate parts of accounts payable, the guide to automating the accounts payable process shows where to put the human checkpoints.
If you are redesigning finance processes around automation and want a second pair of eyes on where the controls should sit, that is exactly the kind of work I do with companies. You can start from the consultation request page on this site.
Segregation of duties by company size
What good looks like depends on how many people you have. Here is a practical benchmark.
Fewer than 5 people in finance or admin
- Owner holds payment release in the bank, with dual approval if a second signatory exists.
- One person handles recording, a second person or the owner handles approvals.
- Owner reviews the bank statement monthly and the vendor change report weekly.
- External accountant reviews journal entries and reconciliations monthly or quarterly.
At this size, the owner is the most important control in the company. That is not a weakness to be ashamed of. It is the design.
5 to 20 people
- Accounts payable, accounts receivable and payroll are handled by different people.
- Vendor master data is managed by someone who does not release payments.
- The controller reviews reconciliations prepared by others.
- Bank release requires two approvers above a defined threshold.
- Quarterly access reviews on the accounting system and the bank portal.
More than 20 people
- Formal role design in the ERP, documented and owned by someone.
- SoD conflict reports run automatically, at least quarterly.
- Internal audit or an external reviewer tests key controls once a year.
- Every exception to the matrix is documented with a compensating control and an owner.
A worked example: a 12-person company
Abstract principles are easy to agree with and hard to apply. Here is how the matrix plays out in a typical company with twelve employees, a part-time bookkeeper, an office manager, an operations lead and the owner.
Before the matrix. The bookkeeper creates vendors, enters invoices, prepares payment batches and reconciles the bank. The office manager has a login to the bank portal "for emergencies" and uses it most weeks. The owner approves large purchases by email but never sees the payment file. Every one of the six critical conflicts listed earlier exists at least once.
After the matrix. The changes are small:
- The owner becomes the only person who releases payments in the bank portal, from a phone, twice a week. The office manager's bank login is removed.
- The bookkeeper keeps recording and reconciliation, but vendor bank changes now require a callback by the office manager, logged in a shared sheet.
- The owner receives the bank statement directly from the bank on the first working day of each month and reads it before the bookkeeper reconciles.
- The external accountant reviews manual journal entries every quarter.
Total cost: about two hours a month of the owner's time and one hour of the office manager's. No new software, no new hire. The two most expensive conflicts (vendor data plus payment release, and approval plus payment) are now separated, and the remaining ones are covered by reviews with a fixed rhythm.
This is what segregation of duties looks like for most companies. Not a governance platform, but a short list of deliberate decisions about who touches what.
Segregation of duties in IT and cybersecurity
The same logic applies outside finance. In IT, segregation of duties means that the person who writes code should not be the only one who can deploy it to production, and the person who administers a system should not be the only one who reviews its logs.
For small companies, three IT conflicts matter most:
- Developer plus production access. Changes to systems that touch money (invoicing, payments, pricing) should go through a review before reaching production.
- Administrator plus log reviewer. An administrator can erase traces of their own actions. Someone else should review admin activity, even if only monthly.
- Security configuration plus security monitoring. The person who configures access rules should not be the only one who checks whether they are being bypassed.
These are not abstract risks. The FBI Internet Crime Complaint Center 2025 report counts about $3 billion in reported losses from business email compromise in a single year, across nearly 25,000 complaints. Those schemes work best when one person, or one compromised identity, has the access to change a bank account and approve a payment. Separating those permissions limits what an attacker can do even after they get in.
What auditors, lenders and investors ask for
If your company is raising money, applying for credit, or preparing for an acquisition, segregation of duties will come up in due diligence. The typical requests are simple: a list of users and roles in each finance system, evidence of who approves payments, recent bank reconciliations with the preparer and reviewer identified, and the delegation of authority.
Having the matrix ready, with evidence that the compensating controls actually ran, turns a weeks-long back and forth into a single document. It also signals that the business is run with discipline, which affects how buyers and lenders price risk.
The most common segregation of duties mistakes
After years of working on business processes, from a sports distribution company where AI marketing lifted sales by 30% to a hotel that grew revenue from 9 to 10 million, I see the same patterns repeat whenever money and process meet.
Designing the matrix around job titles instead of system permissions. The job description says the clerk cannot release payments. The bank portal says otherwise. Only the system matters.
Treating the owner as outside the controls. In small companies, the owner often has unrestricted access to everything and approves their own expenses. The owner is a control, but the owner also needs one: usually the external accountant or a board member.
Separating duties on paper and sharing passwords in practice. If two people share one login to the bank portal, you have one person with two names. Shared credentials destroy every separation you designed.
Never updating the matrix. A matrix built for an audit two years ago and never touched again describes a company that no longer exists.
Adding controls nobody reads. A weekly report that lands in an inbox and is never opened is worse than no report, because it creates a false sense of security. If you cannot commit to reading it, do not create it.
Forgetting temporary access. Holiday cover is the most common moment when conflicting access is granted. Set an expiry date on every temporary permission.
How segregation of duties connects to approval workflows
A segregation of duties matrix tells you who should not do what. An approval workflow tells you who must sign off on what, and at what threshold. The two need to be designed together.
Start with the thresholds. For each type of transaction (purchase orders, invoices, payments, credit notes, journal entries, capital expenditure) define who can approve up to which amount. Then check the result against the matrix: no approver should be able to approve a transaction they also initiated or will also pay.
For capital spending in particular, the approval chain needs its own logic, because a single decision can commit large amounts for years. Our guide to the CapEx approval process shows how to structure it. Expenses follow a similar pattern, covered in the guide on how to write an expense policy.
A simple delegation of authority table
| Transaction | Up to 5,000 | 5,000 to 50,000 | Above 50,000 |
|---|---|---|---|
| Purchase order | Department head | Department head plus finance | CEO |
| Invoice approval | Budget owner | Budget owner plus controller | CEO |
| Payment release | Two finance approvers | Two finance approvers | Finance plus CEO |
| Credit note | Sales manager | Sales director | CEO |
| Manual journal entry | Controller | Controller plus CFO | CFO plus external review |
The thresholds are examples. Set yours based on your transaction volumes and risk appetite. What matters is that the table exists, is known, and is enforced by the system wherever possible.
Self-assessment scorecard: how strong is your segregation of duties?
Score each statement from 0 to 2: 0 means no, 1 means partly, 2 means yes.
Design
- We have a written segregation of duties matrix covering every process where money moves.
- The matrix is based on system permissions, not job descriptions.
- Every conflict is either separated or covered by a named compensating control.
- We have a documented delegation of authority with approval thresholds.
Execution
- Vendor bank detail changes are verified by callback and reviewed by someone who cannot release payments.
- Payments above a threshold require two approvers in the bank portal.
- Bank reconciliations are prepared by someone other than the person who releases payments.
- Manual journal entries above a threshold are reviewed by someone other than the preparer.
Maintenance
- We run an access review on finance systems at least quarterly.
- Temporary access has an expiry date.
- No credentials to finance systems are shared.
- Automated tools and AI agents have limited, logged permissions and are included in access reviews.
How to read your score:
- 0 to 10: high exposure. Start with items 5, 6 and 11 this week. They close the most expensive risks at almost no cost.
- 11 to 18: the basics exist, but they depend on people remembering. Formalize the matrix and the review rhythm.
- 19 to 24: solid. Focus on maintenance, automation and how the matrix will evolve as you grow.
A 30/60/90-day plan to implement segregation of duties
Days 1 to 30: see the problem
- List every process where money moves.
- Break each process into activities and map them to the four functions.
- Export user and role lists from every finance system: accounting, ERP, payroll, banking, expenses.
- Build the first version of the matrix and mark every conflict.
- Fix the urgent items immediately: shared passwords, single-person payment release, unchecked vendor bank changes.
Days 31 to 60: decide and design
- For each conflict, decide: separate or compensate.
- Redesign roles in each system so that permissions follow the matrix.
- Write the delegation of authority table with thresholds.
- Define each compensating control: who performs it, how often, based on which report, where the evidence is kept.
- Agree the review calendar and put it in everyone's diary.
Days 61 to 90: run and verify
- Apply the new roles in each system and remove excess permissions.
- Run the first cycle of every compensating control and check that evidence exists.
- Run the first quarterly access review.
- Ask your external accountant or auditor to test three controls and tell you what they would challenge.
- Update the matrix with what you learned and set the date for the next review.
Ninety days is enough to go from no structure to a working system for a small or mid-sized company. The hard part is not the design. It is keeping the rhythm after the first quarter, when nothing has gone wrong and the reviews start to feel optional.
The real cost of getting it right
Segregation of duties is rarely expensive. The direct costs are a few days of design work, some reconfiguration in your systems, and a few hours a month of reviews. Sometimes it means hiring a part-time bookkeeper or using an external accountant for reconciliations.
Compare that with the alternative. A median fraud loss of $104,000, a typical detection time of a year, and the hidden cost of errors nobody catches. For most companies, the business case writes itself the first time someone looks at the matrix and sees one name in every column.
In the work I do with companies, from a medical center that increased capacity by 20% to a farm stay business that doubled its guests, the gains came after the process was clear, not before. Internal control is no different: clarity on who does what comes first, technology second.
If you want to build a segregation of duties matrix that fits your size and your systems, and connect it to the finance processes you are already redesigning, a structured conversation is a good place to start. You can request a consultation through the dedicated page on this site.
FAQ
What is segregation of duties?
Segregation of duties is an internal control principle that prevents any single person from controlling every step of a transaction that moves money or assets. The four functions to keep apart are authorization, custody of assets, recording, and reconciliation. When one person holds two of them for the same transaction, they can make an error or commit fraud and also hide it. Separating them ensures that a second person sees every critical step.
How do I build a segregation of duties matrix for small teams?
List the processes where money moves, such as procure to pay, payroll and treasury. Break each process into activities and map them to authorization, custody, recording and reconciliation. Then list every person and mark what each one can actually do in your systems. Highlight conflicting combinations and, for each one, either split the activities between two people or add a compensating control performed by someone outside the conflict.
What are compensating controls for segregation of duties?
Compensating controls are reviews or system restrictions that reduce risk when duties cannot be fully separated, usually because the team is small. Effective examples include a weekly review of vendor bank detail changes, dual approval of payments in the bank portal, a monthly owner review of the bank statement, and a review of manual journal entries. They work when performed by someone outside the conflict, based on system reports, on a fixed schedule.
What are the most important segregation of duties conflicts?
The most critical conflicts are changing vendor bank details while also releasing payments, approving and paying the same invoice, maintaining payroll master data while running payroll, issuing credit notes while applying customer cash, posting and approving your own journal entries, and releasing payments while reconciling the bank account. The first two are the most expensive, because they allow money to leave the company in a single step.
Can a small business with two or three people achieve segregation of duties?
Yes, partly. Perfect separation is impossible with two or three people, but the most dangerous conflicts can still be closed. The owner usually keeps payment release in the bank, with dual approval if possible, while another person handles recording. The owner reviews the bank statement monthly and vendor changes weekly, and an external accountant reviews reconciliations and journal entries. At that size, the owner is the central control.
How often should a segregation of duties matrix be reviewed?
Review user access on finance systems at least quarterly, and update the full matrix at least once a year or whenever you change systems, restructure the team, or add automation. Permissions drift over time as people change roles, cover for colleagues, or receive temporary access that is never removed. A matrix that is not maintained quickly describes a company that no longer exists.
Does segregation of duties apply to AI agents and automation?
Yes. An automation tool or AI agent connected to your accounting or banking systems holds whatever permissions its credentials grant. If it can both create vendors and schedule payments, that is a segregation of duties conflict, even without a human involved. Give automated identities a defined role with limited permissions, log their actions, keep a human approval step on payments, and include them in your regular access reviews.