Segregation of duties is an internal control principle that divides financial work among multiple people so no single employee can initiate, approve, record, and verify the same transaction. Split the work, and any fraud scheme requires at least two people cooperating, which makes it harder to pull off and easier to catch. The Association of Certified Fraud Examiners estimates organizations lose about 5% of revenue to fraud each year, and weak duty separation is one of the most common control failures behind those losses.1Association of Certified Fraud Examiners. ACFE Report to the Nations: Organizations Lost an Average of More Than $1.5M Per Fraud Case
The practical payoff isn’t only about fraud. Even without any bad intent, a person who handles a whole transaction alone will occasionally make mistakes that nobody else sees. Splitting the work builds review into the process itself, so errors surface quickly because no one controls the full picture.
The Four Functions That Must Stay in Different Hands
Effective duty separation rests on keeping four specific functions apart. Combining any two of them in one person creates a control gap that auditors treat seriously. The four functions apply across virtually every financial process, though the job titles performing them shift depending on the cycle.
Authorization
Authorization is the formal approval that sets a transaction in motion. A manager signing a purchase order, a credit manager approving a customer’s payment terms, or an HR director authorizing a new hire’s salary are all performing this function. The person who approves a transaction should never be the same person who handles the money or records the entry.
Custody
Custody means physical or electronic control over the asset. The warehouse clerk receiving a shipment controls physical goods. The treasury employee signing checks or initiating wires controls cash. When one person both authorizes a purchase and controls the purchased asset, they can approve fake transactions and pocket the proceeds, with no one in between to catch it.
Recording
Recording is entering the financial effect of the transaction into the accounting system. The accounts payable clerk who posts a vendor invoice, or the billing clerk who records a customer sale, performs this function. If the same person who controls an asset also records its movements, they can steal the asset and adjust the books to make the shortage disappear.
Reconciliation
Reconciliation is the independent verification step: comparing what the records say to what actually exists. An accountant matching a physical inventory count to the recorded balance, or comparing bank statements to the general ledger, performs reconciliation. This function must sit with someone who had no role in recording or custody. Otherwise, the person is just checking their own work and confirming their own numbers.
Procure-to-Pay: Where Most Disbursement Fraud Lives
The procure-to-pay cycle covers everything from identifying a need through making the final payment. It’s one of the highest-risk cycles because it involves both physical assets and cash disbursements, and each step of the process maps to one of the four functions.
A purchasing manager performs authorization by creating a purchase order and sending it to the vendor. When the goods arrive, a different employee in receiving performs custody by accepting the shipment, inspecting it, and generating a receiving report. These two people should never be the same person.
Accounts payable then performs recording by assembling the purchase order, the receiving report, and the vendor’s invoice. This assembly, the “three-way match,” confirms that the company only pays for goods it actually ordered and received. Once the documents match, AP records the liability.
Finally, treasury performs custody over the cash by signing and releasing the check or initiating the electronic payment. The person who assembled and recorded the invoice package should never be the one who signs the check. If they could do both, they could fabricate an invoice for a fictitious vendor and cut themselves a check. That’s where most procure-to-pay fraud schemes live, and it’s exactly the gap that proper duty separation closes.
Payroll: Keeping HR, Managers, and Accounting Independent
Payroll requires particularly strict separation because it involves recurring, predictable cash outflows that can be manipulated in subtle ways. Three groups must stay independent: Human Resources, operational management, and the accounting or treasury department.
HR performs authorization by setting pay rates, adding new employees to the system, and processing terminations. Operational managers perform a second layer of authorization by approving the hours each employee worked. Payroll handles recording and calculation, processing authorized hours and rates to determine net pay and withholdings. Treasury or an external payroll provider performs custody by distributing the funds.
The classic payroll fraud enabled by weak duty separation is the ghost employee scheme. When one person can both add employees to the payroll system and process payments, they can create fictitious workers and funnel the paychecks to themselves. These schemes often persist for years because the fraudster keeps the fictitious salaries at unremarkable levels. Red flags include active payroll records with no corresponding time entries, duplicate bank account numbers across different employees, and payroll records that lack tax withholding documentation.
Revenue: Keeping Cash Collection Away From the Books
The revenue cycle runs from making a sale through collecting the cash, and it has its own separation requirements. The four functions here are credit approval, billing, cash collection, and reconciliation.
A credit manager performs authorization by approving customer payment terms and setting credit limits. A separate billing clerk performs recording by generating invoices after credit is approved. Collections staff handle custody by receiving payments and making deposits. An independent controller or accounting analyst performs reconciliation by comparing invoices, credit approvals, and deposit records.
If the person who collects customer payments also records those payments, they can pocket cash and manipulate the records to hide it. A common scheme is “lapping,” where the employee applies one customer’s payment to cover another customer’s stolen balance, creating a cascading cover-up that can run for months. Keeping collections staff away from the accounting records eliminates this opportunity entirely.
Unusual write-offs and credit adjustments deserve extra scrutiny. When someone who collects payments can also authorize write-offs, they can steal a payment and then write off the customer’s balance as uncollectable. Requiring a second signature on large credit memos or write-offs catches this kind of activity early.
How Auditors Rate the Gaps: Deficiency vs. Material Weakness
Auditors classify control failures on a severity scale, and the labels matter because they determine what gets disclosed and how urgently it must be fixed. Duty separation problems can land anywhere on that scale depending on how severe the gap is and how likely it is to result in a financial misstatement.
The least severe classification is a control deficiency, which exists when a control’s design or operation doesn’t allow employees to catch or prevent errors in the normal course of their work. A step up from that is a significant deficiency: serious enough to merit attention from the people overseeing financial reporting, but not severe enough to threaten the accuracy of the financial statements as a whole.2PCAOB. AS 2201 – An Audit of Internal Control Over Financial Reporting
The most serious classification is a material weakness. Under PCAOB standards, a material weakness is a deficiency, or combination of deficiencies, where there’s a reasonable possibility that a material misstatement won’t be caught in time.2PCAOB. AS 2201 – An Audit of Internal Control Over Financial Reporting For public companies, material weaknesses must be disclosed in the annual report, and the company cannot conclude that its internal controls are effective while a material weakness exists. A single person handling both recording and reconciliation for a material account balance is exactly the kind of finding that pushes auditors toward that conclusion.
Compensating Controls When You Don’t Have Enough Staff
Small businesses and nonprofits with limited staff often cannot achieve clean four-way separation across every process. When only two or three people handle all the accounting, someone is inevitably going to wear multiple hats. That reality doesn’t excuse the organization from managing the risk. It means you need compensating controls that provide oversight through different channels.
The single most effective compensating control is direct owner or manager review of bank reconciliations every month. The person reviewing should not be the person who prepared the reconciliation. They should examine the cleared check images, verify deposit amounts, and look for unfamiliar payees or unusual transactions. This one step catches a surprising number of schemes because it forces someone outside the daily transaction flow to look at where the money actually went.
Requiring two signatures on checks above a set dollar threshold is another strong control. It prevents any one person from unilaterally disbursing significant funds, so a cash scheme requires active collusion rather than just opportunity. Set the threshold low enough to be meaningful; a dual-signature requirement that only kicks in above $25,000 won’t catch the $2,000-per-week embezzlement that’s far more common.
Small organizations should also consider periodic surprise procedures performed by someone outside the normal workflow. An external accountant conducting unannounced cash counts, or reviewing vendor lists for duplicate addresses, introduces unpredictability that deters fraud. The value isn’t only in what these reviews find; employees knowing they could happen at any time is part of the point.
Keeping the Separation Real Over Time
Duty separation doesn’t enforce itself. Organizations need ongoing monitoring to make sure the separation that exists on paper actually holds up in practice, especially as employees change roles, leave the company, or accumulate system permissions.
Build a Control Matrix
The foundation of monitoring is a formal control matrix that documents which position handles each of the four functions across every major business cycle. It should be specific enough that anyone can look at it and immediately identify who authorizes, who has custody, who records, and who reconciles for a given process. When someone changes roles or a department reorganizes, the matrix gets updated first, and system permissions follow.
Watch for Permission Creep
One of the most common audit findings is system access that contradicts the documented separation. This typically happens through “permission creep”: an employee who transferred from accounts payable to treasury still has their old AP access, and now effectively controls both recording and custody in the system. When an employee changes roles or leaves, their old access must be revoked immediately. Failing to do this negates whatever physical separation exists in the org chart.
Use ERP Conflict Detection, But Actually Review the Results
Modern ERP platforms can automatically flag conflicts in user role assignments. They define pairs of functions that should never be combined, then scan all user roles to identify anyone who holds both sides of a conflicting pair. When a conflict appears, the system generates an incident report for the compliance team to investigate.
One refinement that reduces false alarms is restricting the analysis to users with conflicting access within the same business unit. If someone has an accounts payable role in one division and a treasury role in a completely separate division, the practical risk may be lower than the raw conflict report suggests. Sophisticated systems apply these filters automatically, but the compliance team still has to review the results. A report flagging 128 users with conflicts is only useful if someone actually investigates those 128 cases and either remediates the access or documents a compensating control.
The most dangerous configuration to watch for is self-approval: workflows that let a user both make a change and approve it. When finance users can self-approve modifications to vendor records or general ledger entries, the system has effectively eliminated the separation for that process, regardless of what the policy manual says. Periodic testing should specifically target these workflow configurations and verify that approval steps route to genuinely independent reviewers.
Where the Rules Make It Mandatory
For some organizations, duty separation isn’t just a best practice. Regulatory mandates make it a legal requirement with real consequences.
Publicly traded companies face the most explicit rules. Under Section 404 of the Sarbanes-Oxley Act, each annual report filed with the SEC must include an internal control report stating management’s responsibility for controls over financial reporting and containing management’s assessment of how effective those controls are.3Office of the Law Revision Counsel. 15 USC 7262 – Management Assessment of Internal Controls For companies above certain size thresholds, the external auditor must independently evaluate and report on management’s assessment as well. Section 302 adds personal accountability: the CEO and CFO must personally certify that they are responsible for establishing controls, have evaluated their effectiveness within 90 days of the report, and have disclosed all significant deficiencies and any fraud involving employees with significant control roles.4Office of the Law Revision Counsel. 15 USC 7241 – Corporate Responsibility for Financial Reports Duty separation breakdowns are among the most commonly reported control failures under these provisions.
Nonprofits filing IRS Form 990 answer a series of governance questions in Part VI about their oversight policies and practices, including conflict of interest policies, whistleblower protections, and compensation review procedures.5Internal Revenue Service. Form 990 – Return of Organization Exempt From Income Tax The Internal Revenue Code doesn’t technically mandate these policies, but organizations reporting that they don’t have them draw increased IRS scrutiny. The IRS uses Part VI responses to assess noncompliance risk across the exempt sector.6Internal Revenue Service. Form 990 Part VI – Governance, Management, and Disclosure Frequently Asked Questions
Payroll control failures also carry federal tax exposure. Under Section 6672 of the Internal Revenue Code, any person responsible for collecting and paying over employment taxes who willfully fails to do so faces a penalty equal to the full amount of unpaid tax.7Office of the Law Revision Counsel. 26 USC 6672 – Failure to Collect and Pay Over Tax, or Attempt to Evade or Defeat Tax This is a personal liability that follows the individual, not the company. When poor duty separation allows payroll fraud that diverts employment tax funds, the IRS can assess this penalty against any person who had the authority and responsibility to ensure those taxes were paid.8Internal Revenue Service. 8.25.1 Trust Fund Recovery Penalty (TFRP) Overview and Authority