Segregation of duties is the practice of splitting a task so that no single person controls it from start to finish. It is one of the oldest and most effective internal controls, and it exists because concentrating authorisation, execution, custody and recording in one pair of hands creates the opportunity for error and fraud to go undetected.
This guide explains what segregation of duties means, the principles behind it, worked examples by business function, and what to do when a team is too small to separate everything. It sits alongside the IT Finance Professional duties and responsibilities cluster, part of the wider job duties guide.
What Segregation of Duties Means
Segregation of duties, also called separation of duties, means dividing the steps in a process between different people so that completing a transaction requires more than one person. The point is not distrust of individuals. It is that a control which depends on one person being both careful and honest, forever, is not really a control.
The classic framing splits a transaction into four functions that should not sit together:
- Authorisation: approving that a transaction may happen.
- Custody: having access to the asset itself, whether cash, stock or data.
- Recording: capturing the transaction in the books or system.
- Reconciliation or review: independently checking that what was recorded matches what happened.
Why Segregation of Duties Matters
Three practical reasons, in order of how often they actually bite.
- Errors get caught. Most segregation failures surface as honest mistakes that nobody spotted, not as fraud. A second pair of eyes on a payment run catches the duplicated invoice.
- Fraud becomes harder and slower. Where one person can create a supplier, approve an invoice and release the payment, there is nothing standing between intent and money leaving.
- It protects the individual. When something goes missing and only one person had end-to-end control, that person is the only suspect. Proper separation protects honest staff as much as it protects the organisation.
Auditors and funders routinely test for it, and a lack of segregation of duties is one of the most common findings raised in small and medium-sized organisations.
Core Segregation of Duties Principles
- Separate the four functions. Authorisation, custody, recording and reconciliation should not all sit with one person for the same transaction type.
- Nobody reviews their own work. The person who prepared a reconciliation should not be the person who approves it.
- Separate master data from transactions. Whoever can create or change a supplier, employee or bank detail should not also be able to pay them.
- Match system access to the role. Segregation on paper means nothing if system permissions let one person do everything anyway.
- Consider the whole chain. Conflicts often appear across departments, not within one, so map the process end to end.
- Review after every change. Resignations, promotions and system migrations quietly recombine duties that were previously separated.
Examples by Business Function
Accounts Payable
The person who creates or amends supplier master data should not approve invoices or release payments. Ordering, receiving and paying should sit with at least two people, so that goods must actually arrive before a supplier is paid.
Payroll
Adding an employee, changing banking details and releasing the payroll run should be separated. A payroll reconciliation should be reviewed by someone who cannot change the payroll itself.
Cash and Banking
The person receiving cash should not be the person recording it or performing the bank reconciliation. Payment release should require a second authoriser above a defined limit.
Inventory and Stores
Custody of stock and adjustment of stock records should not sit together. A storeman who can also write off variances can conceal a loss with a keystroke, which is why write-offs normally need independent approval.
IT and System Access
Developers should not deploy their own changes to a live environment unreviewed, and administrators who grant access should not be the only people reviewing who has it.
Common Conflicts and Control Gaps
- One person creates suppliers and approves payments to them.
- The bookkeeper prepares and approves their own bank reconciliation.
- The person who captures stock counts also authorises stock adjustments.
- Payroll changes and payroll release sit with the same user profile.
- Signing authority is delegated informally and never documented or withdrawn.
- System roles accumulate over years as people change jobs internally.
- Segregation exists in the procedure document but not in the actual system permissions.
Segregation of Duties Matrix Examples
A segregation of duties matrix maps roles against process steps and flags the combinations that must not sit with one person. A simple version for a payment process looks like this.
| Process step | Clerk | Bookkeeper | Manager |
| Create or amend supplier | Yes | No | Approve |
| Capture invoice | Yes | No | No |
| Match to order and delivery note | No | Yes | No |
| Approve payment | No | No | Yes |
| Release payment on banking system | No | Yes | Second authoriser |
| Reconcile bank account | No | Prepare | Review |
Build the matrix from your actual process, then test it against system permissions rather than against the organogram. The gap between the two is where the real risk usually sits.
How Smaller Teams Can Add Compensating Controls
In a small business full segregation is often impossible: there may be only one person in finance. The answer is compensating controls, which do not remove the conflict but make it visible.
- Owner or director review: the owner reviews the bank statement and payment list directly, independently of the bookkeeper.
- Dual bank authorisation: require a second release on the banking platform above a low threshold.
- Exception reporting: automatic reports on new suppliers, changed banking details and manual journals, sent to someone outside finance.
- Independent reconciliation: an external accountant reviews reconciliations periodically.
- Mandatory leave: requiring uninterrupted leave means someone else runs the process at least once a year.
- Audit trails: ensure the system logs who did what and that the log cannot be edited by the same user.
Document the conflicts you cannot remove and the compensating controls you rely on instead. Auditors accept a documented, mitigated conflict far more readily than an undisclosed one.
Related Governance and Professional Guides
- IT, finance, HR and professional duties: role guides for the finance and assurance positions involved in these controls.
- Bookkeeper duties and responsibilities: where most segregation conflicts arise in smaller organisations.
- Accountant duties and responsibilities: preparation, review and sign-off responsibilities.
- Job duties: the parent guide to duties, responsibilities and job descriptions.
This page is general information on an internal control concept, not audit, accounting or legal advice. Where segregation of duties forms part of a statutory audit, a funder requirement or a regulated control environment, apply the applicable standards and take professional advice.
Last reviewed: 1 September 2026