Segregation of duties is the practice of splitting a task so that no single person controls it from start to finish. It is one of the oldest and most effective internal controls, and it exists because concentrating authorisation, execution, custody and recording in one pair of hands creates the opportunity for error and fraud to go undetected.

This guide explains what segregation of duties means, the principles behind it, worked examples by business function, and what to do when a team is too small to separate everything. It sits alongside the IT Finance Professional duties and responsibilities cluster, part of the wider job duties guide.

What Segregation of Duties Means

Segregation of duties, also called separation of duties, means dividing the steps in a process between different people so that completing a transaction requires more than one person. The point is not distrust of individuals. It is that a control which depends on one person being both careful and honest, forever, is not really a control.

The classic framing splits a transaction into four functions that should not sit together:

Why Segregation of Duties Matters

Three practical reasons, in order of how often they actually bite.

Auditors and funders routinely test for it, and a lack of segregation of duties is one of the most common findings raised in small and medium-sized organisations.

Core Segregation of Duties Principles

Examples by Business Function

Accounts Payable

The person who creates or amends supplier master data should not approve invoices or release payments. Ordering, receiving and paying should sit with at least two people, so that goods must actually arrive before a supplier is paid.

Payroll

Adding an employee, changing banking details and releasing the payroll run should be separated. A payroll reconciliation should be reviewed by someone who cannot change the payroll itself.

Cash and Banking

The person receiving cash should not be the person recording it or performing the bank reconciliation. Payment release should require a second authoriser above a defined limit.

Inventory and Stores

Custody of stock and adjustment of stock records should not sit together. A storeman who can also write off variances can conceal a loss with a keystroke, which is why write-offs normally need independent approval.

IT and System Access

Developers should not deploy their own changes to a live environment unreviewed, and administrators who grant access should not be the only people reviewing who has it.

Common Conflicts and Control Gaps

Segregation of Duties Matrix Examples

A segregation of duties matrix maps roles against process steps and flags the combinations that must not sit with one person. A simple version for a payment process looks like this.

Process stepClerkBookkeeperManager
Create or amend supplierYesNoApprove
Capture invoiceYesNoNo
Match to order and delivery noteNoYesNo
Approve paymentNoNoYes
Release payment on banking systemNoYesSecond authoriser
Reconcile bank accountNoPrepareReview

Build the matrix from your actual process, then test it against system permissions rather than against the organogram. The gap between the two is where the real risk usually sits.

How Smaller Teams Can Add Compensating Controls

In a small business full segregation is often impossible: there may be only one person in finance. The answer is compensating controls, which do not remove the conflict but make it visible.

Document the conflicts you cannot remove and the compensating controls you rely on instead. Auditors accept a documented, mitigated conflict far more readily than an undisclosed one.

Related Governance and Professional Guides

This page is general information on an internal control concept, not audit, accounting or legal advice. Where segregation of duties forms part of a statutory audit, a funder requirement or a regulated control environment, apply the applicable standards and take professional advice.

Last reviewed: 1 September 2026