Skip to main content
All articles

Fraud Risk

Segregation of Duties: Examples and Compensating Controls for Small Teams

By RiskSensai6 min read
Editorial archive date
First published
Facts checked

The archive date places this article in the editorial collection. It is not an original publication date. Guidance reflects the fact-check date above.

Segregation of Duties: Examples and Compensating Controls for Small Teams: original RiskSensai editorial cover

Find the conflict before assigning roles

Segregation of duties is useful because an individual with too much connected authority may be able to create and conceal an error or unauthorized action. The problem is the combination of powers, not the number of employees on the organizational chart.

A finance clerk may prepare payments and reconcile the bank. An administrator may change production access and remove the resulting logs. A founder may approve their own expenses. Each conflict needs a specific response rather than the same “two-person approval” label.

GAO's Green Book discusses separating authority, custody and accounting functions, while recognizing that limited personnel may require alternative controls.1 It is a federal-agency framework used here as a design reference, not a universal mandate for private companies.

Map actual permissions and practice

Begin with one process: supplier onboarding and payment, payroll, refunds or software changes. List its steps in order and identify who can perform each in the actual systems. Include deputies, emergency access, shared accounts and outsourced service providers.

Then check whether nominal separation is real. Someone described as a reviewer may also have permission to edit the record before reviewing it. A manager may approve a payment but see only its total, not its payee or evidence. A shared login may erase the identity of the person acting.

NIST's separation-of-duties control connects documented duties with system access authorizations.2 That connection is important: a policy cannot establish separation if the software gives a person all incompatible powers.

Original duty-conflict matrix

Use this worksheet to test one process. Put names or defined roles in the second column and actual access evidence in the third.

DutyCurrent performerAccess and practice to verifyPotential conflicting duty
Create supplier[Person]Supplier-create and edit rightsRelease supplier payment
Change bank details[Person]Bank-change permission and contact methodApprove the change
Prepare payment batch[Person]Payment preparation rightsFinal release
Release payment[Person]Bank release rightsReconcile own payments
Reconcile account[Person]Statement access and reconciliation editsInitiate/release transactions
Review reconciliation[Person]Direct evidence and escalation authorityPrepare the same reconciliation

This is an illustrative finance process, not a complete required matrix. Add the duties that make your transactions different, such as receiving goods or issuing credits.

For every conflict, record the exposure, proposed separation, cost/practicality and any remaining exception. A reviewer should be able to tell why a conflict remains and how it is addressed.

Worked example: a three-person business

Fictional scenario: A service company has an owner, an office manager and a part-time bookkeeper. The office manager currently enters suppliers, prepares payments and reconciles the bank. The owner occasionally approves a total without checking details.

The team redesigns the highest-consequence steps. The office manager prepares invoices and payment batches. The owner independently verifies bank changes through an established contact and reviews payees and supporting invoices before releasing payment. The bookkeeper performs the reconciliation using statements obtained through authorized direct access.

When the bookkeeper is unavailable, the office manager may prepare the reconciliation, but the owner performs a documented detailed review of bank entries, changes and exceptions. The exception has an expiry and cannot silently become the permanent process.

This arrangement still has limitations. The owner has substantial authority, and the other staff may lack the power to challenge management override. The business documents that residual risk and considers appropriate external review rather than claiming the matrix prevents all fraud.

What makes a compensating control useful?

A compensating control should address the specific missing protection. University of Florida's institutional guidance explains why additional review is a fallback when staffing prevents ideal separation, and why it should not replace separation where that is feasible.3

A useful design states:

  1. Conflict: Which incompatible duties remain with one person?
  2. Risk: What could be created, changed, concealed or lost?
  3. Reviewer: Who has sufficient competence, authority and distance from the action?
  4. Evidence: What source can challenge the operator's record?
  5. Timing: Will review happen before the action or soon enough afterward to matter?
  6. Escalation: What happens when evidence is missing or inconsistent?
  7. Limit: What risk remains despite the review?
  8. Expiry/reassessment: When will the exception be reviewed or removed?

“Owner keeps an eye on it” is not enough. The control needs an observable procedure and retained result. A signature on the cover page does not establish what was checked.

A technology example: deploy and review

A second fictional team has one developer who can deploy production changes and edit monitoring configuration. It cannot immediately hire another engineer.

The team identifies what can be separated now: business approval of high-impact changes, restricted administrator use, protected deployment history and post-change validation by another authorized person. For emergency changes, it defines a limited exception with prompt retrospective review.

The reviewer needs enough information to evaluate the change, and evidence should not rely solely on a report the developer can silently rewrite. This is a proposed control pattern, not a promise that a single reviewer can perform a complete security assessment.

Do not confuse business acceptance with technical review. A product manager can confirm that a workflow behaves as intended but may need specialist help to assess a complex access change.

Test separation without causing harm

Review permission exports and a bounded sample of completed transactions. In a safe test environment, verify that unauthorized roles are denied. Do not attempt unapproved payments, privilege changes or access to customer information merely to test the matrix.

Inspect whether approvals occurred at the right time and whether reviewers could see relevant evidence. Look at exceptions and deputy use, where practical separation often breaks down. Record sample limitations and unresolved questions.

If a conflict appears only when an employee is on leave, update the deputy process. A policy that works only when every team member is present is incomplete.

Keep the matrix current

Recheck duties after staffing changes, new software, outsourcing and material changes in transaction volume. Remove obsolete access rather than relying on a person remembering not to use it.

Connect conflicts to remediation records with an owner, due date and closure evidence. Closure might require a verified permission change and a successful sample approval, not just an updated job description. The remediation template provides a structure for that work.

Questions small teams ask

Is two-person approval always segregation of duties?

No. Both people may have the same conflicting rights, or the approver may lack evidence. Examine authority and actual review.

Does a compensating control prove equivalent protection?

No generic review proves equivalence. Assess the specific risk, procedure, evidence and limitations. Some risks remain unacceptable without real separation.

Can one person own the process?

Yes. Accountability for a process differs from performing every incompatible duty within it. The readiness assessment can begin a broader discussion, but it does not verify your permission matrix or establish independent assurance.

Sources and references

  1. U.S. Government Accountability Office. Standards for Internal Control in the Federal Government: 2025 Green Book (2025-05-15). Federal-agency framework, effective FY2026; voluntary reference here for private-business control design. ↩

  2. NIST. SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations (2020-12-10). Tailorable control catalog; current landing page also links later control releases. It is not a universal private-business requirement. ↩

  3. University of Florida CFO Division. Compensating Controls. Institutional control guidance illustrating alternatives when staff limitations prevent ideal separation. ↩

General educational information, not legal advice, a professional audit opinion, certification, or a guarantee. Applicability and conclusions depend on your organization and should be assessed by an appropriately qualified professional.

Prepared with AI assistance and automated editorial checks. This does not indicate independent professional review or verification of your organization.

  • Segregation Of Duties
  • Access Controls
  • Finance Controls
Connecting to your conversation workspace…