What it means
The idea behind segregation of duties is simple: most serious frauds and most expensive errors need one person to control several steps in a row. Splitting those steps between people means a problem has to survive a second pair of eyes before it reaches the accounts or the bank.
Auditors usually break a transaction into four duties: authorising it, recording it, holding the related asset (custody), and reconciling or reviewing the result. The rule of thumb is that one person should never hold more than two of the four, and should never combine authorisation with custody of the cash.
For a business the pay-off is not only fraud prevention but also error detection, because the reviewer catches honest mistakes long before the year-end close. Auditors, lenders and insurers all look for this control, and a documented weakness here can lead to awkward questions during an audit or a due diligence exercise.
In practice the control is enforced through system permissions rather than good intentions, so the accounting platform is configured such that the clerk who raises a purchase order cannot also release the payment run. Larger organisations run periodic access reviews, listing every user and every conflicting permission pair, then removing the access that has quietly accumulated as people changed roles.
The obvious objection is that a five-person company cannot split every duty cleanly. The standard answer is compensating controls: the owner opens the bank statement personally, reviews the payment run before it is released, and signs off on every change to supplier bank details, which restores oversight without adding headcount.
A common variant is the four eyes principle, where any payment above a set threshold needs a second approver regardless of who prepared it. Both approaches accept that controls cost time, so sensible businesses set thresholds that concentrate the effort on the transactions large enough to hurt them.
In practice
Real-world examples.
Example
A 40-person marketing agency discovers that its bookkeeper both creates new supplier records and releases the weekly payment file. The finance manager takes over supplier approval, the bookkeeper keeps invoice entry, and the managing director releases payments. In the first month the new review catches a duplicate invoice worth $9,400 that would otherwise have been paid twice.
Example
A retail chain has store managers counting the till and also preparing the deposit records that head office checks against. The group introduces a split where the assistant manager counts, the manager records, and a regional accountant reconciles both against the point-of-sale report.
Example
A software company preparing for its first external audit is told that one accountant posts journal entries and also performs the monthly bank reconciliation. Reconciliation moves to a financial planning analyst who reports to a different manager, and the auditors drop the finding the following year.
Think of it
“Segregation of duties means no one person controls everything-splitting responsibilities.
Case study
Seen in the real world.
Kestrel Joinery is an illustrative, entirely fictional cabinet maker with 60 staff and a two-person finance function. Its office manager set up suppliers, entered invoices, released the weekly payment run and filed the bank statements, an arrangement that had grown up over nine years without anyone questioning it.
When the founder applied for an equipment loan, the lender asked for a short summary of financial controls and the gap became obvious. The founder introduced a simple split: the office manager still enters invoices, a part-time bookkeeper reviews and posts them, and the founder personally approves any change to supplier bank details and releases any payment above $5,000.
Within one quarter the new review caught two duplicated invoices worth $6,200 between them and one supplier bank-change request that turned out to be an attempted fraud by email. No dishonesty was ever found in the old arrangement, but the illustrative point stands: the control paid for itself in errors alone.
Watch out
Common mistakes.
- Treating segregation of duties as an anti-fraud measure only, when most of the value in a small business comes from catching ordinary mistakes early.
- Assuming a small team cannot apply it at all, instead of using compensating controls such as owner review of the bank statement.
- Designing the split once and never reviewing system access again, so permissions pile up as people change jobs and the control quietly disappears.
Questions
People also ask.
What are the four duties that should be kept apart?
Authorising the transaction, recording it, holding custody of the asset, and reconciling or reviewing the outcome.
Is segregation of duties a legal requirement?
Not generally for private companies, though listed companies and regulated firms face formal internal control requirements, and lenders and auditors expect to see it.
Can accounting software enforce it on its own?
The software enforces the permissions, but a person still has to review the user access list and act on the conflicts it reveals.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%