Why segregation of duties exists
Segregation of duties is the oldest fraud-prevention idea in accounting — older than the word “audit.” Its logic is simple: a person who can both commit a financial wrong and conceal it is dangerous in a way that a person who can do only one is not. If the same individual approves a payment, writes the check, records the transaction, and reconciles the account, there is no point at which anyone else’s eyes cross the trail. Fraud needs no skill in that arrangement — only opportunity, which has been handed over completely.
The principle formalized as commerce scaled beyond the single proprietor. The remedy was to divide handling of any valuable transaction so completing it required multiple people, each acting as a check on the others. Over time this crystallized into a recognized set of functional categories that must be kept apart, becoming a core control activity within the COSO framework. It is the single most cited control weakness in small-business and nonprofit audits, precisely because small organizations are the ones least able to divide the work and most tempted to let one trusted person handle everything.
What is segregation of duties?
Segregation of duties is the internal control principle that divides the key functions of a financial transaction among different people, so that no single individual can both commit and conceal an error or fraud.
The classic framework separates four incompatible functions: Authorization — reviewing and approving a transaction (approving a purchase, a payment, a write-off, a credit). Custody — having access to or control over the asset itself: cash, checks, inventory, and system access such as bank logins or payment-release rights. Recordkeeping — creating and maintaining the accounting records, posting entries to the ledger. Reconciliation — independently verifying that transactions are valid, authorized, and correctly recorded. The rule: no one person should hold responsibility across more than one of these for the same transaction.
What does segregation of duties mean in practice?
Segregation of duties is best understood through the combinations it forbids — the pairings that, in one person’s hands, create the ability to perpetrate and conceal:
- Custody + Recordkeeping. The person who handles cash also keeps the books. They can take money and adjust the records to hide the gap.
- Custody + Authorization. The person who controls an asset also approves transactions involving it — they can authorize a payment to themselves.
- Recordkeeping + Reconciliation. The person who records entries also reconciles the accounts — they verify their own work, so an error or manipulation never gets independently caught.
- Receiving funds + approving write-offs. The person who takes in customer payments can also write off receivables — they pocket a payment and erase the customer’s balance to match.
A worked example: a small business has one bookkeeper who enters bills, has online banking access to release payments, records the entries, and reconciles the bank account at month-end. That single person holds all four functions. Splitting even one — having the owner release payments, or having someone other than the bookkeeper receive and review the bank statement — breaks the chain.
Where segregation of duties sits in accounting and audit standards
COSO Internal Control Framework. Segregation of duties is a core control activity under COSO’s five-component framework. It addresses the authorization, custody, and recording functions that together create or conceal financial risk.
AICPA AU-C Section 265. Requires auditors to communicate significant deficiencies and material weaknesses in internal control, of which inadequate segregation of duties is consistently the most common. Auditors specifically test whether incompatible functions are separated.
SOX Section 404. For public companies, segregation of duties is one of the most scrutinized control areas in the ICFR assessment. IT access controls — who can approve and post in the same system — are a particular focus.
Compensating controls for small entities. When headcount makes full separation impossible, the answer is compensating controls: the owner reviews and approves key transactions; the bank statement goes to someone other than the bookkeeper; an external accountant performs independent review. The goal is to restore the check that segregation would provide.
Which industries are most affected by segregation of duties failures?
| Industry | Why segregation is challenging | Highest-risk combination |
|---|---|---|
| Nonprofits | Small staff plus stewardship of donor funds | One person handles cash receipts and also records donations |
| Small business generally | Limited headcount forces one person into multiple functions | Single bookkeeper with bank access and reconciliation responsibility |
| Cash-intensive (retail, hospitality) | High volume of cash and checks raises custody/recording overlap risk | Cashier who also records daily sales and reconciles the register |
| Payroll-heavy operations | Authorizing, processing, and reconciling payroll must be separated | One person who adds employees, sets rates, and processes payroll |
| Professional services | Billing and collection concentrated in small teams | Person who bills clients also records receipts and applies credits |
How software supports segregation of duties
- QuickBooks Online. Role-based permissions can restrict who enters bills, who pays them, who reconciles, and who sees reports; the audit log records who did what. A single user granted full admin access defeats all of it — the design depends on assigning narrow roles.
- Xero. Granular user roles (e.g. a user who can enter bills but not pay them), bank-feed visibility separable from payment rights, and an immutable history per transaction.
- Sage Intacct. Multi-level authorization and dimensional restrictions enforce separation natively, with full audit trails and approval routing.
- Zoho Books. Roles, permissions, and multi-stage approval workflows that can require a different user to approve than to record.
The common thread: software can enforce the segregation you design, but it cannot design it. The most common real-world failure is a single user holding an all-access role because it was easier to set up — and that is precisely where the offshore question turns.
How CPA firms apply segregation of duties
For a CPA firm, segregation of duties is the control it flags most often and advises on most directly. In audits and reviews, inadequate segregation is the most common control weakness — the firm identifies the dangerous overlaps and recommends compensating controls. When a client genuinely cannot add staff, the firm designs the workaround: owner review, independent bank-statement access, external reconciliation.
When a firm uses offshore staff, segregation isn’t just something it assesses at clients — it’s something it must build into its own delivery engagement. That is the offshore line, and it’s the direct continuation of what internal controls establish.
How segregation of duties works in offshore accounting
Internal controls established the promise: segregation of duties is how the offshore team’s incompatible combinations are prevented. This is where that promise is kept, and it turns on a single structural fact — a natural unit of accounting work, “doing the whole client file end to end,” is intrinsically a bundle of all four incompatible functions. Authorization, custody, recordkeeping, reconciliation: a person who owns a client file completely touches all of them. Segregation of duties therefore always cuts against the grain of efficiency, and nowhere does that grain pull harder than in offshore delivery, where the entire commercial logic is “give us the file and we’ll handle it.” The cheap version of offshore is the segregation of duties violation, dressed as a value proposition.
The characteristic failure mode is end-to-end bundling — concentrating all four functions in a single offshore seat because it is efficient to have one person who just does everything for client X. It is efficient. It is also the precise arrangement that lets one person both commit and conceal, and it recreates every forbidden combination at once. What makes this specifically dangerous in the offshore context is distance. When one over-empowered person sits in the same building as the owner, an informal control still operates — the owner might simply notice something off. Offshore removes that. Distance doesn’t relax the need for segregation; it strips away the informal backstop that partially substituted for it, so formal segregation matters more offshore, not less.
The well-designed engagement answers this on two axes. Across the boundary, the two power functions stay onshore. Authorization — approving payments, write-offs, credits — and custody — control of cash, the bank login, payment-release rights — remain with the firm or client. Offshore can assemble a payment batch; the firm releases it. Within the offshore team, the two execution functions are segregated by design. Recording and reconciliation are both genuinely offshore-able — but they are themselves an incompatible pair, so they must be held by different offshore people, never the same hand, and the firm retains independent visibility of the source data. A partner that offers to own the whole file with one person is offering a control failure. A partner that insists on designed-in segregation is offering the opposite — and the difference is visible in how the engagement is structured, not in what the contract promises.
What are the common misconceptions about segregation of duties?
- “We’re too small for segregation of duties.” Small organizations need it most — they’re where one person ends up doing everything. The answer isn’t a bigger team; it’s a compensating control. The most powerful one is nearly free: the owner receives and reviews the bank statement directly, independent of the bookkeeper.
- “I trust my bookkeeper completely, so I don’t need it.” Segregation isn’t a statement about trust — it’s structural protection that also shields the honest employee from suspicion. Most occupational fraud is committed by long-tenured, trusted staff in poorly segregated roles.
- “Segregation of duties stops all fraud.” It raises the bar so fraud requires collusion. It doesn’t defeat collusion or management override — which is why it works alongside monitoring and the audit trail.
- “Letting one offshore person own the whole client file is efficient and fine.” That bundle is the violation. Owning a file end to end means holding all four incompatible functions — the exact concentration segregation exists to prevent, placed where the firm can least observe it.
What terms are commonly confused with segregation of duties?
| Confused with | The key difference |
|---|---|
| Internal controls | The broad system of all controls; segregation of duties is one specific principle within it — one important wall, not the whole structure |
| Audit trail | The detective record that proves what happened; segregation is a preventive design. Segregation prevents; the trail proves |
| Maker-checker / dual control | A specific two-person implementation (one initiates, one approves) — a way of applying segregation to one step, not the full four-function separation |
| Access controls | The IT mechanism used to enforce segregation. Segregation is the principle; access control is one means of enforcing it |
Common client questions about segregation of duties
What are the four incompatible functions in segregation of duties?
Authorization (approving a transaction), custody (physical or system access to the asset), recordkeeping (entering and maintaining the accounting records), and reconciliation (independently verifying that transactions are correct and complete). No single person should hold more than one of these for the same transaction.
How does a small business segregate duties with limited staff?
Full segregation often isn’t possible with a small team, but compensating controls can fill the gap. The most effective and nearly free control: the business owner receives and reviews the bank statement directly, independent of the bookkeeper. Other options include requiring owner approval for all payments above a threshold, having an outside accountant perform reconciliations, and rotating who handles specific tasks.
Does segregation of duties prevent all fraud?
No — it makes fraud require collusion between two or more people rather than a single actor, which is a strong deterrent but not an absolute barrier. Collusion and management override are the residual risks that segregation cannot eliminate. This is why it works alongside the audit trail, monitoring, and independent review rather than as a standalone control.
When an offshore team keeps our books, how are duties segregated?
Authorization — approving payments, write-offs, and credits — and custody, meaning control of the bank login and payment release, stay with the client or firm. The offshore team handles recording and reconciliation, split between different people so the person posting entries is not the one signing off the reconciliation. The client retains independent visibility of the bank feed.
Is letting one offshore person own an entire client file a problem?
Yes — that is a segregation of duties violation. Owning a client file end to end means one person holds all four incompatible functions: they authorize, have custody, record, and reconcile. That concentration is exactly what segregation of duties exists to prevent, and it’s placed where the firm can least observe it.