Skip to content
Log inBook a demo
Compliance

Segregation of duties without the friction

Most segregation rules are written as headcount.Written as combinations instead, they get stronger and considerably cheaper to live with.

Bram de Vries

Compliance Lead, Finly · · 1 min read

An analyst working through a control matrix at a whiteboard

Segregation of duties has a reputation as the control that makes small teams miserable, and it earns that reputation whenever it is written as a headcount requirement rather than as a statement about which pairs of actions must not meet in one person.

The rule is about pairs

The risk is not that one person did several things. It is that one person did two particular things: created the supplier and approved the payment, or changed the bank details and released the run. Those pairs are short lists, and everything outside them is fine in any combination.

Written as pairs, a five-person finance team can satisfy the same control that a headcount rule says needs eleven people — and the pairs version is the one that actually describes the fraud you are worried about.

Compensating controls are not a consolation prize

Where a pair genuinely cannot be separated, the answer is a detective control with teeth: a review of exactly those transactions, by someone outside the function, with a record that they looked. That is a legitimate answer, and auditors accept it routinely when it is documented as a deliberate choice rather than discovered as a gap.

What they do not accept is the same arrangement with no review and no documentation, which is what the gap looks like from outside.

The three that matter most

  • Supplier creation and payment approval.
  • Bank detail changes and payment release.
  • Policy changes and the spend they govern.

The second is where nearly all real payment fraud lives, and it is the one most often left unseparated because changing bank details feels administrative.

Test it by trying it

Once a quarter, take one person and list everything they could do end to end without anyone else. Not what they do — what the permissions allow. The gap between the two is the control you have not written down yet.

Bram de Vries

Compliance Lead, Finly

Bram handles controls and audit readiness at Finly, after six years of being the person auditors asked for the evidence nobody had kept.

More from Bram

Keep reading

More from compliance.

Get started

Open an account today. Change plan any month.

Issue your first card the same day.Or let us run your own last month through a sandbox first, so you see the close before you commit to anything.