Segregation of duties has a reputation as the control that makes small teams miserable, and it earns that reputation whenever it is written as a headcount requirement rather than as a statement about which pairs of actions must not meet in one person.
The rule is about pairs
The risk is not that one person did several things. It is that one person did two particular things: created the supplier and approved the payment, or changed the bank details and released the run. Those pairs are short lists, and everything outside them is fine in any combination.
Written as pairs, a five-person finance team can satisfy the same control that a headcount rule says needs eleven people — and the pairs version is the one that actually describes the fraud you are worried about.
Compensating controls are not a consolation prize
Where a pair genuinely cannot be separated, the answer is a detective control with teeth: a review of exactly those transactions, by someone outside the function, with a record that they looked. That is a legitimate answer, and auditors accept it routinely when it is documented as a deliberate choice rather than discovered as a gap.
What they do not accept is the same arrangement with no review and no documentation, which is what the gap looks like from outside.
The three that matter most
- Supplier creation and payment approval.
- Bank detail changes and payment release.
- Policy changes and the spend they govern.
The second is where nearly all real payment fraud lives, and it is the one most often left unseparated because changing bank details feels administrative.
Test it by trying it
Once a quarter, take one person and list everything they could do end to end without anyone else. Not what they do — what the permissions allow. The gap between the two is the control you have not written down yet.





