Segregation of duties means splitting authorization, custody, recordkeeping, and reconciliation across different people so no single employee can commit and conceal fraud or an error alone. It's the control that reduces both fraud risk and the chance of misstated financial reports, which is why it sits at the center of two major frameworks:
- COSO treats it as a core control activity in its internal control framework, guiding how organizations design preventive and detective controls.
- The GAO Green Book lists it under the design of control activities and explicitly allows for scalable, compensating controls when a small team can't fully separate tasks.
Key Takeaways
A segregation of duties matrix works only when it maps actual system entitlements, not job titles, and gets reviewed on a fixed quarterly or annual cadence tied to risk.
| Point | Details |
|---|---|
| Separate four core functions | Authorization, custody, recordkeeping, and reconciliation should never sit with one person on the same transaction. |
| Start with AP, payroll, procurement | These three areas carry the highest fraud exposure and the clearest audit trail for a first matrix. |
| Map entitlements, not titles | Pull actual system access reports; job titles routinely misrepresent what someone can actually do. |
| Document compensating controls | Supervisory review, second approvers, and exception logs satisfy auditors when full separation isn't possible. |
| Set a review cadence and stick to it | High-risk rows need quarterly review; everything else needs at least an annual check. |
Table of Contents
- Segregation of Duties in Practice: The Functions Auditors Check First
- Building a Segregation of Duties Matrix: Fields, Risk Ratings, and Review Cadence
- Map Entitlements, Not Job Titles
- Compensating Controls for Small Teams
- Keeping the Matrix Alive: Testing and Remediation
- What Operational Efficiency Audits Usually Turn Up
- Get Your Segregation of Duties Matrix Audit-Ready
- Primary Sources Worth Saving for Audit Evidence
- The Real Priority Most SoD Advice Gets Backward
- Sources
Segregation of Duties in Practice: The Functions Auditors Check First
Four functions need separation in any control-conscious organization: authorization (approving a transaction), custody (handling the asset, like cash or inventory), recordkeeping (entering it into the books), and reconciliation (verifying it independently). When one person controls two or more of these for the same transaction, you have a conflict worth flagging.
Auditors gravitate toward specific "money in, money out" zones because that's where the highest concentration of past fraud schemes lives. In accounts payable, the person who enters a new vendor should never also approve that vendor's invoices. In payroll, whoever sets up a new employee record shouldn't be the same person who approves the pay rate or signs off on hours. Vendor creation is a classic blind spot: someone with the rights to both create a vendor and issue a payment can build a fake vendor and pay it without a second set of eyes ever seeing it. Bank reconciliation stays high on the checklist too, since the person recording cash transactions should not be the one reconciling the bank statement against the ledger.

Pro Tip: Pull your last three vendor additions and trace who created the record versus who approved the first payment. If it's the same login, you've found your first matrix entry.
Building a Segregation of Duties Matrix: Fields, Risk Ratings, and Review Cadence
A segregation of duties matrix is the working document that turns the concept into something you can hand an auditor. It doesn't need to be complicated to be useful. At minimum, a usable matrix needs six fields:
- Task — the specific action (e.g., "approve purchase order")
- Conflicting task — the action that creates risk if held by the same person (e.g., "receive goods")
- Risk rating — high, medium, or low, based on dollar exposure and detection difficulty
- Compensating control — what mitigates the risk if separation isn't feasible
- Owner — the named person accountable for monitoring that row
- Review cadence — how often the row gets reassessed
| Field | Example Entry |
|---|---|
| Task | Approve vendor payment |
| Conflicting task | Create/edit vendor master record |
| Risk rating | High |
| Compensating control | Monthly vendor master change report reviewed by controller |
| Owner | AP Manager |
| Review cadence | Quarterly |
Start scoping with accounts payable, payroll, and procurement. Those three areas carry the highest fraud exposure and the clearest audit trail, so they deliver the fastest return on the effort. Manual spreadsheets work fine for a first pass in a company with under 50 employees, but once you're managing role changes across multiple systems, automated detection tools start paying for themselves in reduced review time.
Pro Tip: Rate risk by dollar exposure times detection difficulty, not by gut feeling. A $500 error caught monthly rates lower than a $50,000 wire that only gets reviewed annually.
Map Entitlements, Not Job Titles
Job titles lie about actual system access more often than people expect. Two employees with different titles can still create a toxic combination if their combined entitlements let one create a vendor and the other approve payment to it. That's why entitlement-level mapping matters more than an org chart ever will.
Permission creep is the quiet killer here. An employee promoted three times in five years often accumulates every access right from each prior role, because IT rarely revokes anything on a promotion. Nobody notices until an audit pulls the entitlement report and finds a mid-level accountant who can still approve journal entries from a job she left two years ago.
- Run a joiner-mover-leaver process that revokes old access the same day a role changes, not at the next quarterly review.
- Pull entitlement reports directly from the ERP system rather than relying on HR's org chart.
- Log every access change and tie it to an approval ticket.
- Review high-risk roles (AP, payroll, treasury) quarterly; review everything else at least annually, per practitioner guidance on review cadence.
Manual access reviews still work for smaller entitlement sets, but they scale poorly past a few hundred user accounts spread across multiple systems.
Compensating Controls for Small Teams
Full separation isn't realistic for a five-person finance department, and both COSO and the GAO Green Book acknowledge that directly. What they expect instead is a documented compensating control that closes the gap.
The standard toolkit includes:
- Supervisory review of transactions above a set dollar threshold, performed by someone outside the process.
- Mandatory second approver on any payment, journal entry, or vendor change, even if that approver isn't full time in finance.
- Transaction sampling, where a manager pulls a random slice of the month's activity for detailed review rather than reviewing everything.
- Exception logs that capture every instance where normal separation couldn't hold, with a reason and a sign off.
Document each control with a name, a date, and a specific transaction reviewed, not a vague statement that "management oversees the process." Auditors accept compensating controls as a bridge, not a destination. If the same compensating control has been in place for three years with no plan to hire or restructure, that's a sign the organization has outgrown the workaround.
Keeping the Matrix Alive: Testing and Remediation
A segregation of duties matrix built once and filed away is worthless within a year. Roles change, systems get upgraded, and new hires inherit access nobody double checked.
- Set a baseline cadence. Review high-risk rows quarterly and everything else annually, with an off-cycle trigger for any ERP upgrade, reorganization, or new system rollout.
- Test the matrix against live entitlements, not job descriptions. Pull the actual access report and cross-reference it against every row.
- Remediate toxic combinations immediately by removing the conflicting access, adding a compensating control, or reassigning the task.
- Document every exception in a standing log auditors can review without asking follow up questions.
Pro Tip: Keep a one-page remediation tracker with the date found, the toxic combination, the fix applied, and the sign off. Auditors spend less time asking questions when they can see the trail themselves.
What Operational Efficiency Audits Usually Turn Up
Operational efficiency audits tend to surface segregation of duties problems that nobody flagged internally, mostly because the people closest to a process stop noticing its risks. Amcfo's operational efficiency audits and accounting and bookkeeping work regularly turn up permission creep and undocumented compensating controls that a company assumed were still active. A common finding: an AP clerk promoted into a supervisor role a year earlier who still holds vendor creation rights.
The gap is rarely dishonesty. It's usually a promotion nobody followed up on, or a compensating control that got written down once and never checked again.
Before deciding whether you need outside help, run through this:
- Can you name who created your last five new vendors and who approved their first payment?
- Does your payroll approver also process new hires?
- When did you last pull a live entitlement report instead of trusting the org chart?
- Do you have a documented compensating control for every unavoidable conflict?
- Has any compensating control been in place unchanged for over two years?
- Would your matrix survive a surprise audit tomorrow?
If more than two answers worry you, a structured operational efficiency audit is worth the conversation.
Get Your Segregation of Duties Matrix Audit-Ready
Building a matrix is one project. Keeping it current while running a business is another, and it's the piece most internal teams let slip after the first year. Amcfo works directly with finance leaders to map entitlements against live systems, document compensating controls that will hold up under audit, and set a review cadence that doesn't fall apart the moment someone gets promoted. If you suspect a control gap has already been exploited, Amcfo's forensic accounting team investigates the transaction history and quantifies exposure. For ongoing bookkeeping and control design, Amcfo's accounting and bookkeeping services build the separation into your monthly close process from the start rather than bolting it on after an incident.
Primary Sources Worth Saving for Audit Evidence
Keep PDFs of these on file. Auditors expect citations, and having the primary source ready speeds up every review conversation.
- COSO's Internal Control Framework defines control activities and where segregation of duties fits within them.
- The GAO Green Book covers scalability and compensating controls for smaller organizations, directly relevant to any team under 50 people.
- NIST's separation of duty glossary entry explains static versus dynamic enforcement and the two-person rule for IT systems.
- OMB Circular A-123 distinguishes preventive from detective controls in federal guidance, useful language for private-sector policy writing.
- ISACA's implementation guide walks through entitlement mapping step by step, the same approach this article recommends.
The Real Priority Most SoD Advice Gets Backward
Most guidance on this topic leads with the matrix template, as if the spreadsheet itself creates the control. It doesn't. The workflow design comes first; the matrix just documents what you already decided about who touches what. Skip that sequencing and you get a beautifully formatted document that describes a process nobody actually follows.

The bigger blind spot is entitlement drift. Companies spend real effort building an initial matrix, then treat it like a compliance artifact rather than a living record. The failure mode isn't usually a missing control. It's a control that existed on paper eighteen months ago and quietly stopped matching reality the moment someone got promoted or a system migration reshuffled access rights.
If you're prioritizing one thing from everything here, prioritize the entitlement review over the matrix design. A mediocre matrix checked quarterly against live access beats an elegant matrix nobody has opened since it was built. Small teams especially should stop apologizing for compensating controls. A documented second approver, reviewed and evidenced consistently, satisfies auditors more than a "clean" org chart that nobody actually enforces.
— Angelica
This article is general information, not a substitute for advice from a qualified financial advisor. Consult a qualified financial professional about your own circumstances before acting on anything here.
Sources
- COSO — Internal Control Framework (segregation of duties references)
- GAO — Standards for Internal Control in the Federal Government (Green Book)
- NIST — Separation of duty (glossary)
- ISACA — A step-by-step SoD implementation guide
- Zluri — How to build an SoD matrix (template)
