All posts
6 min readUpdated July 22, 2026

What is segregation of duties?

By MacrosLM Team · Reviewed by Anel Komratova, ex-PwC Audit Expert

Segregation of duties (SoD) means splitting a process across more than one person so no single individual controls it from start to finish. One person requests a payment, another approves it, a third reconciles the account. No one hand touches the whole transaction — which is exactly the point.

It's one of the oldest ideas in internal control, and it scales from a small-business owner splitting bookkeeping from bill payment to a Fortune 500 company mapping access rights across a dozen finance systems. It's also one of the first things a SOX auditor asks to see.

The four duties that must never combine

Underneath every SoD rule is one framework, sometimes shortened to ACRR: authorization, custody, recording, and reconciliation. The insight is that fraud (and undetected error) becomes possible when one person holds more than one of these for the same asset — because the combination lets them both commit an act and conceal it.

The core frameworkFour duties that must never sit with one person
A

Authorization

Approve the transaction before it happens.

e.g. sign off on a purchase order or a payment run.

C

Custody

Hold or control the asset itself.

e.g. access to cash, cheques, inventory, or the ability to release a payment.

R

Recording

Enter the transaction in the books.

e.g. post the invoice or the journal entry to the ledger.

R

Reconciliation

Independently check that records match reality.

e.g. reconcile the bank account or the subledger.

The rule: no single person should perform more than one of these for the same asset or transaction. Whoever authorizes shouldn't also hold custody; whoever records shouldn't also reconcile. Hold two, and you can both commit and conceal.

Concretely: someone who can authorize a payment and also has custody (can release the cash) can pay themselves. Someone who records transactions and also reconciles the account can post a false entry and then sign off that everything ties. Separating the four is what forces a second person into the loop.

Why it matters more than it sounds like it should

If one person can create a vendor, approve the invoice, and cut the cheque, nothing stops them from paying a fake vendor. Split the steps and fraud requires collusion instead of opportunity — a much higher bar that's usually enough to stop it before it starts. The ACFE's Report to the Nations consistently finds that more than half of occupational-fraud cases trace to a missing internal control or an overridden one, with a global median loss well into six figures.

It's not only about bad actors. Most SoD failures aren't fraud — they're an honest mistake nobody caught because nobody else was looking. A second set of eyes on an entry, an approval, or a reconciliation catches errors before they compound into a bigger cleanup later. SoD is preventive by design: it stops the problem from being possible, rather than detecting it after the fact.

The conflict matrix

Auditors and controls teams turn the ACRR principle into a concrete conflict matrix — a grid of sensitive functions with the incompatible pairs marked. It's the working document behind an SoD review: list who can do what in the ERP, then flag anyone holding both sides of a marked pair.

 Create vendorApprove payExecute payPost JEReconcileManage access
Create vendor
Approve pay
Execute pay
Post JE
Reconcile
Manage access

✕ = must be separated · blank = generally compatible · — = same duty. Illustrative — every organization tailors its own matrix. Note how "Manage access" conflicts with everything: whoever can grant permissions can hand themselves any other duty, which is why IT access is tested as rigorously as the accounting duties.

The conflicts auditors flag most often:

Task pair held by one personWhy it's a problem
Create vendor + approve vendor paymentCan set up a fake vendor and pay it
Prepare + post journal entryNo independent check before it hits the books
Reconcile bank account + approve payments from itCan hide a discrepancy they created
Process payroll + approve payroll changesCan add a ghost employee and pay them
Request + approve system accessCan grant themselves permissions no one signed off on

None of these mean the person has done something wrong — only that nothing stops them if they try. That gap is the whole reason the control exists.

A cautionary pattern

The textbook embezzlement case is almost always an SoD failure. A long-trusted bookkeeper or treasurer ends up holding custody (access to the bank), recording (the ledger), and reconciliation (the monthly bank rec) all at once. They move money out, book it to an innocuous account, and — because they also perform the reconciliation — the statement always ties. The scheme runs for years precisely because no independent person ever compares the bank to the books. The fix isn't a smarter detective control; it's structural: take the reconciliation away from whoever touches the cash and the ledger.

Preventive by design — and how to fix a conflict

When a review surfaces a conflict, there are three ways to resolve it, in order of preference:

  • Redesign the role. The cleanest fix — move one of the conflicting duties to a different person so the conflict simply doesn't exist. Not always possible on a small team.
  • Add a compensating control. When you can't split the duties, layer an independent check on top: an independent review of every payment the conflicted user processes, a manager sign-off, an exception report someone else reviews. Document the compensating control and confirm it actually operates — a conflict "mitigated" by a control nobody performs is still open.
  • Re-certify access periodically. Conflicts creep in by accident when someone picks up a task in a busy quarter and the access is never removed. Periodic user-access re-certification (quarterly or semi-annual) catches this drift.

Edge cases and common errors

  • Small teams can't fully separate every role — so they lean on compensating controls. Document them; don't just note the conflict and move on.
  • Access creep is the silent failure. Conflicts appear when access accumulates and no one removes it — re-certification catches it.
  • It's not only accounting. IT access management has the same problem: whoever can request and grant their own elevated permissions has a blank cheque — which is why "Manage access" conflicts with everything on the matrix.
  • A flag isn't a finding. Holding both sides of a conflict means nothing stops wrongdoing, not that it happened — disposition (real risk vs. mitigated) is a judgment call.
  • For public companies it's not optional. SOX 404 auditors ask for the SoD matrix early; an unresolved conflict shows up as a control deficiency, sometimes serious enough to delay a filing.

A worked example: an ERP access review

What testing looks like as a deliverable: a set of ERP users tested against the conflict matrix, flagging who holds both sides of an incompatible pair — with severity, status, and a remediation or compensating-control note on each finding.

Interactive — click to explore

Where the data comes from

InputSource
User access / rolesERP and application access listings
Conflict rulesThe firm's SoD matrix of incompatible duty pairs
Compensating controlsControl documentation / management sign-off records

Determining who holds which capabilities across every system, identifying every conflict, and documenting the results for the auditor is tedious, repetitive work — precisely the category of effort that formerly consumed days of a team's time and increasingly need not. MacrosLM's controls agents pull the access data, test it against the conflict matrix, and produce the exhibit with each flagged conflict traced to the underlying permissions. Whether a conflict is a real risk or covered by a compensating control stays human.

Bottom line

Segregation of duties splits the four core functions — authorization, custody, recording, and reconciliation — so no one person controls a transaction end to end, turning fraud from an opportunity into something that requires collusion. It's one of the cheapest, most effective controls there is, one of the first things a SOX auditor checks, and — through the conflict matrix and periodic access re-certification — very testable. Design it in, document the exceptions, and re-check access before it drifts.


Sources

This article is for general information and is not legal, audit, or compliance advice. Control design and remediation depend on the specific organization and should be reviewed by a qualified professional.

Frequently asked questions

What is segregation of duties?
Segregation of duties (SoD) denotes the division of a process across more than one individual such that no single person controls it from initiation to completion — one person requests a payment, another approves it, and a third reconciles the account. It is a foundational internal control that transforms fraud from a matter of opportunity into one requiring collusion.
Why is segregation of duties important?
Because where a single individual can create a vendor, approve the invoice, and issue the check, nothing prevents payment to a fictitious vendor. Dividing the steps forces collusion rather than opportunity, and introduces an independent review that also detects honest error. The ACFE finds that more than half of occupational fraud traces to a missing or overridden control.
What are common segregation-of-duties conflicts?
The classic incompatible pairs held by a single individual are: creating a vendor and approving payments to it; preparing and posting a journal entry; reconciling a bank account and approving payments from it; processing payroll and approving payroll changes; and requesting and approving one's own system access.
How does segregation of duties relate to SOX?
For public companies, the control is not discretionary. Section 404 of the Sarbanes-Oxley Act requires management to document and test internal control over financial reporting, and a segregation-of-duties matrix — identifying who may create, approve, and post a transaction — is among the first items auditors request. An unresolved conflict is reported as a control deficiency, in some cases of sufficient severity to delay a filing.
AK

Reviewed by Anel Komratova

ex-PwC Audit Expert. Written by the MacrosLM editorial team.

View profile →