Glossary
Segregation Of Duties
Segregation of duties is the control principle that no single person should be able to authorize a transaction, handle the related asset, and record it in the books all by themselves. Split those three functions across different people (or at minimum, add a second set of eyes before money moves) and it becomes much harder for an error or a deliberate act to go undetected. At Treewalk, we build this into how we staff and process client accounting from day one, not as a checklist item added after something goes wrong.
What it actually is
Most guidance on segregation of duties boils it down to three functions that should never sit with one person:
Authorization
: approving that a transaction should happen (signing off on a purchase, approving a payment run)
Custody
: handling the actual asset (holding banking access, cutting a cheque, sending a wire)
Recording
: entering the transaction into the accounting system and reconciling it
What it looks like in practice
Here’s a concrete version we use on client files: the accounting team pulls the AP listing and prepares payments, a Treewalk lead reviews it, and the client (or a second internal approver) signs off before anything releases. Nobody who enters an invoice is also the person who releases the funds.
We’ve seen what happens when that structure isn’t in place. On one file, payment handling had been loosely delegated with no second check, and outgoing wires ended up going to the wrong payees and the wrong amounts before anyone noticed. Nobody had done anything malicious. The process just had no gate. That’s the pattern behind almost every segregation-of-duties failure we get called in to fix: not fraud, just a missing checkpoint that let an error travel too far before anyone caught it.
Who runs into this problem
This shows up most often in organizations that are too small to have a finance department but too large to run informally:
- A bookkeeper or office manager who both enters bills and pays them
- A controller who is also the only person with online banking access
- A finance team that’s grown fast enough that the “we all just know each other” trust model no longer matches the transaction volume
It also shows up at organizations with formal structure on paper that erodes under pressure. We’ve worked with clients where a predecessor finance leader had controls in place but leadership pushed to bypass them, which is a segregation-of-duties failure even when the policy manual says otherwise.
How we build it in at Treewalk
Our answer isn’t a longer approval chain. It’s a processing-plus-one-approval model: our team prepares and reviews, the client (or a designated internal approver) is the final gate, and a separate treasury function actually owns payment release. Nobody who touches the entry also touches the wire.
We believe clients shouldn’t have to ask for permission to see their own bank statements at any time. That principle captures the flip side of segregation of duties: control shouldn’t mean opacity. The point isn’t to lock information away from the client. It’s to make sure that whoever can move money isn’t also the only person who can see or record where it went.
On files where we’re the outsourced accounting team, we keep it simple: one accounting lead owns the file relationship, a payment control sits between entry and release, and a treasury function handles the mechanics of moving cash because payment fraud attempts have gotten sophisticated enough that we treat this as its own discipline, not an add-on to bookkeeping.
What this is not
Segregation of duties isn’t the same thing as an audit, and it isn’t bureaucracy for its own sake. An audit tests whether controls existed and worked over a period already passed. Segregation of duties is the control itself, running in real time, before a transaction clears. You don’t need an auditor to have it. You need a process design that doesn’t let one person own the whole chain, and someone paying attention to whether that design still matches how the organization actually operates today.
Frequently asked questions
What is segregation of duties?
It’s the practice of splitting transaction authorization, asset custody, and recordkeeping across different people so no single person can complete a transaction from start to finish unchecked. It reduces the chance that an error or a deliberate act goes unnoticed.
What is an example of segregation of duties?
A common example: one person enters and codes an invoice, a second person reviews and approves the payment, and a third function (or a separate approver) actually releases the funds. No one person controls the whole cycle from entry to cash out the door.
What are the three segregation of duties?
The three core functions to separate are authorization (approving a transaction), custody (handling the asset, such as cash or banking access), and recording (entering and reconciling it in the books). Keeping these with different people is the core of the control.
Do we need this if we’re a small organization with only a few finance staff?
Yes, in a scaled-down form. Even with two or three people, you can rotate who approves versus who processes, or add the business owner as a final sign-off on payment runs. The principle scales down; it doesn’t disappear.
Is this the same as internal controls generally?
Segregation of duties is one internal control among several, but it’s usually the first one worth fixing because it’s the most common gap we find, and it’s the one most directly tied to preventing undetected errors or misuse of funds.
Where to next
If your finance function has grown past the point where one person can safely own the whole payment cycle, that’s usually a sign it’s time to bring in outsourced controllership rather than patch the gap internally. Our private company advisory team is the right starting point for that conversation. Reach out to our team to talk through what that looks like for your organization.