Access & controls

Segregation of Duties on a Small Finance Team

6 min read·March 3, 2026· Ressura

The control every small company struggles with

Segregation of duties (SoD) is a core internal control. No single person should control a transaction end to end. The classic conflicts are letting one person both create a vendor and pay it, or both record cash and reconcile the bank. Put those duties together and you create room for fraud and hidden error.

It is also the control small companies find hardest. SoD assumes you have enough people to divide the work. When finance is one or two people, textbook separation is not always possible.

Start with the incompatible pairs

You don’t need to separate everything — you need to separate the combinations that matter. The high-risk pairs to break up first:

  • Create/approve a vendor and pay a vendor.
  • Record cash receipts and reconcile the bank.
  • Approve payroll changes and run payroll.
  • Post journal entries and approve them.
  • Custody of an asset and the records for that asset.

If you can’t split every one of these across people, split the ones with a direct path to cash first.

When you can’t separate, compensate

The COSO framework is the internal-control model behind many audits. It allows compensating controls when a primary control is not feasible. For a small team, those controls are how you get real assurance without more headcount:

  • Owner or manager review of bank reconciliations, new vendors, and payments over a threshold — with a record that the review happened.
  • System-enforced approvals so a payment can’t be released without a second set of eyes.
  • After-the-fact monitoring that flags conflicts and exceptions someone then reviews.
  • A clear audit trail so every action is attributable to a person.

Auditors accept compensating controls. What they cannot accept is a gap with nothing covering it.

Make the invisible visible

The hardest part of SoD at small scale is simply seeing the conflicts. Access grows in small steps. Someone gets admin rights to fix an urgent problem and keeps them for two years. Review who can do what, and where incompatible permissions overlap. That is the control behind the control. It is also one of the first things an IT general controls review examines.

The practical takeaway

Small teams can have strong control environments. They do it by targeting the incompatible pairs first. Then they add review and system approvals where separation is not possible. They also keep a clean audit trail that shows who did what. Done right, this satisfies auditors and closes the gaps fraudsters look for.

Ressura flags segregation-of-duties conflicts and risky access automatically, and monitors the compensating controls that keep a small team audit-ready.