Access & Segregation of Duties

Who can do what in your finance systems, and whether one person did two things that should take two.

An audit means the audit firm asks for the documents behind every balance, on a date. Access & Segregation of Duties gets you ready. Who can do what in your finance systems, checked against your rules every quarter, with every time one person did two jobs that should take two.

What it checks

  • Segregation conflict. No one both created and approved the same bill, payment, journal entry or supplier record.
  • Conflicting roles. No one holds two roles your rules say one person should not hold, unless you have approved an exception.
  • Approval limit respected. No approval was given above the approver's limit, and no limit was raised without a second person.
  • Privileged access reviewed. Every admin account is on your approved list and was reviewed in the last quarter.
  • Change to a financial setting approved. A change to a tax rate, approval rule, bank account or list of accounts in a connected system has a recorded approver.
  • Dormant account. A user with no activity for 90 days who still has access is flagged.
  • Leaver's access removed. A user whose employment has ended and who still has access after their leaving date is flagged.

A finding, in its own words

User U-004 created supplier 'Ridgeway Services' on 2 May, entered bill 5490 for $7,200.00 against it on 3 May, and approved the payment on 4 May. Your rules say creating a supplier and approving its payment take two people. No exception is recorded.

User U-011 has admin access to QuickBooks and no activity since 14 February. Confirm the account is still needed or remove it.

What it may ask you

  • Which two jobs should never be done by the same person? Leave blank for the standard six pairs. Unless you say otherwise: create supplier and approve payment, enter bill and approve bill, prepare journal and approve journal, change bank details and pay, create user and assign role, run payroll and approve payroll.
  • Anyone allowed to do both jobs on purpose? For example the owner in a two-person company. Unless you say otherwise: the Owner.
  • Who is allowed to be an admin in your finance systems?
  • After how many days without logging in should an account be flagged? Unless you say otherwise: 90.
  • How often do you review who has access? Unless you say otherwise: quarterly.

What it draws on

  • Conflicting duties are not held or exercised by one person. COSO Control Activities, principle 10; SOX: Segregation of duties in financial systems.
  • Segregation of duties. COSO Control Activities, principle 10; SOX: Control activities over initiation, authorisation, recording and reporting.
  • Changes to financial settings and limits are approved. COSO Control Activities, principle 11; SOX: Change management over financial systems.
  • Authorisation of transactions and changes. COSO Control Activities, principle 10; SOX: Authorisation of transactions.
  • Access is granted on purpose, reviewed on schedule, and removed when people leave. COSO Control Activities, principle 11; SOX: Logical access controls (IT general controls).

What it needs

  • the user lists and roles from your finance systems
  • their audit logs, the record of who did what and when
  • your employee list with leaving dates, so a leaver's access can be checked
  • your segregation rules and approved exceptions, or the six pairs of jobs we start from if you have none
  • Connections, optional: QuickBooks or Xero, which bring the user list and the log of who did what. A user list and a log export are enough to start.