- Segregation of duties (SoD) is an internal control that separates access to assets, authorization of transactions, and accounting recordkeeping to reduce fraud, errors, and financial reporting risks across business processes.
- Segregation of duties often breaks down due to staff constraints, employee collusion, organizational change, and poor follow-through, with the ACFE’s 2026 Occupational Fraud report finding collusive fraud schemes cause higher median losses.
- Organizations can strengthen segregation of duties by designing controls at the business-process level, evaluating cross-process interactions, and empowering employees to escalate concerns, while lean teams can use outsourcing or compensating controls.
According to the Association of Certified Fraud Examiners’ “Occupational Fraud 2026: A Report to the Nations (ACFE 2026 Report),” occupational fraud cases studied showed more than $3.4 billion in losses, with a median loss of $104,000 per case. The report also found that organizations with internal controls experienced a 37% lower average loss than those without controls.
Segregation of duties (SoD) is one of the most effective ways to reduce the risk of fraud, errors, and financial reporting issues. While often associated with accounting and compliance, its impact extends across multiple business processes. SoD prevents too much control from resting with one person and introduces additional review into important processes to support accountability, oversight, fraud risk reduction, and better decision-making. Yet many organizations struggle to implement SoD effectively — here are internal control insights and actions to put into practice:
What Segregation of Duties Is Designed to Do
SoD is designed to prevent one individual from controlling multiple critical functions within a transaction or business process. A proper framework separates key responsibilities among different roles to increase accountability, detect errors, and prevent unauthorized activity.
Although organizations may categorize responsibilities differently, SoD generally focuses on separating three key functions:
- Access to assets, systems or transaction processing
- Authorization of transactions or activities
- Accounting, recordkeeping, and reconciliation
Risk increases when one employee controls more than one of these functions. For example, an employee who can write checks moves into a role reconciling the bank account. This creates a control gap if one of the functions is not removed because the employee can now write a check and reconcile the account, making it easier to hide errors or improper activity. As roles change, SoD helps catch access rights, system permissions, and job duties to keep check and balances intact.
The Risks of Weak Segregation of Duties
Inadequate segregation of duties can have organizational consequences that extend beyond accounting errors.
Increased risk of fraud
SoD can help reduce fraud by identifying and limiting the opportunities for misconduct through the separation of key responsibilities. Consider a scenario in which one employee can create vendors and approve payments without sufficient oversight; the individual may be able to establish a fictitious vendor and authorize payments without detection.
Errors and financial reporting issues
The possibility of mistakes can multiply under weak controls. Employees who process, approve, and record transactions without independent review may inadvertently produce inaccurate accounting records. These errors can compromise financial reporting accuracy and lead to increased reconciliation challenges, audit findings, and remediation efforts.
Operational disruption
Weak controls can also create operational disruption. If a single employee holds too much institutional knowledge or controls too many steps in a process, the organization may struggle when that person leaves, takes time off, or moves into a different role.
This is especially important for growing businesses. A process that worked when the company was smaller may no longer be appropriate as transaction, reporting, and compliance needs increase.
Why Segregation of Duties Breaks Down
Control failures can arise from gaps in planning, technology, and staffing. Business growth and changes in roles or processes can also contribute to the breakdown of well-designed SoD.
Staff constraints
Finance departments are often asked to do more with less. In lean teams, one employee may handle accounts payable, cash management and financial reporting because additional staffing is not available. This makes it difficult to maintain a clear separation of responsibilities.
The reality is that most organizations cannot afford to separate every duty perfectly — the challenge is in deciding which risks warrant additional controls and which can be managed through oversight and monitoring. If a small organization cannot fully separate duties, a business owner or executive may review bank statements, cleared checks, and exception reports each month to provide the necessary oversight.
Employee collusion
SoD is designed to reduce the risk that one individual can commit and conceal misconduct; however, controls can be circumvented when employees collude. The ACFE’s 2026 report found that collusive schemes were associated with higher median losses than schemes committed by a single person, and losses increased as more perpetrators were involved.
Organizations can reduce the risk by:
- Requiring mandatory vacations and rotating job duties: This can help uncover unusual activity by requiring another person or outside provider to perform the role for a short period of time.
- Developing monitoring controls and exception reporting: Reports can help identify unusual patterns, such as payments to a vendor occurring much faster than the normal approval cycle.
- Maintaining clear policies and procedures: Documented approvals, required signoffs, and evidence trails can increase accountability.
- Building a culture with zero tolerance for fraud: A culture grounded in ethical behavior makes it harder for misconduct to be normalized or concealed.
Organizational change
An employee’s role and business processes typically cross paths with SoD. In many cases, management focuses on maintaining operational continuity but does not fully evaluate how changes affect existing controls. When an employee leaves, another employee could take on additional responsibilities that cover access, authorization, and accounting duties.
“In many cases, segregation of duties does not fail because the original design was flawed. It fails because responsibilities change over time and no one revisits the controls.”
Jeff Aucoin, Assurance Principal
Lack of ownership and poor follow-through
Poor follow-through is one of the most common reasons SoD fails over time. Designing the plan is difficult but maintaining it is often harder. Controls are effective only when the responsible parties understand and perform their assigned duties in accordance with SoD. Managers who approve transactions without review, employees who bypass procedures, or leaders who fail to monitor control performance can unintentionally undermine an otherwise well-designed system.
Build Stronger Segregation of Duties for Stronger Controls
1. Design SoD at the business process level
Organizations can begin by understanding how work gets done. Start by mapping out how work moves through the organization for each major business process, such as accounts payable, accounts receivable, payroll, cash management, and financial reporting, and then identify the roles associated with each stage.
A practical next step is listing activities within each process and identifying who performs each one by role. A grid or matrix can visualize workflows and show where access, authorization, and accounting functions overlap. This exercise often reveals where too much responsibility is in the hands of one person.
2. Evaluate how business processes interact
SoD issues often appear across processes that interact. An employee may approve payment transactions in one process and confirm receipt of goods or services in another. Individually, those duties may appear appropriate, but together, they may create a control weakness.
The biggest problems tend to occur when one person controls too much of a transaction from start to finish. In an accounts payable scenario, one employee should not be able to create a vendor, approve an invoice, issue payment, and reconcile the bank account without independent review.
3. Obtain a fresh perspective during the design phase
It is often easier for someone outside the process to spot control weaknesses. This perspective can come from a leader with a working knowledge of internal processes, an internal audit professional, or an external adviser to challenge assumptions and add practical insights.
4. Regularly review controls as the business changes
SoD development is not a one-time exercise. Controls should be reviewed periodically and especially after changes such as employee turnover, promotions, restructurings, acquisitions, system implementations, or rapid growth.
A common control breakdown occurs when an employee changes roles but retains access from a prior position. Before responsibilities are reassigned, management should evaluate how the change affects access, authorization, and accounting controls.
5. Empower employees to identify and escalate concerns
SoD is most effective when employees understand not only their assigned duties, but also their role in questioning unusual activity. Encouraging employees to speak up can bring additional scrutiny to a transaction that may technically include the right approvals but still appear suspicious.
For example, an accounts payable employee notices that a vendor payment meets each required approval step but also includes a mismatch between vendor details and tax documentation. If employees are empowered to pause the process and ask questions, they can become a preventive control against collusion among employees who try to circumvent SoD controls.
Rethinking Segregation of Duties for Lean Organizations
A widely held misconception is that effective SoD is achievable only in large organizations with extensive staffing resources. While limited headcount can create challenges, smaller organizations and lean teams can often improve controls by:
- Involving personnel outside the accounting function in approval processes.
- Separating the highest-risk duties, even when full segregation is not possible.
- Implementing compensating controls, such as management review.
- Increasing oversight through monitoring reports and exception reviews.
- Using technology to automate approval and validation procedures.
- Engaging an outsourcing provider to support accounting, reconciliation, and reporting functions.
The goal is less about perfection and more about reducing risk in a way that makes sense for the size and complexity of the business.
How Outsourcing Can Help Strengthen Segregation of Duties
For many organizations, especially those with lean accounting teams, outsourcing support can provide the additional capacity needed to strengthen controls without significantly expanding headcount.
Third-party experience can be especially valuable when an organization:
- Has limited finance or accounting staff.
- Is experiencing rapid growth.
- Is preparing for an audit, financing event or transaction.
- Has employees changing roles or retiring.
- Needs stronger documentation and process discipline.
- Wants to improve controls without adding multiple full-time positions.
Outsourcing and interim staffing can also serve as a practical alternative to building a larger internal finance function while freeing up employees to focus on higher-value business activities.
How BDO can help
Segregation of duties is a relatively simple concept to understand, yet one of the hardest to maintain in practice. Regular review and oversight will help organizations adjust processes through change and growth to maintain effective controls and manage risk.
Our Outsourced Finance & Accounting team offers comprehensive accounting experience, up-to-date technology resources, and a global network to handle projects from start to finish.