Avenlor
Home / Insights / Internal controls
Internal Controls

Segregation of Duties When the Team Is Small

It is the control an auditor tests first, and the one a small company finds hardest — because there simply are not enough people. The good news: you rarely need more headcount. You need the right duties kept apart, and deliberate compensating controls where they cannot be.

Avenlor ConsultingGovernance & Internal Controls7 min read

In most growing companies, the finance function started with one trusted person who did everything — raised the payment, approved it, entered it in the ledger, and reconciled the bank at month-end. It worked because the person was capable and trusted. But "capable and trusted" is not a control, and it is precisely the arrangement that makes both honest error and quiet fraud possible. When an auditor arrives, or a bank, or an investor, this is the first place they look.

Segregation of duties (SoD) is the principle that no single person should control a transaction from beginning to end. It is simple to state and genuinely hard to apply in a team of two or three. This is how to do it without hiring an army.

The four functions that must not sit together

SoD is easier to reason about when you stop thinking "who does the finance" and start thinking about four distinct functions in every transaction. The risk lives in one person holding more than one of them:

The single most dangerous combination is custody plus recording: the person who can move money can also adjust the books to hide it. If you separate nothing else, separate those two.

Why small teams are the most exposed

In a large company, these four functions naturally fall to different people. In a company of thirty, they collapse into one or two — not through negligence, but through headcount. That concentration is exactly the condition every fraud case study describes after the fact, and auditors know it. A control weakness here does not just risk a finding; it lowers how much the auditor can rely on your numbers at all, which makes the whole audit longer and more expensive.

Trust is not a control. The point of segregation is to protect the honest majority from suspicion, and the business from the rare exception.

What a two- or three-person split can look like

You can achieve meaningful separation with very few people if you use the owner or a manager as one of the pairs of hands. A workable pattern for a small team:

No one there does more than they should, and the owner's involvement is a control rather than a bottleneck, because it is limited to authorization and independent review.

When you genuinely cannot separate: compensating controls

Sometimes the numbers just are not there, and one person really must both record and pay. That is acceptable if you put deliberate compensating controls around it — documented, not assumed:

Let the system and the bank do the work

Modern accounting systems and business banking give small teams separation that used to require extra staff. Use role-based access so people can only do their function; turn on approval workflows so a payment cannot be released without a second person; give the owner a view-only login to the books and the bank. These cost nothing but the discipline to configure them — and an auditor can see they are switched on.

If it is not evidenced, it did not happen

Every control above is worth far more when it leaves a trace. "The owner reviews the bank statement" is a claim; a bank statement with the owner's initials and the date, kept on file, is a control an auditor can test. As you design the split, ask of each control: could I prove, six months from now, that this operated? If not, add the signature, the timestamp, or the system log that makes it provable.

A minimum SoD split for a small finance team

  • The person who records transactions cannot release payments alone
  • Payments need a second, independent authorizer (bank or signature)
  • The owner or a manager holds view-only access to the books and the bank
  • Bank reconciliations are reviewed by someone outside the payment process
  • Payments above a threshold require dual approval
  • System roles restrict each person to their own function
  • Every review is dated and initialled, and the evidence is retained

Segregation of duties is not a luxury that arrives once you are big enough. It is a small number of deliberate choices about who can do what — choices that protect your people, your money, and the credibility of your numbers long before an auditor ever asks.

Not enough people to separate duties?

We design segregation-of-duties and compensating-control frameworks sized to your actual team — practical, evidenced, and ready for audit.

Discuss your mandate →

Read next

Internal Controls Before an External Audit → Building an Internal Control Framework with COSO →

This article is general guidance on internal-controls practice and does not constitute legal, audit, or regulatory advice. Obtain professional advice for your specific circumstances.