ComplyBar logoComplyBar
Internal Controls

Segregation of Duties on a 3-Person Accounting Team

The textbook version of segregation of duties (SoD) assumes you have people to spare. One person prepares the journal entry, a second reviews it, a third approves it, and a fourth handles the cash. On a three-person accounting team—say a controller, a senior accountant, and an AP/AR clerk—that model collapses immediately. You physically cannot put four sets of hands on every transaction.

Auditors know this. What they're actually testing is whether one person can initiate and conceal an error or fraud without anyone noticing. If you can break that chain, you satisfy the control objective even without a headcount you'll never get approved.

The two conflicts that actually matter

Forget the 40-line SoD matrix your ERP vendor sold you. On a small team, two conflicts create almost all the audit risk:

  • Custody + recording. The person who can move money (cut checks, initiate wires, access the bank portal) should not also be the one recording those transactions in the ledger unchecked.
  • Recording + reconciliation. The person who posts entries to an account should not be the sole person reconciling that account. Otherwise a plugged reconciliation hides a bad entry forever.

Solve those two and you've addressed the bulk of what a financial statement auditor cares about. Everything else is refinement.

A concrete example

Say your AP clerk enters vendor bills, has login access to the bank, and reconciles the operating cash account. That's all three incompatible duties in one seat. A fictitious vendor for $4,800 a month—just under most approval thresholds—could run for a year before anyone catches it. That's $57,600, and it's exactly the pattern occupational fraud studies keep finding at small organizations, where median losses run well into six figures precisely because oversight is thin.

Compensating controls that work with three people

You compensate by inserting independent review at the points where custody, recording, and reconciliation would otherwise overlap. Here's the practical layout.

1. Move approval up, keep preparation down

Let the clerk and senior accountant prepare; reserve approval for the controller. Set dollar thresholds so routine work flows but anything unusual stops. A workable set for a small company:

  • Any single disbursement over $2,500 requires controller approval before release.
  • Any new vendor or change to vendor banking details requires the controller to approve and confirm via a phone call to a known contact—not a reply to the email that requested the change.
  • Any journal entry over $10,000 or any manual entry to cash, revenue, or an accrual gets reviewed before the books close.

2. Separate the bank portal from the ledger

Even on three people, you can usually arrange dual authorization at the bank. The clerk initiates a wire; the controller releases it. That single split removes the custody-plus-recording conflict for your highest-risk transactions and costs nothing but a call to your bank's treasury desk.

3. Never let the preparer of an account be its only reconciler

If the senior accountant posts payroll entries, the controller reconciles the payroll clearing account—or at minimum reviews the completed reconciliation and signs off. The review has to be real: tie the reconciling items to support, not just glance at the ending balance.

Why the review has to leave a trail

Here's where most small teams lose the argument with their auditor. The controls above may genuinely happen, but if the only evidence is "I looked at it," you can't prove it. Auditors test operating effectiveness, which means they want to see who reviewed what and when, across a sample of periods.

This is the specific place Excel-based closes fall apart. Consider what actually happens with a shared close checklist in a spreadsheet:

  • Anyone with access can mark a task "reviewed" and backdate it. There's no enforcement that the reviewer wasn't the preparer.
  • The "Prepared by" and "Reviewed by" columns are just text. Nothing stops the same person typing both names.
  • File history is unreliable—someone saves over the workbook, and last month's evidence of who signed off is gone.
  • When the auditor asks for proof that the bank rec was reviewed before close in March, you're reconstructing it from email and memory.

A structured close platform enforces the separation you designed on paper. When a task is assigned to a preparer, the sign-off routes to a different user—the system won't let the same person do both. Each approval carries a locked timestamp and user identity, so the audit log answers "who reviewed this and when" without you assembling anything. For a three-person team, that enforcement is what turns an informal habit into a control an auditor will accept.

What the audit log should capture

At minimum, for every close task and every approval gate:

  • Preparer identity and completion timestamp
  • Reviewer identity (system-enforced to differ from preparer) and review timestamp
  • The supporting document attached at the moment of review
  • Any comments or rejections, so a bounced-back reconciliation shows the back-and-forth

When you can hand an auditor a report showing that across twelve months no reconciliation was ever reviewed by its own preparer, the SoD conversation is essentially over. That's a claim a spreadsheet can never substantiate.

Document the design—not just the execution

Write a one-page SoD memo. List each incompatible duty pair, name who does what, and describe the compensating control that covers the gap. Then note that the controller's own work—since the controller is often preparing too—gets reviewed by the CFO, owner, or an outside CPA on a quarterly basis. That last piece closes the loop most small teams forget: the person doing the reviewing needs someone reviewing them.

The takeaway

You don't need a fourth accountant to pass an SoD review. You need to break the custody-recording-reconciliation chain at its two most dangerous points, enforce independent review where duties overlap, and capture tamper-resistant evidence that the review happened. The design is straightforward. The evidence is where small teams win or lose—and it's the reason a system that enforces separation and logs it automatically earns its keep faster than any spreadsheet ever will.

Ready to streamline your month-end close?

ComplyBar helps accounting teams close faster with less stress.

Start Free Trial