Finance Index
How do I achieve segregation of duties with a small finance team?
Reference guide to SoD small finance teams, including control design, audit evidence, risk points, finance procedures, and compliance review.
You won't achieve textbook SoD with two or three people - and auditors know it. The standard is reasonable control, met through ruthless prioritization (separate cash movement above all), compensating review by the owner or CEO, bank-level dual controls, and system-enforced separations that don't consume headcount.
At a Glance
| Aspect | Short Answer | Why It Matters |
|---|---|---|
| Achieve segregation of duties | You won't achieve textbook SoD with two or three people - and auditors know it. | Keeps evidence clear and reduces control risk. |
| Control point | The portfolio that satisfies most auditors: the owner or CFO reviews and releases every payment run (or every run above a floor), seeing payee, amount, and supporting invoice. | Keeps evidence clear and reduces control risk. |
| Technology substitute for headcount | Substantially, yes. | Helps finance decide what to do next. |
| Audit evidence | Split the highest-risk piece you can (typically: the second person, or the owner, approves what the first enters), add owner-level payment release review, and document both. | Keeps evidence clear and reduces control risk. |
| What should the ceo | Three things, monthly or per-run: the payment run before release (payees, amounts, anything unfamiliar), new vendors and banking-detail changes, and the bank statement against expectations. | Reduces payment errors, timing issues, and reconciliation cleanup. |
What compensating controls work when full SoD is impossible?
The portfolio that satisfies most auditors: the owner or CFO reviews and releases every payment run (or every run above a floor), seeing payee, amount, and supporting invoice - not just a total; dual authorization at the bank for payments above a threshold; someone outside AP - even the CEO - receiving and scanning the unopened bank statement or its digital equivalent monthly; an independent review of vendor master changes (new vendors, banking edits) on a monthly cadence; and mandatory vacation or duty rotation so concealment requires continuous presence. Each is cheap in hours; together they cover entry-to-payment risk without new headcount. Document who performs each, how often, and what they'd do on an exception - that documentation is what converts "the owner keeps an eye on things" into a control an auditor can test.
Can technology substitute for headcount in SoD?
Substantially, yes. A system that enforces role separation gives a three-person team separations that used to require five: the same person physically can't approve an invoice they entered, payment approval is a distinct permission, vendor changes route to someone else, and every action is attributed and logged. Technology also upgrades the detective side - exception reports and anomaly flags replace manual log review. What it can't replace is independent judgment: someone outside the process still has to look at what the system reports.
Our auditors flagged that the same person enters and approves invoices but we're a 2-person finance team - what do we do?
Split the highest-risk piece you can (typically: the second person, or the owner, approves what the first enters), add owner-level payment release review, and document both. Auditors don't expect a 2-person team to look like an enterprise - they expect the conflict to be acknowledged and compensated, not waved off.
What should the ceo or owner personally review in AP at a small company?
Three things, monthly or per-run: the payment run before release (payees, amounts, anything unfamiliar), new vendors and banking-detail changes, and the bank statement against expectations. That's a few hours a month covering the major fraud paths.
Our office manager does AP, payroll, and bank recs - what's the minimum viable control redesign?
Take the bank reconciliation away first - the person moving money must not be the person checking the bank. Then add owner payment release and a vendor-change review. Those three moves break the conceal-your-own-work loop that makes the all-in-one role dangerous.
As we grow from 5 to 50 finance people, when and how should we formalize SoD?
Formalize in stages: at ~5, enforce the cash separations and owner review; at ~10 - 15, adopt a documented SoD matrix and role-based system permissions; by the time audit or investor scrutiny arrives, add periodic access reviews and tested compensating controls. The trigger isn't headcount - it's the first external party who will test you.
How do I document compensating controls so auditors accept them - what level of detail is needed?
Per control: the risk it addresses, who performs it, frequency, what they examine, what triggers escalation, and the evidence it leaves (sign-off, log entry, reviewed report). Auditors accept compensating controls they can test; they reject vibes.
The controller is also the backup AP approver - is that an SoD violation or acceptable?
Generally acceptable if the controller doesn't also enter invoices or maintain vendors, and their backup approvals are visible (logged as such, reviewable). It becomes a problem when "backup" turns into routine and the controller is approving spend they later review in reconciliation - watch the volume.
At what company size do auditors stop accepting "we're too small for SoD" as an answer?
There's no bright line, but tolerance fades fast once a finance team can support basic separation - roughly when you have three or more finance staff, or when transaction volume makes owner review impractical. What auditors never accept at any size: unacknowledged conflicts with no compensating control.
Stampli perspective
Stampli lets small teams run separations as system rules rather than staffing plans: role-based permissions split entry, approval, payment, and admin functions; approval authority limits enforce who can sign at what amount; and invoice approval and payment approval remain distinct gates. The immutable activity record gives the reviewing owner or CFO a complete, attributable history to scan - so the compensating-review controls small companies depend on take minutes instead of evenings.