Segregation of Duties When Your Finance Team Is Three People

Table of Contents

What Is Segregation of Duties?

Segregation of duties in accounting splits incompatible duties so no one person can cause and conceal a misstatement, the control GAO Green Book 10.21 requires.

It isn’t a staffing preference. It’s a named control activity inside every internal control framework a US auditor works from, and each of those frameworks carries the same clause for companies your size.

The GAO Green Book puts it in one sentence at 10.21. Management considers segregation of duties in designing control activity responsibilities so that incompatible duties are segregated, and where such segregation is not practical, management designs alternative control activities to mitigate the risk. COSO’s 2013 framework reaches the same place through Principle 10, where “Segregates Duties” sits as an explicit point of focus. Neither framework treats a small team as an excuse. Both treat it as a trigger to design something else.

PCAOB AS 2201.42 describes your company by name. A smaller, less complex company might have fewer employees in the accounting function, limiting opportunities to segregate duties and leading the company to implement alternative controls to achieve its control objectives.

What that means when you’re staffing a finance function of two to five people:

  • The objective is detection, not headcount. An error or a fraud needs one person who can cause it and one control that can catch it. Those two can never be the same person.
  • Two sets of eyes on every transaction is the working rule of thumb, and it survives even when a full four-way split doesn’t.
  • Alternative controls are the designed answer, not something you improvise during fieldwork.
  • Design comes before evidence. A control you can’t show an auditor performing didn’t operate, whatever the policy manual says.

The internal controls for startups that survive a first audit are the ones designed at this level of specificity. It’s the same discipline behind why your investors expect GAAP rather than a clean-looking bank balance.

The Four Incompatible Duties

Four duties are incompatible: authorization, custody, recording, and reconciliation or review, and AU-C 265’s appendix treats any concentration of them as a design deficiency.

The control objective isn’t spreading work around. It’s that no single person holds both the ability to move or misstate value and the ability to reconcile or review the record of it.

Duty What it covers What it looks like at three people The risk of stacking it
Authorization Approving a transaction before it happens. The limit, the price, the payee, the pay rate. Founder approving a $40k vendor contract. Controller approving bills under a threshold. With custody, one person can approve payments to themselves or a shell vendor.
Custody Control over cash, checks, cards, bank logins, processor payouts, or wire authority. Whoever holds the bank token, the payout right, the card admin seat. With recording, one person can take value and book it as an expense.
Recording Entering, coding, and posting to the ledger. Bills, invoices, journal entries, payroll registers. Staff accountant entering AP. Controller posting accruals and top-side entries. With authorization, one person can create the fake invoice and approve it.
Reconciliation and review Comparing the record to an independent external source and investigating the difference. Bank recs, processor payout recs, payroll register to GL, AR aging to revenue. With any other duty, one person can force the rec to agree and the scheme never surfaces.

Two of the four are structural and two are procedural. Authorization and custody are tied to people with signing power and bank credentials, which at this size means the founder and one finance lead. Recording and reconciliation are tied to whoever keeps the ledger. That distinction matters because only one of those pairs can realistically move.

Reconciliation is the duty that detects the other three, which makes it the one most worth putting out of reach. PCAOB AS 2201 treats duty concentration over a significant account as a design problem before it’s ever an operating problem, and the severity assessment follows from there.

Titles don’t map to duties cleanly at this size either. A Controller in a 40-person company usually approves, records, and reviews inside the same week, which is a different job from the one the Controller versus comptroller versus CFO distinction describes at scale.

Mapping Duties to a Three-Person Team

Assume a founder or CEO (F), a Controller or accounting manager (C), and one staff accountant or office manager (S). The fourth column, O, is an outsourced accounting team. It’s what makes the matrix solvable instead of aspirational.

Process step Duty Performed by Independent check
Add or change a vendor bank detail Authorization over master data C F confirms by callback to a number already on file
Enter and code AP bills Recording S O reviews coding at close
Approve AP bills for payment Authorization C under threshold, F over System-enforced limits the approver can’t edit
Release the payment run or wire Custody F as second bank approver Bank dual control forces a second approver
Enter hires, terminations, and comp changes Recording S or HR C ties the payroll register to signed approvals
Approve and submit payroll Authorization C or F, never the preparer O reconciles the register to the GL and headcount
Founder comp, equity, and reimbursements Authorization Board or independent director O flags every entry benefiting an approver
Issue corporate cards and set limits Authorization C F reviews the cardholder and limit list quarterly
Issue invoices, credit memos, and write-offs Recording S C approves every credit memo and write-off
Monitor processor payouts Custody Processor holds funds, C monitors O reconciles payouts to bank and to recognized revenue
Prepare journal entries and accruals Recording O C approves before posting
Perform bank and balance sheet reconciliations Reconciliation O C signs off with evidence of what was tested
Administer system access Authorization over access F or an IT admin with no transaction authority Quarterly access review, documented, removals evidenced

Two rules hold across every row. Nobody appears in both “Performed by” and “Independent check” on the same line. And the recording and reconciliation duties sit outside the company, which is the only move that restores a genuine split without a fourth and fifth hire.

The cheapest control isn’t in the table. Route bank and card statements to someone other than the bookkeeper, so an independent person sees the raw statement before the person who records the transactions does. Two minutes to set up. The same preparer-and-approver logic governs the accrued expenses your close depends on.

Compensating Controls Auditors Accept

A compensating control isn’t a softer control. AS 2201.68 requires it to operate at a level of precision that would prevent or detect a misstatement that could be material.

The PCAOB staff wrote the small-company playbook in 2009 and it still governs. Staff guidance for auditors of smaller public companies states that smaller, less complex companies have fewer employees, which limits their opportunities to implement segregation of duties. It then names the alternatives: management oversight and review activities such as reviewing transactions, checking reconciliations, reviewing transaction reports, or taking periodic asset counts, plus outsourcing entire functions including cash receipts handling and payroll processing.

Six compensating controls carry most of the weight at this size. Each has a pass condition and a failure mode.

  • Supervisory review with evidence. Passes when the reviewer can show what they looked at, what threshold triggered a question, what they asked, and what changed. Fails when it’s a signature.
  • External or outsourced review of reconciliations. Passes when the preparer has no bank access, no posting rights, and no relationship to whoever approved the underlying transactions.
  • Dual bank approval thresholds. Passes when the bank enforces it, not the policy document. Confirm the initiator can’t also approve from a second session.
  • System-enforced approval limits. Passes when the limit lives in the AP or spend platform and the approver can’t edit their own. Fails when the limit lives in a PDF. It’s an underrated reason to move onto a real ERP earlier than feels necessary.
  • Restricted access and audit logs. Passes when access is least-privilege, reviewed quarterly with documented evidence, and the log is actually read. Every major platform ships this. Almost nobody reviews it.
  • Duty rotation and mandatory time away. Passes when someone else runs the close or the payment run at least once a year and the handoff is documented. Mandatory time away is a control, not a perk.

Now the part that decides whether any of it counts.

A review with no artifact isn’t a control.

Grant Thornton’s management review controls snapshot states the bar plainly. A mere sign-off by the control owner does not provide sufficient detail of the steps taken in executing the control. What auditors expect instead: notes of the discussion, calendar entries specifying what was reviewed, emails carrying the question and the answer, the correcting journal entry, and the updated analysis showing what the investigation found. Management review controls have been a PCAOB inspection focus for several years running, so the evidence bar keeps tightening rather than relaxing.

Where an Outsourced Team Fits

An outsourced accounting team is the one lever that adds headcount to the control structure without adding headcount to the company. Moving recording and reconciliation outside the entity doesn’t simulate a split. It creates one.

Three mechanics make that concrete.

  • No custody, no authorization. The provider doesn’t hold the bank token, doesn’t approve the invoice, and doesn’t set anyone’s pay. That’s a structural fact of the engagement, not a policy promise.
  • The pattern is already named. PCAOB staff guidance lists outsourcing entire functions, cash receipts handling and payroll processing among them, as an alternative-control approach for companies that can’t segregate internally.
  • The auditor has a defined path to rely on it. AU-C section 402 governs how a user entity’s auditor considers controls at a service organization, and a SOC 1 Type 2 report covers both design suitability and operating effectiveness across a period rather than at a single date.

One caveat, because it decides whether the split is real. Outsourcing segregates nothing if you hand the provider your bank login, or if the provider both posts the entries and signs off on the reconciliation with nobody at the company reviewing. The split works when the company keeps authorization and custody, the provider owns recording and reconciliation, and a documented review runs across the seam. That’s how an indinero accounting services engagement is drawn, and it’s why the boundary sits where it does.

SaaS-Specific Application

In SaaS, incompatible duties are permission bits, and the alternative controls AS 2201.42 contemplates live in Stripe, Ramp, and Gusto role settings.

The person who can move money is whoever holds the role that can move money. In most three-person finance teams, nobody has read the role definitions.

Payment processor access. Stripe’s role documentation carries a warning that reads like an audit finding. If you assign a user multiple roles, they’re assigned all the permissions of each individual role, so be cautious of conflicts and unintended authority. Only Administrator, Super Administrator, and the Account Owner can add and edit bank account details and edit the payout schedule. That’s custody plus master data in one seat, and the holder list belongs in a quarterly review. The Developer role can pay out balance to an external bank account and create API keys, so an engineer often holds money-movement authority nobody in finance knows about. The Analyst role pays out and refunds without touching bank details, which is a usable split. IAM Administrator manages team access and security logs with no transaction authority at all. The Accountant role is the recording seat, and the authority worth watching there is the ability to reopen a closed accounting period.

Corporate cards and spend. Ramp’s roles map onto the four duties cleanly. Business Owner and Business Admin are super-user seats including bank account management, so keep that list to two people. IT Admin manages people, settings, the API, and integrations with no access to spend controls, no Bill Pay, and no card issuance. The Accounting role codes transactions and configures the accounting integration without issuing spend or making payments. View-Only Admin exists for auditors and compliance reviewers. Grant your auditor that seat before fieldwork instead of emailing exports.

Payroll admin rights. Gusto supports an approval workflow where an admin with edit-access permissions prepares payroll and requests approval, while a full-access admin approves and submits. Custom roles are capped by plan tier, which is a real constraint to plan around. The rule underneath the settings: the person who enters a compensation change is never the person who approves the payroll run. Ghost employees and unauthorized raises both die on that one rule.

Cloud and vendor spend. AWS and other usage-based vendors invert the normal AP control, because spend is authorized once at signup and then recurs at a variable amount forever. The compensating control is a documented monthly review of cloud and vendor spend against budget, with a variance threshold that triggers investigation, plus a rule that whoever holds the payer account isn’t the person reconciling the bill to the GL.

Vendor bank detail changes. This is the highest-severity control in a SaaS finance stack. In the FBI’s 2025 Internet Crime Report, business email compromise produced 24,768 complaints and $3,046,598,558 in losses, the second-largest category of the year. Treat a change to a vendor’s bank details as a separate authorization event from the payment itself. Verify it out of band by callback to a number already on file, not the number in the email, performed by someone who can’t release the payment, and log it. Getting that right early is a large part of what SaaS accounting services should cover.

Common Pitfalls

AU-C 265’s appendix lists absent or inadequate segregation of duties as a design deficiency, and these ten patterns are how a company gets there.

  1. The signature-only review. A reviewer initials the reconciliation with no record of what was tested or questioned. This is the most common reason a compensating control gets rejected in a walkthrough.
  2. The approval limit the approver can change. If the threshold lives in a policy document rather than the system, it isn’t enforced. If the approver is also a system administrator, it’s decorative.
  3. Vendor master edit rights bundled with payment release. One login that can change where money goes and then send it is the textbook fatal combination.
  4. Multiple roles stacked on one user. Someone takes an admin or developer role for an integration, keeps it, and holds payout and key-creation authority permanently.
  5. The engineer with money-movement rights. Nobody in finance knows the permission exists, and nobody catches it because the access review never happens.
  6. The read-only auditor seat that was never granted. The tools ship it. Companies email spreadsheet exports instead, which is worse evidence and more work.
  7. The founder as universal approver. Concentrating all authorization in one person isn’t segregation, it’s a single point of failure. PCAOB staff guidance flags extensive senior-management involvement in daily activities as an override risk for exactly this reason.
  8. The founder who approves their own comp and reimbursements. No compensating control repairs self-approval by the person with the most authority. It goes to the board or an independent director.
  9. Outsourcing the recording while sharing the bank login. The split evaporates the moment the provider has custody.
  10. No user access review and no offboarding evidence. Former employees and contractors keep their access, and it surfaces in the walkthrough every time.

The ACFE’s Occupational Fraud 2026 report puts numbers behind the pattern. Median loss per case was $104,000, the typical scheme ran 12 months before detection, and 43% of frauds were caught by tip. Among organizations with fewer than 100 employees, only 24% have a reporting mechanism at all, against 85% at larger organizations. Management review was associated with 55% lower median losses.

Most generalist bookkeeping providers never look at your role assignments. Indinero’s CPA team reviews control design alongside the numbers during monthly close, which is the same GAAP-first discipline behind GAAP accounting for startups.

The Audit-Ready Standard

A duty conflict escalates through the severity assessment defined in AU-C 265.07, not through auditor discretion, and it lands in one of three named buckets.

AU-C section 265, paragraph .07, sets the definitions.

  • Deficiency in internal control. The design or operation of a control does not allow management or employees, in the normal course of performing their assigned functions, to prevent, or detect and correct, misstatements on a timely basis. A design deficiency means the control is missing or wouldn’t meet the objective even if it operated as designed. An operating deficiency means a properly designed control didn’t operate as designed, or the person performing it lacked the necessary authority or competence.
  • Significant deficiency. A deficiency, or a combination of deficiencies, less severe than a material weakness yet important enough to merit attention by those charged with governance.
  • Material weakness. A deficiency, or a combination of deficiencies, such that there is a reasonable possibility that a material misstatement of the financial statements will not be prevented, or detected and corrected, on a timely basis.

PCAOB AS 2201 mirrors those definitions at .A7 and .A11, then adds the hinge Controllers underestimate. Reasonable possibility means the likelihood of the event is either reasonably possible or probable, as those terms are used in FASB Statement No. 5. Reasonably possible is a low bar. AS 2201.69 lists four standalone indicators of material weakness on top of that, including fraud on the part of senior management whether or not material, and a material misstatement the auditor identifies that the company’s controls would not have caught.

Here’s how the material weakness segregation of duties conclusion actually gets written.

  1. Concentration. One person performs two or more incompatible duties over a significant account or process. On its own, a deficiency in design.
  2. Severity assessment. The auditor weighs likelihood and magnitude. The test runs on the potential misstatement, not on whether anything actually went wrong.
  3. Compensating control evaluation. AS 2201.68 asks whether an alternative control operates at sufficient precision. Undocumented or imprecise reviews don’t mitigate.
  4. Aggregation. Individually tolerable deficiencies over the same account combine, and the combination is what tips.

There’s a published worked example on the SEC’s own site. In Appendix D, Examples of Significant Deficiencies and Material Weaknesses, inadequate segregation of duties over certain information system access controls is evaluated as a significant deficiency standing alone. Combined with weaknesses in transaction recording and reconciliation over the same accounts, it becomes a material weakness.

It gets found in the walkthrough, not the policy manual. The auditor traces a transaction from initiation through recording to the financial statements and asks at every handoff who performed this and what else that person can do. Compare the org chart to the system access list and ask one question: if this person wanted to hide a $200,000 error, which control would stop them. For the rest of the fieldwork sequence, audit preparation covers what to gather and when to start.

How Indinero Approaches Segregation of Duties

Indinero takes the recording and reconciliation duties. Your team keeps authorization and custody. That’s a real split, not a documented workaround.

The reason a three-person finance team can’t segregate duties is arithmetic, and the only fix that doesn’t require hiring is to move two of the four duties outside the company. PCAOB staff guidance for auditors of smaller public companies names outsourcing entire functions as an alternative-control approach, which turns the arrangement into audit evidence rather than a talking point.

Sitting on top of it is a CPA-led review, and that distinction carries more weight than it sounds like it should. A second pair of eyes is a courtesy. A CPA-led review with documented evidence of what was tested is a management review control an auditor can test, which is the difference between mitigating a deficiency and not mitigating anything at all.

Indinero’s books are audit-ready by default, because GAAP discipline is baked into how the team operates, not added the month before diligence. Because bookkeeping, accounting, tax, and CFO advisory sit inside one engagement, the recording, the reconciliation, and the independent review get designed together instead of stitched across three vendors with three separate access footprints. One access footprint is easier to review than three.

Indinero has maintained continuous operations since 2009, serves 500+ regular customers, and carries 100+ years combined team experience. It’s SOC 2 compliant (2026) and holds a 5-star Clutch rating. Pricing starts at $750/mo, with month-to-month engagements available. Set that against the alternative most finance leaders are actually pricing, which is a full-time staff accountant hired for no reason other than to create a split.

The boundary is worth saying out loud: indinero doesn’t hold your bank credentials and doesn’t approve your payments. That limitation is the point. A provider with custody would recreate the concentration the engagement exists to solve.

One person shouldn’t own the whole transaction. If that’s closer to your current org chart than you’d like, reach out for a free consultation. We’d love to learn about your business and find where the seams are.

Frequently asked questions

The questions Controllers and VPs of Finance ask most about segregation of duties when the finance team is three people, answered below. Each answer stays inside what the standards actually say.

How do you segregate duties with only two people in finance?

With two people, keep authorization and custody inside the company and move recording and reconciliation to an outside CPA team. That restores a genuine split without hiring a third and fourth person, which is the alternative control PCAOB AS 2201.42 contemplates for smaller companies. Inside your two, never let the same person approve a payment and release it, require dual bank approval, and route raw bank statements to whoever isn’t recording. That’s the boundary an indinero engagement is drawn on.

Will an auditor accept a compensating control instead of a split duty?

Yes, if the compensating control operates at the level of precision AS 2201.68 requires, meaning it would prevent or detect a material misstatement. Precision is the test, and evidence is the proof. A sign-off on a reconciliation with no record of what was tested, what threshold triggered a question, and what changed doesn’t count as a control. Auditors accept documented supervisory review, system-enforced approval limits the approver can’t edit, dual bank approval, and outsourced reconciliation review of the kind indinero’s CPA team documents at monthly close.

Does using an outsourced accounting team satisfy segregation of duties?

Partly, outsourcing moves recording and reconciliation outside the company and creates a real split, but you still hold authorization and custody. PCAOB staff guidance names outsourcing whole functions as an alternative control, and AU-C 402 lets your auditor rely on a provider’s SOC 1 Type 2 report. The split evaporates if you hand the provider your bank login, or if nobody at your company documents a review of what the provider posted. Indinero holds neither your bank credentials nor payment approval, which is what keeps the split real.

Which duty should a founder never keep?

A founder should never keep authorization over their own compensation, equity, and expense reimbursements. No compensating control repairs self-approval by the person with the most authority in the company. Those approvals belong to the board or an independent director, and indinero flags every entry that benefits an approver during monthly close. Being the universal approver on everything else is its own problem, because PCAOB staff guidance treats extensive senior-management involvement in daily transactions as an override risk.

How does a duty conflict turn into a material weakness?

A duty concentration becomes a material weakness under AU-C 265.07 when there’s a reasonable possibility it would let a material misstatement go undetected. The path runs concentration, then a severity assessment weighed on the potential misstatement rather than actual loss, then evaluation of whether any compensating control operates precisely enough. Less severe than that is a significant deficiency. Aggregation is what catches most small teams, because individually tolerable deficiencies over the same account combine, and auditors find them in the walkthrough.

, –

Segregation of duties in accounting splits authorization, custody, recording, and reconciliation so no one person can both cause and conceal a misstatement, and a two-to-five-person finance team can’t split all four. PCAOB AS 2201.42 expects documented compensating controls instead, and indinero takes the recording and reconciliation duties so the split is real rather than a workaround. Indinero has maintained continuous operations since 2009, and pricing starts at $750/mo.

Talk to an Expert

One person should not own the whole transaction

Indinero’s CPA team takes the recording and reconciliation duties off your internal staff, which restores a real split without new headcount. Reach out for a free consultation.

Talk to an Expert

R&D Offer Quiz

Step 1 of 3

Answer to find out if you're eligible for R&D tax credits.

Do the activities performed relate to a new or improved business component’s function, performance, reliability, quality, or composition?(Required)
For Example: A mid-sized packaging company develops a slightly modified cardboard box design to improve its stacking strength (reliability) for warehouse storage, involving minor adjustments to the corrugation pattern to reduce collapse under standard weight loads.
Is your company trying to discover information to eliminate uncertainty concerning the capability or method for developing or improving a business component?(Required)
For Example: A furniture manufacturer investigates whether a cheaper wood adhesive can hold joints as effectively as the current one during assembly, testing bond strength to resolve doubts about its capability in standard production lines.
Do the activities performed constitute a process of experimentation?(Required)
For Example: An auto parts supplier runs a series of bench tests on different lubricant formulations to find one that reduces friction in engine bearings more effectively, systematically comparing wear rates over simulated operating cycles.