In a large company, different people create, approve, record and reconcile financial transactions. In a small business, one or two people may do all of it. That makes errors and misuse easier to hide, so access and approvals deserve careful thought. This article covers the principles and how to apply them when you cannot fully separate every task.
The principle: segregation of duties
The idea is simple: no single person should be able to start, approve and conceal a transaction alone. Four kinds of task are worth keeping apart where you can:
- Initiating, such as creating a supplier bill or a payment request.
- Approving, which means authorising it.
- Recording, which means posting it to the books.
- Reviewing or reconciling, which means checking the result against an independent source such as the bank.
Give people the least access they need
Start every role with nothing and add only what the job requires. Someone who enters sales invoices does not need to edit the chart of accounts, and someone who reviews reports does not need to post journals. Fewer permissions mean fewer opportunities for error.
Design roles around functions, not people
Define roles such as "Accounts receivable clerk" or "Approver", and then assign people to them. When someone leaves or changes job, you change their role instead of rebuilding their permissions one by one.
| Role | Typically can | Typically cannot |
|---|---|---|
| Bookkeeper | Enter invoices, bills and receipts; prepare reconciliations | Approve payments; change account structure |
| Approver | Approve bills, payments and expense claims | Enter the transactions they approve |
| Finance manager | Review reports; post adjustments; close periods | Be the only person who approves and releases payments |
| Owner or director | Review everything; approve large or unusual items | Share a login with staff |
Use approval rules for money going out
- Require a second person to approve payments above a threshold you set.
- Require approval for new suppliers and for changes to supplier bank details. These changes are a common route for fraud.
- Route expense claims to someone other than the claimant.
When you cannot separate everything
If two people share all the work, add compensating controls instead of accepting the risk silently:
- An owner or outside accountant reviews bank statements directly, not only the reconciliation prepared by staff.
- Someone independent reviews the list of changes and unusual entries each month.
- Duties rotate periodically, and staff take leave without their work being handled by the same person.
- The audit trail is switched on and actually looked at.
Housekeeping that matters
- One login per person. Shared logins destroy accountability.
- Remove access promptly when someone leaves or changes role.
- Limit administrators. Keep the number of people who can change settings and permissions as low as practical.
- Review access every quarter. Check that each person still needs what they have.
- Use strong sign-in practices, including two-factor sign-in where your system offers it.
