Glossary

Controls

What is segregation of duties?

Segregation of duties is the control principle that no single person can both create and approve a payment or a change to payment data, so that one compromised or coerced individual cannot complete a fraudulent transaction alone.

Also called separation of duties · SoD · dual control · maker checker

In payments this usually means splitting four capabilities: creating a vendor, changing bank details, entering a payment, and releasing it. Small finance teams often collapse these into one or two people, which is the condition most commonly cited in post loss reviews.

Dual control only works if the second approver is looking at something meaningful. Approving a payment batch without visibility into what changed since the last run is a signature, not a control.

Common questions

How can a small finance team apply segregation of duties?

Split the highest risk pair first, changing bank details and releasing payments, and use the bank's own approval tiers to enforce a second approver even when only two people are available.

Is dual approval the same as segregation of duties?

Dual approval is one implementation of it. Segregation of duties also covers who can create records and who can execute, not only who signs off.

Primary sources

Citing this entry? Cite as Coffr, LLC and link to https://getcoffr.com/glossary/segregation-of-duties.

Read the longer research behind this in Insights, or browse the full glossary.