Providence, RI · Independent public-finance research & analytics
Fraud Prevention & Detection · Practice guide

Segregation of Duties in Small Finance Departments

In a department of three, ideal segregation is arithmetically impossible. Compensating controls are not a lesser substitute — but they only work if they are specified precisely.

The standard control framework assumes enough people to separate authorisation, custody, recording and reconciliation. A great many public entities — small municipalities, special districts, school districts, fire districts, authorities — have two or three people in the finance function. Auditors write the finding every year, management responds that the entity is small, and nothing changes. This is a solvable problem, but not by pretending the segregation exists.

Start with the incompatible pairs that matter

Not all combinations carry equal risk. Four pairings account for most realised losses in small entities:

  • Creating a vendor and approving a payment to it. The single highest-risk combination, because it requires no collusion and leaves no unusual document.
  • Receiving cash and recording the receipt. Enables lapping and unrecorded collections.
  • Processing payroll changes and approving the payroll register. Enables ghost employees and unauthorised rate changes.
  • Performing the bank reconciliation and having disbursement authority. Allows a discrepancy to be concealed indefinitely.

An entity that cannot segregate everything can usually segregate these four by moving one task, often outside the finance department entirely.

Compensating controls that actually compensate

The phrase is often used loosely to mean "someone senior looks at it". That is not a control unless the look is specified. A compensating control needs a defined performer, a defined procedure, a defined frequency, and evidence.

Reconciliation review by a non-finance official

A board member, clerk, or manager receives the bank statement directly from the bank — unopened, or by separate electronic access — and compares the ending balance and cleared cheque sequence to the reconciliation prepared by finance. This is perhaps twenty minutes a month and closes the most dangerous gap in small-entity control structures. The essential element is that the statement does not pass through the person being monitored.

Positive pay and ACH filters

Bank-side controls do not require additional staff. Positive pay validates cheques against an issued file; ACH debit filters block unauthorised direct debits. Both are typically inexpensive and both convert a detective control into a preventive one.

Vendor master file review

A quarterly report of vendors added or amended, reviewed by someone outside accounts payable, with confirmation of supporting documentation for each. Short list, high value.

Surprise verification

Unannounced cash counts and a periodic independent confirmation of a sample of bank and investment balances. Announced procedures on a published schedule provide much weaker assurance.

Mandatory leave

A requirement that anyone with disbursement authority takes at least five consecutive business days annually, during which their duties are performed by someone else. Many long-running small-entity frauds are discovered during an unplanned absence. Making the absence planned is nearly costless.

Document the design, not just the deficiency

Where segregation is not achievable, the entity should maintain a written control matrix: the incompatible duty, why segregation is not feasible, the compensating control, who performs it, how often, and what evidence it produces. This converts a recurring audit finding into a documented, monitored risk acceptance — and it gives a successor something to inherit.

Governing body responsibilities

In a small entity, several controls necessarily sit with the governing body or its finance committee. Those responsibilities should be written into the body's own procedures rather than treated as informal practice, because informal practice does not survive turnover. At minimum: review of the monthly reconciliation summary, approval of new bank and investment accounts, review of the vendor addition report, and annual approval of check-signing and electronic payment authority.

Where technology helps and where it does not

System-enforced approval workflows genuinely reduce risk, provided that the administrator role is not held by a person who also processes transactions. This is the most frequently overlooked exposure in small entities: the finance director who is also the ERP administrator can, in most systems, alter approval limits, add users, and delete audit trail entries. Where no separate IT function exists, administrator credentials should be held outside the finance department and their use logged and reviewed.

Shared services

Several small entities contracting jointly for an internal audit function, or for a shared accountant who performs reconciliation review across all of them, achieves genuine independence at a cost each entity could not bear alone. Arrangements of this kind are increasingly common among special districts and are worth raising before accepting a permanent control deficiency.


This publication is general information and is not legal, accounting, audit or financial advice. See our Disclaimer. Found an error? Write to [email protected] — we correct in place and note what changed.

Talk to us about your oversight programme

Walk through the platform with your own chart of accounts, or start with the research library. Both routes are free to begin.