---
title: "Accounts payable segregation of duties: a practical matrix"
description: "How to segregate duties in accounts payable, with a role matrix, small-team workarounds and the gap segregation of duties does not close: impersonation."
url: https://realpayee.com/blog/segregation-of-duties-accounts-payable
canonical: https://realpayee.com/blog/segregation-of-duties-accounts-payable
date_published: 2026-10-05
date_modified: 2026-10-05
updated: 2026-10-05
author: "RealPayee"
site: RealPayee
---

# Segregation of duties in accounts payable: a practical matrix for small teams

> Segregation of duties in accounts payable means no single person can create a vendor, approve an invoice and release the payment to it. Split four functions: vendor master changes, invoice entry, approval and payment release, plus independent reconciliation. Small teams can use compensating controls such as a controller review of change logs and bank-portal dual approval.

_Guides · Published 2026-10-05 · 5 min read · By the RealPayee team_

## Key takeaways

- The four AP duties to keep apart: **vendor master maintenance, invoice processing, approval, and payment release**. Reconciliation should sit with someone else again.
- The most dangerous combination is **editing vendor bank details and releasing payments**. Separate those first.
- Small teams that cannot fully separate roles use compensating controls: system-enforced approvals, change-log reviews and bank dual control.
- Segregation of duties stops insiders. It does not stop an outsider who convinces two honest people, so pair it with verification of the request itself.

## What segregation of duties means in AP

Segregation of duties (SoD) is the internal control principle that no one person should control every step of a transaction. In accounts payable, that means the person who can set up who gets paid should not also be able to approve what gets paid and push the money out. Splitting the work means a single mistake or a single dishonest employee cannot complete a fraudulent payment alone: someone else has to look at it.

Auditors test SoD because it is one of the cheapest controls to run and one of the most expensive to lack. For companies subject to SOX, it is a core part of internal control over financial reporting. For everyone else, it is usually the first thing an auditor or cyber insurer asks about after a payment fraud.

## The duties to separate

| Function | What it covers | Risk if combined with payment release |
| --- | --- | --- |
| Vendor master maintenance | Creating vendors, changing bank details, addresses and contacts | Create a fake vendor or redirect a real one, then pay it |
| Invoice processing | Entering invoices, matching to POs and receipts | Enter a fake or duplicate invoice and pay it |
| Approval | Approving invoices and payment batches against budget and authority limits | Approve own fraudulent invoices |
| Payment release | Releasing ACH files, wires and checks in the bank portal | The final step: whoever controls it can move money |
| Reconciliation | Bank reconciliation, vendor statement review, change-log review | Hide the evidence of any of the above |

## A segregation of duties matrix for accounts payable

Use this as a starting point and adjust to your team. "Do" means the role performs the task; "Review" means it checks someone else's work; a blank means no access.

| Task | AP clerk | AP manager | Controller | CFO or treasurer |
| --- | --- | --- | --- | --- |
| Create vendor | Do | Review |  |  |
| Change vendor bank details | Do (after verification) | Review | Review change log |  |
| Enter invoice | Do |  |  |  |
| Approve invoice |  | Do (within limit) | Do (above limit) | Do (above higher limit) |
| Prepare payment batch | Do | Review |  |  |
| Release payment in bank portal |  | Do (first approver) | Do (second approver) | Do (wires above threshold) |
| Reconcile bank account |  |  | Do | Review |
| Review vendor change log |  |  | Do |  |

> [!WARNING]
> **Separate this pair first**
> If you can only fix one thing, make sure nobody who can change vendor bank details can also release payments. That single combination enables most insider vendor fraud.

## Segregation of duties for small AP teams

A two-person finance team cannot fill five columns. That is normal, and auditors accept **compensating controls** when full separation is impossible. The useful ones:

- **System-enforced approvals.** Configure the ERP so a user cannot approve a bill or payment they entered. NetSuite, QuickBooks Online Advanced and Xero all support some form of approval workflow or user roles; use them rather than relying on habit.
- **Bank-portal dual control.** Require two users to release ACH files and wires, and to add new payees. Your bank can enforce this even if your ERP cannot.
- **Owner or outsourced review.** A founder, CFO or outsourced accountant reviews a weekly report of new vendors, bank-detail changes and payments above a threshold.
- **Change-log review before each payment run.** Someone who did not make the changes confirms every vendor bank-detail change since the last run has a recorded verification.
- **Statements to someone else.** Bank statements go directly to someone outside AP, who reviews them before reconciliation.
- **Mandatory time off.** Schemes that need daily maintenance tend to surface when the person running them is away.

## Making it stick in your ERP

1. **Export user roles and permissions** from your ERP and bank portal. List who can do each task in the matrix today.
2. **Mark the conflicts**, starting with vendor bank changes plus payment release.
3. **Remove access** that is not needed. Former employees and shared admin logins are common findings.
4. **Turn on approval workflows** and the audit trail for vendor record changes.
5. **Document compensating controls** for any conflict you cannot remove, with an owner and frequency.
6. **Re-check quarterly**, and whenever someone joins, leaves or changes role.

## Common segregation of duties findings in AP audits

When auditors test accounts payable, the same handful of issues come up again and again. Check for them before the auditors do:

| Finding | Why it matters | Typical fix |
| --- | --- | --- |
| Shared bank-portal login used by several people | No record of who released which payment, and dual control is meaningless | Individual logins with tokens; disable the shared account |
| AP clerk has full admin rights in the ERP | Can edit vendors, approve and pay, and change the audit settings | Role-based access; admin rights held by IT or an outsourced provider |
| Vendor bank changes not logged or not reviewed | A redirected payment is invisible until the vendor complains | Turn on field-level audit trail; review before each run |
| Approval limits exist on paper only | Large invoices are approved by whoever is available | Enforce limits in the ERP approval workflow |
| Leavers still have access | Former staff, or attackers using their credentials, can act | Remove access on the last day; quarterly access review |
| Controller both releases payments and reconciles alone | Errors and fraud can be hidden in the reconciliation | Owner, CFO or outside accountant reviews the reconciliation |

Each fix is cheap on its own. Together they turn segregation of duties from a policy document into something your systems enforce, which is what auditors actually test.

## What segregation of duties does not stop

SoD is designed to stop one person acting alone. External fraud does not need an insider: it needs two honest people to each do their job on a false premise. A clerk updates a vendor's bank details because the request looked real; a manager approves the payment run because the invoice is genuine. Both steps were separated and both were correct on their own. The money still goes to the criminal.

That is how most business email compromise succeeds. The FBI's IC3 recorded about **$3.0 billion** in reported BEC losses in 2025, and in the AFP's 2026 survey **76% of organizations** reported payments fraud in 2025. To close the gap, add a control that checks the **request**, not just the process: verify every bank-detail change and high-value payment with the known contact, on a channel you start. Our guides to [vendor verification](https://realpayee.com/vendor-verification) and [business email compromise examples](https://realpayee.com/blog/business-email-compromise-examples) show how.

RealPayee adds that check without adding headcount. It holds vendor bank-detail changes and payments above your threshold, confirms them with the real person out-of-band and logs who verified what, which also gives your auditors evidence for the change-log review. [Book a demo](https://realpayee.com/demo).

## Frequently asked questions

### What is segregation of duties in accounts payable?

It is the practice of splitting AP tasks so no single person can set up a vendor, approve an invoice and release the payment. The key functions are vendor master changes, invoice processing, approval, payment release and reconciliation.

### What is an example of segregation of duties in AP?

An AP clerk enters invoices and prepares the payment batch, the AP manager approves invoices within a limit, and the controller releases payments in the bank portal and reconciles the account.

### How do small businesses handle segregation of duties?

With compensating controls: system-enforced approvals, dual control in the bank portal, an owner review of new vendors and bank changes, and statements sent to someone outside AP.

### Is segregation of duties required by SOX?

SOX requires effective internal control over financial reporting, and auditors treat segregation of duties as a key part of it. Private companies are not bound by SOX but are usually tested on SoD in audits.

### Does segregation of duties prevent business email compromise?

Not on its own. BEC deceives honest employees at each step. You also need verification of payment requests and bank-detail changes with the real person.

## Sources

- [FBI IC3 2025 report: business email compromise losses (McDonald Hopkins summary)](https://www.mcdonaldhopkins.com/insights/news/the-sobering-truth-of-the-fbis-2025-internet-crime-complaint-center-report)
- [AFP: over 75 percent of US firms experienced payments fraud in 2025](https://www.financialprofessionals.org/about/learn-more/press-releases/Details/over-75-percent-of-us-firms-experienced-payments-fraud-in-2025-while-ai-adoption-for-fraud-mitigation-lags)

## Related

- [Vendor onboarding checklist: a fraud-safe process for AP](https://realpayee.com/blog/vendor-onboarding-checklist) - A step-by-step vendor onboarding process and checklist for AP teams: what to collect, how to verify bank details, who approves, and what to log for audit. (markdown: https://realpayee.com/blog/vendor-onboarding-checklist.md)
- [Business email compromise examples and how to stop them](https://realpayee.com/blog/business-email-compromise-examples) - Seven business email compromise (BEC) examples finance teams see, the red flags in each, and the specific control that stops it before money moves. (markdown: https://realpayee.com/blog/business-email-compromise-examples.md)
- [Vendor verification: how to verify vendor bank details before you pay](https://realpayee.com/vendor-verification) - A practical guide to vendor verification for finance teams: how to confirm vendor bank-detail changes, run callbacks, and prevent vendor impersonation fraud. (markdown: https://realpayee.com/vendor-verification.md)
- [Wire fraud prevention: how to stop bank wire fraud](https://realpayee.com/wire-fraud-prevention) - Controls that prevent business wire fraud: out-of-band verification, payment thresholds, dual approval and audit trails. (markdown: https://realpayee.com/wire-fraud-prevention.md)
- [Free vendor bank-change verification policy template](https://realpayee.com/templates/vendor-bank-change-policy) - A free, copy-ready vendor bank-detail change and callback verification policy template plus checklist for AP teams. (markdown: https://realpayee.com/templates/vendor-bank-change-policy.md)

---

**Further reading**
- [Vendor verification guide](https://realpayee.com/vendor-verification.md)
- [Free vendor bank-change policy template](https://realpayee.com/templates/vendor-bank-change-policy.md)
- [Compare: callbacks vs bank-account validation vs RealPayee](https://realpayee.com/compare.md)
- [Pricing](https://realpayee.com/pricing.md)

Canonical HTML: https://realpayee.com/blog/segregation-of-duties-accounts-payable · Site index for AI agents: https://realpayee.com/llms.txt?src=md-footer · Pricing: https://realpayee.com/pricing.md · Book a demo: https://realpayee.com/demo
