Segregation of duties
Also known as: separation of duties
Segregation of duties is an internal control that divides key responsibilities — authorizing transactions, recording them, and holding custody of assets — among different people so no single employee can both commit and conceal fraud.
Segregation of duties is a foundational internal control principle: no single person should control all stages of a transaction. By splitting responsibilities among different employees, an organization ensures that committing fraud or hiding an error would require collusion between two or more people, which is far less likely than a single bad actor operating alone.
The classic framework separates four functions: authorization (approving transactions), custody (physically holding cash, inventory, or other assets), recordkeeping (entering transactions in the accounting system), and reconciliation (comparing records to reality). Consider accounts payable: if one employee could create a vendor, approve an invoice, and sign the check, they could pay a fictitious company and bury the evidence. Splitting those steps among different people makes the scheme visible.
When staffing is too small to fully separate duties, organizations apply compensating controls — increased management review, mandatory vacations, job rotation, and independent reconciliations. Segregation of duties also extends to information systems, where access rights are configured so users cannot both initiate and approve the same transaction.
The CMA Part 1 exam tests segregation of duties within its internal controls section, tied to the COSO framework's control activities component. Expect questions asking which combinations of duties are incompatible — authorization, custody, and recordkeeping held by one person is the red flag — and which compensating controls address gaps in small organizations.
Key takeaways
- Segregation of duties prevents any one person from controlling a transaction end to end, so fraud requires collusion.
- The incompatible functions to separate are authorization, custody of assets, recordkeeping, and reconciliation.
- Small organizations that cannot fully separate duties rely on compensating controls like management review and job rotation.
- The CMA Part 1 exam tests identifying incompatible duty combinations as part of its internal control coverage.
