Guide

Segregation of duties in expenses: the four roles that shouldn't overlap

Segregation of duties is the principle that no single person should control every step of a transaction. In an expense process it has a narrow, testable meaning: the person who incurs a cost should not be the person who approves it, records it, and releases the payment.

Most companies believe they have this covered because expenses go to a manager. Then someone checks what actually happens when the manager is the one who ate the dinner, or when finance both records the claim and executes the transfer, or when the person who maintains the approval rules is also an approver. Each of those is a duty overlap, and none of them shows up as an error — the process runs perfectly, which is exactly the problem.

This guide is about expenses specifically, not about access control in general. If you arrived looking for SoD in the identity-management sense — privileged accounts, role mining, ERP authorisation objects — this is not that page. What follows is the four duties in an expense lifecycle, a matrix for finding your own overlaps, and what to do when the team is genuinely too small to separate them.

Written by

Clara Global Editorial Team

finance operations content

Updated

12 min read

Share
Summarize this article with:
Table of contents

The four duties in an expense

Every expense passes through four distinct kinds of authority. Naming them separately is most of the work, because in practice they get bundled into job titles that obscure the split.

Incurring. Committing the company to the cost. Usually the employee, sometimes a budget owner booking on someone's behalf.

Authorising. Deciding the cost is legitimate and within policy. The approver.

Recording. Entering the expense into the books: category, entity, cost center, period.

Custody and disbursement. Controlling the money and releasing the payment.

A fifth function sits across all four: reviewing, meaning the after-the-fact check that the other four behaved. Reviewing is not a duty in the same sense — it is the control that detects when the separation failed — but it needs its own independence, which is why an approver auditing their own approvals is not a review.

The rule of thumb is that the first four should be spread across at least two people for a routine claim, and across at least three where the amount or the risk is material.

The conflict matrix

Read this as: if one person holds both duties in a row, this is what becomes possible and this is what to do about it.

Duty combinations that concentrate authority, what each enables, and the control that addresses it.
Combined dutiesWhat it enablesPractical control
Incur + AuthoriseSelf-approval. Any personal or out-of-policy spend passes because the only reviewer is the beneficiary.Reassign by rule when the approver appears in the expense; route to the approver's own approver.
Incur + RecordThe person who spent chooses the category, entity and period the cost lands in. Misclassification becomes invisible.Categories driven by rules or by a finance-owned mapping, not free choice at submission.
Authorise + DisburseAn approved payment can be released with no second look at whether it matches the approval.Payment executed by someone who did not approve; match the payment file against the approved set.
Record + DisburseThe classic cash-misappropriation combination: the record can be adjusted to fit what was paid.Independent reconciliation of the payment run against recorded liabilities.
Authorise + Configure the rulesAn approver can widen a threshold, approve, and narrow it again. Nothing in the expense record shows it.Rule changes are audit-logged, versioned, and reviewed by someone who is not an approver.
Any duty + ReviewThe check is performed by a participant. It will not find anything.Review assigned to someone outside the chain, or to an external party.

The last two rows are the ones most often missing from SoD checklists. Configuration authority is a real duty — someone who can edit the approval thresholds has effective authority over every expense those thresholds govern — and it usually sits with whoever administers the system, which is frequently also a senior approver. Worth checking explicitly, because no expense record will ever reveal it.

Self-approval: the one everybody has

Self-approval is the most common overlap and the easiest to reason about, which makes it a good place to start.

The obvious form — an employee approving their own claim — is usually blocked by construction. The forms that survive are subtler:

  • The manager attended the team dinner the employee submitted. The approver is a beneficiary even though they are not the submitter.
  • A founder or country lead submits an expense and the only person senior enough to approve it reports to them.
  • An approver is temporarily covering for their own manager and approves an expense they themselves would otherwise have submitted upward.
  • Two peers approve each other's claims reciprocally. Formally separated, practically not.

The first is fixable by rule: when the approver appears in the expense — as an attendee, a beneficiary, or the requester — reassign it. The second is not fixable by rule and needs a named exception route, typically to the board, an audit committee, or an external reviewer, with the exception itself recorded. The third and fourth are detection problems: they are visible in the approval history and invisible in any single claim, which means the control is a periodic report, not a check at submission time.

Do not attempt to solve the second case by adding a fictional approver. An approval chain that routes to someone with no real authority to refuse is worse than an acknowledged exception, because it looks like a control in the audit file.

When the team is too small to separate

Below a certain size the four duties genuinely cannot be spread across four people, and pretending otherwise produces paper controls. The accepted answer is compensating controls: accept the overlap, document it, and add detection that a small team can actually sustain.

What works in practice:

  1. Move the review outside the process

    The person who cannot be separated from the transaction should not be the one reviewing it. An owner, a board member, or an external accountant reviewing a monthly report is a real control even when they touch nothing daily.

  2. Make the exception explicit and dated

    "Finance manager both records and pays, reviewed monthly by the CFO against the bank statement" is a defensible position. The same arrangement undocumented is a finding.

  3. Use thresholds to buy separation where it matters

    Full separation on everything is unaffordable; separation above a threshold is not. Concentrate the second pair of eyes where the amount justifies it.

  4. Log configuration changes

    This is cheap and it covers the duty most likely to be concentrated in a small team, where one person usually administers everything.

  5. Rotate what you can

    Even irregular rotation of who performs the monthly reconciliation breaks the assumption that the same person's work is never seen by anyone else.

The framing that helps here comes from the internal-control literature: control activities are one component among several, and they depend on information and monitoring to function. A small team that cannot separate duties can still monitor, and monitoring is what turns an acknowledged overlap into a managed risk rather than an unexamined one.

Delegation without breaking segregation

Delegation is where a well-designed separation quietly collapses, because the delegate inherits authority without inheriting the constraints that justified it.

Three rules keep it intact:

Delegation is a recorded state, not a favour. It has a delegate, a start, an end, and a reason. An approval that appears under someone’s name because a colleague had their laptop is not a delegation; it is an unlogged authority transfer, and it is indistinguishable from the real thing in the record.

A delegate inherits the delegator's conflicts. If the delegator could not approve a given expense, neither can the delegate acting in their place. This is easy to state and easy to omit from a system that treats delegation as a simple reassignment.

Delegation does not stack. A delegate should not be able to delegate onward. Two hops is enough to make the chain unreconstructable, and the audit question is always "who actually decided this?"

A delegation of authority matrix builder, in preparation, will produce the role and threshold grid this rests on; automated expense approvals covers the routing mechanics.

Checking your own setup in an afternoon

This is a review any finance team can run without a project.

  1. List who can do each of the five things. Incur, authorise, record, disburse, configure. Names, not roles — job titles hide overlaps.
  2. Cross the list with itself. Anyone appearing in two columns of the matrix above is a finding. Do not skip the configure column.
  3. Pull the last quarter's approvals and look for reciprocity. Pairs who approve each other repeatedly are a pattern, not a coincidence.
  4. Find the expenses where the approver appears in the expense itself. Attendee lists, "team lunch", travel booked for a group. This is where self-approval hides.
  5. Check what happened during leave. Every delegation in the period should have a record with a start and an end. Approvals during someone’s absence with no matching delegation record are the finding.
  6. Check whether approval rules changed. If you cannot answer "who changed a threshold and when", that is the first gap to close, regardless of what else the review found.
  7. Write down the overlaps you are choosing to keep, with the compensating control for each. This is the output. A review that produces only findings and no accepted-risk list will be repeated identically next year.

How Clara supports separation of duties

Clara Global routes each expense to the right person based on the approval rules the finance team defines, rather than relying on the submitter to forward it to an appropriate reviewer. Because the routing is rule-based, the conditions that enforce separation — amount bands, entity ownership, who the approver is — are configuration rather than convention, and the record shows which rule sent the expense where it went.

The rules are configured per company and evaluated on the expense itself, so the same separation holds for an employee in any country submitting in any currency.

Two limits are worth stating plainly. Software cannot separate duties that a company has assigned to one person — if the same individual approves, records and pays, no configuration changes that, and the honest control is the documented compensating one. And the routing enforces the rules it was given: a threshold set too high or an exception route pointing at a beneficiary will be applied faithfully and repeatedly. The separation is a design decision; the system's contribution is making it consistent and visible.

For the evidence side — what the record has to contain for any of this to be checkable later — see expense audit trails.

Methodology

The conflict matrix and the review procedure on this page are practitioner guidance, not quotations from a standard. The frameworks referenced below describe internal control in general terms; none of them prescribes an expense-specific split of duties.

What a particular organisation is expected to separate depends on its size, sector and regulator, so use the matrix as a starting point for your own assessment rather than a checklist to satisfy.

Frequently asked questions

What is segregation of duties in an expense process?

Segregation of duties in an expense process means splitting the four kinds of authority over a claim — incurring the cost, authorising it, recording it in the books, and releasing the payment — across more than one person, so that no individual can complete a transaction end to end without a second party seeing it. A fifth function, reviewing, sits above the four and needs its own independence to be meaningful.

The reason it matters in expenses specifically is that expense transactions are numerous, individually small, and initiated by the person who benefits from them. That combination makes them a poor fit for controls that rely on someone noticing an unusual item. The separation is what makes the process resistant to both error and misuse without requiring anyone to be suspicious.

How many people do you need to segregate duties in expenses?

Two people can cover a routine claim if the submitter is not the approver and the person who releases payment is not the person who approved it. Three gives you meaningful separation on material amounts, typically by splitting recording from disbursement. Four is the textbook arrangement and is more than most finance teams below a few hundred people can staff.

The number is less important than which pairs you avoid. Recording plus disbursement in one person is the combination that historically enables misappropriation, so if you can only separate one pair, separate that one. Where the headcount genuinely is not there, the accepted approach is to document the overlap and add a compensating control — most usefully an independent review of a monthly report by someone outside the process, such as an owner, a board member or an external accountant.

Can a manager approve an expense they benefited from?

Generally no, and this is the most common overlap that survives in otherwise well-run processes. A manager who attended the dinner an employee submitted is a beneficiary of the expense, and the fact that they did not submit it does not restore independence. The control is a rule that reassigns the claim when the approver appears in the expense — as attendee, beneficiary or requester — routing it to the approver’s own approver instead.

There is a case that cannot be fixed by routing: an executive whose only plausible approver reports to them. Adding a nominal approver with no real authority to refuse makes the audit file worse, because it presents a control that does not exist. The defensible handling is a named exception route — an audit committee, a board member, or an external reviewer — with the exception itself recorded as such.

Does segregation of duties apply to a five-person company?

Yes, but as a documented compromise rather than a full separation. A five-person company cannot spread four duties across four people, and an SoD policy that claims otherwise will not survive its first review. What is expected at that size is that the overlaps are identified, written down, and paired with detection that the team can actually sustain.

In practice that usually means one arrangement: whoever holds the concentrated duties does not also perform the review. A monthly reconciliation of the payment run against the bank statement, performed by an owner or an external accountant who touches nothing day to day, is a genuine control. Combined with logging changes to approval rules and applying a threshold above which a second approver is required regardless, it is a proportionate answer — and, importantly, one an auditor can be shown.

How do delegated approvals affect segregation of duties?

Delegation preserves segregation only when the delegate inherits the delegator’s constraints as well as their authority. If the delegator could not approve a particular expense because they appear in it, the delegate standing in for them cannot either — a system that treats delegation as a plain reassignment will silently drop that restriction.

Two further conditions matter. Delegation should be a recorded state with a named delegate, a start and an end, so that an approval during someone’s absence can be tied to an authorised handover rather than to a shared password. And it should not chain: allowing a delegate to delegate onward makes the question "who actually decided this?" unanswerable within two hops, which is precisely the question an audit asks.

Who should be able to change approval rules?

Not an approver, if you can avoid it. The authority to change a threshold is authority over every expense that threshold governs, which makes configuration a duty in its own right rather than an administrative task. Where it is concentrated in the same person who approves — common, since both tend to land on whoever administers the system — the overlap should be recorded as an accepted risk with a compensating control.

The minimum control is a versioned, audit-logged history of rule changes, reviewed periodically by someone outside the approval chain. This is worth prioritising over most other SoD work in a small team, because it is inexpensive and because no amount of scrutiny of individual expense records will ever reveal a threshold that was widened and narrowed again.

Sources

About this guide

This guide covers segregation of duties in expense processes specifically, not access control in general. The conflict matrix is practitioner guidance rather than a standard, and what your organisation is expected to separate depends on its size, sector and auditor.

This page is operational guidance for finance teams. It is not legal, audit, or accounting advice. The segregation of duties expected of a particular organisation depends on its size, sector, regulatory regime and auditor — confirm requirements with a qualified adviser before relying on any arrangement described here.

Make separation configuration, not convention

Start free and see how rule-based routing keeps approval separation consistent instead of conventional.

Start free

Start now!