Key takeaways

  • The four incompatible functions are authorization, custody, record-keeping and reconciliation. No one person should hold more than two for the same cycle.
  • Full segregation is impossible below about twenty people. The answer is compensating controls, not a control matrix nobody follows.
  • Vendor master change control is the single highest-value control most small businesses do not have.
  • A control that leaves no evidence it was performed is, to an auditor, a control that does not exist.

Most internal control advice written for small businesses is written for large ones and then apologized for. It arrives as a forty-line framework, gets read once, and is quietly abandoned by the second month because nobody has the people to run it.

So here is the honest version. In a business under about fifty employees, seven controls prevent most of the damage. They are the ones we test first in an assessment, and the ones whose absence shows up most often in the investigations we are called into afterward. Each is achievable in a small team, and each leaves evidence, which matters, because a control that leaves no trace is indistinguishable from a control that was never performed.

The principle underneath all seven

Segregation of duties means no single person controls a transaction from beginning to end. There are four incompatible functions:

  1. Authorization: approving that the transaction should happen
  2. Custody: having physical or system control of the asset
  3. Record-keeping: entering it into the accounting system
  4. Reconciliation: independently checking the record against reality

Ideally, no person holds more than two of these for the same cycle. In a nine-person business that is simply not achievable, and pretending otherwise produces a document that describes a company you do not have.

The goal is not perfect separation. It is that no single person can both cause a misstatement and conceal it. The working definition we use in small-team control design

That reframing is what makes the seven controls below possible. Each one takes something a single person currently controls end to end and inserts a second pair of eyes at the point where concealment would otherwise happen.

01. Independent bank reconciliation review

Whoever reconciles the bank account should not also authorize or release payments. Where the team is too small for that, the compensating control is straightforward: an owner, director or board member receives the bank statement directly from the bank and reviews the completed reconciliation.

Directly matters. A statement forwarded by the person being checked is not independent evidence. It is a document that person had an opportunity to alter. Most banks will provide read-only access or a duplicate statement to a second party in about ten minutes.

What the reviewer should look at: unusual payees, round-number transfers, payments to individuals rather than businesses, and any reconciling item older than sixty days. It takes fifteen minutes a month and closes the most common concealment route there is.

02. Vendor master change control

If we could install only one control in a small business, this would be it. Adding a new vendor, or changing an existing vendor's bank details, requires approval from someone who cannot process payments.

Two very different schemes run straight through this gap. The first is the fictitious vendor: an employee creates a supplier that does not exist and pays it. The second, far more common now, is business email compromise: an attacker impersonates a real supplier, requests a bank detail change, and the next legitimate invoice is paid to them. The invoice is real. The goods were delivered. Only the destination changed.

Make the verification out-of-band

A bank-detail change must be verified by phoning the vendor on a number you already held, not the number in the email requesting the change. Emails claiming urgency and confidentiality around a payment detail change are the pattern, not the exception. Building a "call the number on file" step into the process costs nothing and is the difference between a near miss and a six-figure loss.

03. Dual authorization above a threshold

Payments over an agreed value require two approvers. The art is entirely in setting the threshold: too low and operations grind while people chase signatures; too high and it never actually applies.

A reasonable starting point is to set it so that roughly the top five to ten percent of payments by count require dual approval: enough that it catches anything material, low enough that it does not become theater. Then watch for structuring. If the threshold is $10,000 and you begin to see a cluster of payments at $9,700, that is not coincidence. It is the control working, and telling you something.

04. Purchase approval before commitment

Approval must happen at the point of order, not the point of invoice. Approving an invoice for goods already received and consumed is not a control. It is a formality, because the only options at that stage are to pay or to default.

In a small business this does not require a purchase order system. A rule that any commitment above a stated value needs written approval before it is placed (an email is sufficient) achieves most of the benefit. It also produces the first honest picture many owners get of what is actually being committed each month, as opposed to what is being invoiced.

05. Payroll change review

New starters, leavers and pay rate changes should be reviewed against independent HR records by someone outside the payroll function. Payroll is usually the largest expense line in a service business, and it is the line with the least routine scrutiny precisely because it is recurring and therefore looks unremarkable.

Two schemes live here. Ghost employees: a person who no longer works there, or never did, still on the payroll, survive only where nobody compares the payroll register to the HR roster. Unauthorized rate changes survive where nobody compares this period's rates to last period's. Both are caught by a monthly exception report showing every change since the prior run. Most payroll systems produce this natively; almost nobody reads it.

The seven controls, the function each separates, and the time each takes
#ControlSeparatesOngoing effort
01Independent bank reconciliation reviewReconciliation from custody~15 min/month
02Vendor master change controlAuthorization from record-keeping~5 min per change
03Dual authorization above thresholdAuthorization from custodyPer payment, top decile
04Purchase approval before commitmentAuthorization from custodyPer commitment
05Payroll change reviewAuthorization from record-keeping~10 min/pay run
06Journal entry reviewRecord-keeping from authorization~20 min/month
07System access reviewAll four~1 hour/quarter

06. Journal entry review

Manual journal entries above a threshold, and all entries posted after the close date, should be reviewed and approved by someone other than the preparer.

This is the control that matters most for financial statement integrity rather than asset protection. Most manipulation of reported results runs through manual journals, because that is the only mechanism that can move a number without a corresponding real-world transaction. The pattern worth watching for is the entry that is posted, then reversed the following period, then posted again: a number being held at a desired level rather than reflecting anything that happened.

In practice this is twenty minutes a month reviewing a journal listing. Most accounting systems will produce one filtered to manual entries only.

07. System access review

Quarterly, someone should review who has access to what (accounting system, banking, payroll, expense platform) and remove what is no longer needed.

Access accumulates. People change roles and keep the old permissions alongside the new ones, which is how a single individual quietly ends up holding all four incompatible functions without anyone deciding that should happen. And departed employees retaining access is startlingly common: it is nobody's explicit job, so it is nobody's job.

An hour a quarter, with a written record of what was reviewed and what changed. That record is also the first thing an auditor will ask for.

Controls need evidence

One point that undoes otherwise good practice: a control that leaves no evidence it was performed is, to an auditor, a control that does not exist.

"The owner looks at the bank statement every month" is not a control anyone can rely on. "The owner signs and dates the reconciliation, and the signed copies are filed" is. The difference is not diligence. It is provability. Where possible, let the system be the evidence: approval workflows in your accounting or payments platform create a timestamped record automatically and cannot be reconstructed after the fact.

Where to start

If you are implementing from nothing, sequence it by exposure rather than by ease:

  1. Vendor master change control: highest value, lowest effort, and the loss it prevents is immediate and large
  2. Independent bank reconciliation review: closes the main concealment route
  3. System access review: tells you how bad the segregation problem actually is
  4. Then the remaining four, in whatever order fits your operating rhythm

All seven can realistically be in place within a quarter. If you would like an outside read on which ones you already have in substance rather than on paper, that is what a controls assessment is for, and the uncomfortable question it starts with is whether one person in your business could set up a vendor, approve an invoice, release the payment and reconcile the bank.


Article tags