Corpay

Segregation of Duties in AP: Why It Matters and How Automation Enforces It

Category:AP Automation, Risk management
Updated:2026-09-15
Author:David Luther

Segregation of duties in accounts payable means no single person controls a payment from vendor setup through invoice approval through payment release and reconciliation. The duties are split so that committing fraud requires collusion rather than just access.

Almost nobody decides to skip it. What actually happens is that the treasury team can enter invoices, and so can procurement, and so can the general ledger team, because at some point each of them needed to and the permission never came back off. Separation gets lost one access grant at a time, and the org chart still says it's in place.

The cost is measurable. More than half of the 2,402 occupational fraud cases studied in the Association of Certified Fraud Examiners' Occupational Fraud 2026: A Report to the Nations involved an internal control failure. Segregation of duties is one control inside a wider framework, and the full accounts payable controls checklist covers the rest of that framework. This piece stays on this one control.

Key Takeaways

  • The principle in AP is narrow. Nobody who can create or change a vendor record should also be able to release a payment to it.

  • Six duties matter, and only a handful of their pairings are genuinely dangerous. Knowing which ones lets a small team focus its limited separation where it counts.

  • A four-person finance team cannot achieve textbook separation, and pretending otherwise is why control documentation goes stale.

  • Compensating controls substitute partially, not fully. Say which risk each one actually covers and which it leaves open.

  • System permissions, not the org chart, are what an auditor tests. Separation that exists in a policy document and not in the ERP does not exist.

What does segregation of duties mean in accounts payable?

It means splitting the AP cycle so that no one person can originate, approve, and complete a payment. The generic accounting definition talks about authorization, custody, and recording. The AP version is more specific and more useful.

Four functions have to stay apart in an AP cycle:

  • Establishing who gets paid, meaning creating and editing vendor records including banking details

  • Authorizing what gets paid, meaning approving the invoice and the underlying obligation

  • Executing the payment, meaning releasing the check run, the ACH file, or the card payment

  • Recording and reconciling, meaning posting to the ledger and reconciling the bank statement

Separation is a preventive control rather than a detective one, and that distinction carries practical weight. A detective control finds the fraud afterward, which is better than nothing and much worse than prevention. Prevention makes the fraud require a second person, and a scheme that needs collusion is dramatically less likely to start.

The duration data makes the case in dollars. The median fraud case runs 12 months before detection at a median loss of $104,000, but schemes caught within six months cost a median $40,000, while those running five years or longer exceeded $1.1 million. A split duty doesn't only reduce the chance of fraud; it shortens the window before someone notices, and that window is most of the loss.

How does this fit inside the wider AP controls framework?

It's one control among many, and the others belong to the wider checklist rather than here. What accounts payable actually covers is the definitional layer upstream of all of it. Matching, duplicate detection, reconciliation procedure, and documentation standards are all separate mechanisms with their own failure modes.

Separation earns its own treatment because it's structural rather than procedural. You can add a matching rule on a Tuesday afternoon. Changing who can do what touches job descriptions, system permissions, and sometimes the way a person has worked for eleven years.

Which accounts payable duties must never sit with the same person?

Six duties, and the dangerous combinations are specific. This is the table worth printing and holding against your actual permission set.

If one person can...

...and also...

The fraud that enables

Create or edit a vendor record

Release a payment

A fictitious vendor paid to an account the same person controls

Create or edit a vendor record

Approve invoices

A shell vendor with self-approved invoices, no PO required

Change vendor bank details

Release a payment

Redirecting a legitimate supplier's payment to a personal account

Enter an invoice

Approve that invoice

Inflated or duplicate invoices approved by the person who created them

Approve an invoice

Release the payment

Payment to an approved but altered amount or payee

Release a payment

Reconcile the bank statement

Concealment; the unauthorized payment never surfaces in the reconciliation

Enter an invoice

Reconcile the bank statement

Fictitious invoices masked by adjusting entries at reconciliation

Pairings reflect standard internal control practice; the specific fraud descriptions are illustrative of each conflict.

The first three rows are where the real money goes. Vendor-master control combined with payment release is the pairing that produces the losses people read about in the news, because it removes every barrier between deciding to steal and having the money.

Who should be able to create or change a vendor record?

Someone who cannot release a payment, and ideally someone outside AP entirely. The vendor master is the highest-privilege object in the whole cycle, because it determines where money goes, and most organizations guard it far more loosely than they guard the payment run.

Bank-detail changes deserve their own treatment, separate from vendor creation. A change request should come from one person and be approved by another, with independent verification against a known phone number rather than the contact details in the request email. That specific control is what stops vendor impersonation.

The scale of the threat justifies the friction. The FBI's Internet Crime Complaint Center recorded 1,008,597 complaints and $20.877 billion in losses in 2025, a 26% increase over 2024, with business email compromise alone accounting for $3,046,598,558, up from $2,770,151,146 in 2024. The AP-facing version of BEC is vendor impersonation, and it works precisely when one person can both update a bank record and push the payment. Broader defensive tactics are covered in defending the business against payment fraud.

Who approves an invoice, and who releases the payment?

Different people, and the approval should belong to whoever owns the budget rather than to anyone in AP. AP's job is to verify that an approved obligation is documented and matched, not to decide whether the purchase should have happened.

Release is a separate act again. Someone builds the payment batch; someone else reviews and releases it. That review has to be real, meaning the releaser looks at payee, amount, and any changes since approval, rather than clicking through a summary screen. Designing invoice approval routing so the right person sees the right invoice is what makes real review possible instead of theatrical.

Who mails or releases the checks?

Not the person who prepared them, and not the person who reconciles the account. This sounds like a small question and it's asked constantly, because check handling is where separation quietly collapses in small offices.

The person with physical custody of signed checks has custody of assets. Combining that with the ability to record transactions means an altered or diverted check can be hidden in the books. Positive pay and check fraud defense is the compensating control where custody can't be split, and checks remain the most-attacked instrument. AFP's 2026 Payments Fraud and Control Survey Report found 58% of organizations reported checks subject to fraud, against ACH debits at 30% and wire transfers at 25%.

What do you do when the team is too small to separate the duties?

You accept that you can't reach textbook separation and you build a compensating-control ladder instead. A four-person finance team has fewer people than the model requires, and a control matrix that claims otherwise is a document nobody believes.

The arithmetic is getting harder, not easier. Bookkeeping, accounting, and auditing clerks held 1,532,400 jobs at a median wage of $50,670 in 2025, and employment is projected to decline 6% from 2025 to 2035, a loss of 85,600 jobs, according to the Bureau of Labor Statistics' Occupational Outlook Handbook. The invoices aren't declining at that rate, so the average AP team is getting smaller relative to its workload.

What compensating controls substitute for headcount?

Five, roughly in order of how much they buy you:

  1. Owner or executive review of the payment register. The business owner or a non-finance executive reviews every payment run before release, at least by exception above a threshold. This covers fictitious vendors and unauthorized payees. It does not cover inflated amounts to legitimate vendors, because the reviewer has no basis to judge them.

  2. Independent bank reconciliation. Someone with no payment authority reconciles the account, monthly, with the statement obtained directly rather than handed over. This covers concealment. It's detective rather than preventive, so it finds the problem after the money left.

  3. Mandatory dual approval above a dollar threshold. Two approvers on anything above a set amount. This covers large single-event losses and leaves small recurring ones entirely open, which is the shape most long-running schemes actually take.

  4. Positive pay and vendor-account validation at the bank. The bank rejects checks or ACH items that don't match what you told it to expect. This covers alteration and forged items, and nothing about internal authorization.

  5. Rotating duties and mandatory time off. Someone else does the job for two weeks a year. This is genuinely effective for detection, because most concealment requires continuous attention, and it's the control small teams skip first.

None of these is separation. Each one narrows a specific opening, and the honest way to document them is to write down what each covers and what it leaves exposed, rather than listing five controls and implying the sum equals a clean split.

Protect cash flow with modern AP

Modernize AP to cut costs, speed approvals, and mitigate payment risk — gaining the real-time visibility to protect cash flow and scale with confidence.

Download the whitepaper
protect-cashflow-with-ap.jpg

How much separation can a three-person finance team realistically reach?

More than most of them do, if you're deliberate about which split matters. With three people, you can't separate all six duties, and you can separate the one that matters most, which is vendor-master maintenance from payment release.

Give vendor creation and bank-detail changes to the person who never touches the payment run. Give payment release to someone else. Let invoice entry and approval overlap if they must, with owner review of the register as the compensating control. That's an imperfect arrangement that closes the expensive door, which beats a perfect-looking matrix that closes none of them.

Multi-entity setups need the split to hold per subsidiary as well as per person, which is a requirement generic AP tooling handles poorly. Running AP across multiple entities is a separate problem with its own routing and queue requirements.

When does moving a duty outside the team restore the split?

When the duty leaves your organization entirely, which is the only way a four-person team gets a genuine sixth pair of hands. Vendor onboarding and bank-detail validation are the natural candidates, because they're rules-driven, high-risk, and low-judgment.

If an outside service establishes and verifies supplier banking details, nobody inside your AP team controls where money goes. That's not a compensating control; it's actual separation, achieved by subtraction. The same logic applies to supplier enrollment work generally, which is covered in why vendor enrollment decides program success.

How does a system enforce separation the org chart cannot?

By binding permissions to duties rather than to job titles. ERPs grant access by role, and roles are built around jobs. One job frequently contains several incompatible duties, so the permission set inherits the conflict and nobody notices until an auditor maps it.

That mismatch is the mechanism behind most segregation failures. Nobody granted a person the ability to create a vendor and pay it. Somebody granted a person the "AP Manager" role, which happened to contain both.

How do approval hierarchies and thresholds encode the split?

By making the routing a property of the transaction rather than a habit of the team. An approval hierarchy that routes by amount, GL account, department, or entity produces a different approver for a $500 office supply invoice than for a $95,000 subcontract, without anyone deciding in the moment.

Thresholds turn dual approval from a policy into a mechanic. Above the line, a second approver is required and the system won't advance without one. That's separation that holds when the controller is on vacation, which is exactly when policy-based separation stops holding.

What should vendor-master permissions block?

The ability of one identity to both request and approve a change to payment destination. Requesting a bank-detail update and approving it are two duties, and a system that treats "edit vendor" as a single permission has collapsed them.

Maker-checker on the vendor master is the control. One person submits, another approves, and the record shows both. The same applies to new vendor creation, and it should apply to reactivating a dormant vendor, which is the path most often used to avoid the scrutiny a new record attracts.

Every one of those actions should leave a record that survives the person who took it. Vendor management across the lifecycle covers the wider discipline around the master file.

Why does system access matter more than the org chart?

Because the org chart is what you intend and the permission set is what's true. An auditor doesn't ask who is supposed to be able to create vendors; they pull the list of users who can.

Automation helps here in a way that's easy to undersell. Straight-through processing reduces the number of transactions a human touches at all, which concentrates human attention on the exceptions where override risk actually lives. Companies whose touchless invoice-processing rate clears the 30% mark run 3.5 times higher AP productivity, and customers of evaluated AP platforms averaged a 60% touchless rate with cycle times improving 59% after implementation, according to The Hackett Group's 2025 Digital World Class Matrix: Accounts Payable Provider Perspective. Fewer hands on the routine work means the hands you do have can be split where it matters.

The systems most of these teams run, NetSuite and Sage Intacct and Dynamics 365 and Acumatica and QuickBooks, each handle duty-level permissioning differently. How ERP systems fit the payments stack sets the context if that's the gap.

How do you know your segregation of duties is actually working?

Pull the evidence rather than asking people. This is a self-check for the finance team, not an audit-testing procedure, and it takes an afternoon.

Start with the permission export. List every user who can create or edit a vendor, every user who can approve an invoice, and every user who can release a payment, then look for names appearing in more than one list. Most organizations doing this for the first time find at least one person who shouldn't be there, and it's usually someone who covered for an absence in 2023.

What evidence should a working control leave behind?

An audit trail showing different identities at each step of the same transaction, with timestamps. Pick ten payments at random and trace each one, checking that the vendor record, the approval, and the release show different users.

If the same name appears twice on a single payment path, the control failed on that transaction regardless of what the policy says. The trail also has to be immutable, because a log that can be edited by the people it records proves nothing. This is the same evidence base that matters in how accounts payable fraud happens and how it gets found.

How do conflicts creep back in after go-live?

Through temporary access that never gets revoked, and through role changes where new permissions are added but old ones aren't removed. Both are administrative rather than malicious, and both are invisible until someone looks.

Set a quarterly recertification. The owner of each system confirms in writing which users hold which duty-level permissions. Ninety minutes a quarter catches drift that would otherwise surface in an audit finding two years later. The ACFE study's core finding, that control failures are involved in most fraud, is largely a story about controls that existed at implementation and quietly stopped being true.

What happens to separation when someone is out?

It usually breaks, which is why leave coverage deserves a documented plan rather than an improvised permission grant. The pattern is familiar. The controller is out for a week, someone gets temporary access to release payments, and the access stays.

Plan the coverage in advance and name the backup for each duty. Use time-limited access where the system supports it, and put the revocation on a calendar rather than trusting anyone to remember. The broader fraud picture makes the stakes concrete: 76% of U.S. organizations experienced attempted or actual payments fraud in 2025, while just 17% use AI to fight it, according to AFP's 2026 survey.

Build enforced separation into AP with Corpay

The strongest thing an outside platform can do on this topic is take the riskiest duty out of your building.

Corpay's supplier enrollment and vendor banking validation run as part of a fully managed AP service, which means establishing and verifying where money goes happens outside your AP team entirely. For a four-person finance department, that's separation that could not otherwise exist, and it's the piece no amount of internal process design can create.

The rest is configurable control. Approval hierarchies route by amount, account, department, and entity, so dual approval above a threshold is enforced by the system rather than remembered by a person. Payment release requires a second identity. Vendor-master changes run maker-checker, and every action leaves a timestamped record. Payments go out across virtual card, ACH, and check, with single-use virtual cards closing after one transaction so an intercepted number is worthless.

We're an ERP complement rather than a replacement, which matters here because the ERP is where the permission problem lives. Corpay maintains 100+ ERP integrations, including NetSuite, Sage Intacct, Business Central, and Acumatica, and the ERP integrations page covers how the connection works. Customers see about 40% time saved on the AP cycle, and implementations go live in weeks rather than quarters.

For teams still mapping the basics, the accounts payable process, step by step, three-way matching, and purchase order versus invoice fill in the surrounding mechanics, and corporate card controls and spend policies cover the card side of the same principle.

Frequently Asked Questions

What does segregation of duties mean in simple terms?

It means splitting a process so no one person can complete it alone. In accounts payable, that means the person who sets up a vendor can't also approve its invoices or release its payments, so fraud requires two people to cooperate rather than one person to decide.

What are the three functions that must be separated?

The classic three are authorization, custody, and recording. In accounts payable terms, that translates to approving the obligation, controlling the payment and the vendor record, and posting and reconciling the transaction. Keeping any two of those with one person creates a specific fraud opening.

Is segregation of duties an internal control?

Yes, and a preventive one. It stops fraud from occurring rather than detecting it afterward, which is why auditors weight it heavily. It sits alongside authorization limits, matching, reconciliation, and documentation standards within a wider controls framework.

Can one person do accounts payable?

Operationally, yes. Safely, only with compensating controls in place. A single-person AP function needs owner review of every payment run, independent bank reconciliation, and vendor banking validation performed outside the team, with each gap documented rather than papered over.

What is a segregation of duties matrix?

A grid mapping duties against each other, marking which combinations conflict. Rows and columns list the duties, and each cell shows whether one person may hold both. It's used to test an actual permission set against intended separation and to document known exceptions.

Who should mail or release the checks?

Someone who neither prepared the checks nor reconciles the bank account. Physical custody of signed checks is custody of assets, and combining custody with recording lets a diverted payment be concealed. Where the split isn't possible, positive pay is the usual compensating control.

Does an ERP handle segregation of duties on its own?

Not by default. ERPs assign permissions by job role, and a single role often contains several incompatible duties. Duty-level permissioning has to be configured deliberately, and the resulting access lists have to be recertified as roles change.

What compensating controls work for a small finance team?

Owner review of the payment register, independent bank reconciliation, mandatory dual approval above a threshold, positive pay at the bank, and rotating duties with mandatory time off. Each closes a specific gap and leaves others open, so document what each one actually covers.

Headshot.JPG

David Luther

Product Marketing Program Manager
David Luther, MBA is a product marketing program manager with years of experience in commercial banking, finance, and technology sectors, with research and writing appearing in financial publications.
AP Automation
Risk management

Smarter payments. Stronger growth. Keep business moving.

Corpay powers payments for 800,000+ businesses worldwide. Let’s build what’s next for yours.

Please select your communication type
Please enter your first name
Please enter your last name
Email address is required
Please enter your company
Please enter your region

By submitting your information through this form, you agree to receive a telephone call or email from a Corpay representative. Your information will be used in accordance with our Privacy Policy.