Skip to Content

Why Segregation of Duties Outweighs Employee Loyalty

July 29, 2026 by

“We trust our employees.”

This is one of the most common responses internal auditors hear when raising concerns about inadequate segregation of duties.

Employee loyalty is valuable. Long-serving and trusted employees often possess deep institutional knowledge, strong relationships, and a genuine commitment to the organisation. However, loyalty should never be treated as a substitute for internal control.

A well-designed control environment does not assume that employees are dishonest. It recognises that mistakes, pressure, conflicts of interest, changes in personal circumstances, and management override can occur in any organisation.

The purpose of segregation of duties is therefore not to demonstrate distrust. It is to protect the organisation—and its employees—from avoidable risk.

What Is Segregation of Duties?

Segregation of duties, commonly referred to as SoD, is the separation of critical responsibilities across different individuals.

In a properly controlled process, one person should not have complete authority over an entire transaction from beginning to end.

The key responsibilities that should normally be separated include:

  • Initiating or requesting a transaction
  • Approving the transaction
  • Recording the transaction
  • Holding or controlling the related asset
  • Reviewing or reconciling the transaction

For example, an employee who creates a new supplier should not also be able to approve supplier payments and reconcile the bank account.

Similarly, an employee responsible for receiving cash should not be solely responsible for recording revenue and reconciling the cash balance.

When these responsibilities are concentrated in one person, errors or irregularities may occur without timely detection.

Trust Is Important, but Trust Is Not a Control

Many organisations rely heavily on trusted employees, particularly in finance, procurement, payroll, inventory, and treasury functions.

This often develops gradually.

An employee performs well, gains management’s confidence, and receives additional responsibilities. Over time, the employee may gain access to supplier creation, purchase approval, payment processing, accounting records, and bank reconciliation.

Management may view this as operational efficiency. From an internal control perspective, however, it creates a significant concentration of risk.

The problem is not necessarily the employee’s character. The problem is that the organisation has created an environment in which:

  • Errors can remain undetected;
  • Fraud can be committed and concealed;
  • Management cannot independently verify transactions;
  • Business continuity depends excessively on one person; and
  • Allegations against the employee become difficult to investigate objectively.

Even an honest employee may make an error and unintentionally conceal it while trying to correct the issue. In other cases, an employee may be placed under unexpected financial or personal pressure.

A control system should not depend on the assumption that circumstances will never change.

Segregation of Duties Also Protects Employees

Segregation of duties is sometimes perceived as burdensome or as a sign that management does not trust its employees.

In reality, effective segregation protects employees from suspicion.

Consider a situation where one finance employee controls supplier records, payment files, online banking access, and bank reconciliation. If a payment irregularity is later identified, that employee may immediately become the primary subject of investigation, even if the issue resulted from a system error or another person’s actions.

When responsibilities are appropriately separated and transactions are independently reviewed, accountability becomes clearer.

Employees are less likely to be unfairly blamed, and management has stronger evidence to determine what actually occurred.

Therefore, segregation of duties should be communicated as a protection mechanism—not merely as a fraud prevention measure.

Why Smaller Businesses Are Particularly Vulnerable

Small and medium-sized businesses frequently face practical limitations. They may not have enough employees to separate every responsibility fully.

This does not mean segregation of duties should be ignored.

Where complete separation is not practical, management should introduce compensating controls. These may include:

  • Independent review of bank reconciliations;
  • Secondary approval of payments;
  • Regular review of supplier master-data changes;
  • Automated notifications for unusual transactions;
  • Restricted access to accounting and banking systems;
  • Periodic review of user access rights;
  • Direct review of bank statements by an owner or director; and
  • Unannounced inventory or cash counts.

The objective is not to create unnecessary bureaucracy. The objective is to ensure that no individual can initiate, approve, record, and conceal a transaction without independent oversight.

Warning Signs Management Should Not Ignore

Certain conditions may indicate that segregation-of-duties risk requires immediate attention.

These include:

  • One employee refuses to take leave;
  • Transactions can only be explained by one individual;
  • Shared system accounts or passwords are used;
  • The same employee creates and approves suppliers;
  • Payment approvers rely entirely on documents prepared by the payment processor;
  • Bank reconciliations are not independently reviewed;
  • Former employees retain system access;
  • Emergency access is frequently used;
  • Manual journal entries receive limited review; or
  • Management accepts explanations without supporting evidence.

Individually, these conditions do not prove misconduct. Collectively, however, they may indicate that the control environment depends too heavily on personal trust.

How Internal Audit Can Help

Internal audit can provide an independent assessment of whether duties, system access, approval authority, and monitoring controls are appropriately designed.

A segregation-of-duties review may include:

  1. Mapping critical business processes and responsibilities;
  2. Identifying incompatible duties;
  3. Reviewing system access and authorisation levels;
  4. Testing approval and reconciliation controls;
  5. Assessing management override and emergency access;
  6. Evaluating compensating controls;
  7. Investigating unusual access combinations; and
  8. Recommending practical improvements based on the organisation’s size and resources.

An effective review should not simply produce a list of access conflicts. It should distinguish between theoretical conflicts and actual business risks.

For example, an employee may technically possess conflicting system permissions but may not use both permissions in practice. Conversely, a process may appear adequately segregated on paper while employees share passwords or routinely approve transactions without meaningful review.

Internal audit must therefore evaluate both system design and actual behaviour.

The Right Balance Between Trust and Control

Strong organisations do not choose between trusting employees and implementing controls.

They do both.

Management should build a culture of integrity, hire trustworthy people, and maintain strong working relationships. At the same time, it should establish clear accountability, independent review, transparent approval processes, and appropriate access restrictions.

Segregation of duties does not weaken trust. It makes trust sustainable.

When responsibilities are appropriately separated, the organisation is less dependent on individuals, employees are better protected, and management receives more reliable information.

The key question is not:

“Do we trust this employee?”

The better question is:

“Would our controls still protect the organisation if an error, conflict, pressure, or unexpected event occurred?”

At Arbor Thailand, we support organisations in evaluating internal controls, segregation of duties, system access, fraud risks, and governance arrangements. A focused internal control or segregation-of-duties review can help management identify hidden vulnerabilities before they result in financial loss, operational disruption, or reputational damage.

Employee loyalty is an asset. Segregation of duties is protection. A resilient organisation needs both.

#InternalAudit #SegregationOfDuties #InternalControls #FraudRisk #RiskManagement #CorporateGovernance #AuditCommittee #BusinessResilience #ArborThailand #Governance

5 Common Accounting Mistakes Thai SMEs Should Avoid