Segregation of Duties (SOD): The Golden Rule for Preventing Employee Fraud

Segregation of duties in financial management for preventing employee fraud

Introduction

Financial fraud doesn’t usually need high tech tools or a large scale criminal organization. In many companies what opens the door to fraud is one person having too much control over the financial processes. An employee who is able to add a new supplier, okay an invoice, issue a payment, and do bank reconciliation may have the access which enables him to carry out an improper transaction for months. This is when the concept of segregation of duties comes into play. Segregation of duties which we also refer to as SOD is very important in internal control and financial management. SOD requires that organizations break up key functions between different people so no one person has end to end control of a transaction. When done right SOD deters fraud, makes it easier to spot errors, improves accountability and also puts in place an extra layer of protection for company assets and financial info.

What Is Segregation of Duties?

The issue at hand is that which employee does a transaction should not be the which does also approve of it, record it, manage related assets, or do an independent check of the results out. For example in a purchase process one employee may put in the request for goods, a different one may approve the purchase, another may receive the goods, and a separate accounting employee may record the invoice and see to payment. By separating out these actions we create a system of checks and balances. Also if an employee tries to put through an unauthorized purchase there is another employee in place to question or reject it. Also should an error happen independent review is more likely to catch it before it causes large scale financial damage.

The role of SOD is made more apparent when we look at what may transpire should a single individual have full charge of the finance process. Picture a case in which a staff member can set up suppliers, post purchase invoices, issue payments, use the company’s bank account, and also do transaction reconciliations. In that scenario the employee could put out fake suppliers, submit false invoices, go ahead with the payments, move funds around, and at the same time alter records to present those transactions as legitimate. Also, even if the employee is a trustworthy one, putting in such large roles for a single person brings out great risk that of which simple errors go unchallenged as they work their way through the whole process. What SOD does is present a solution for both intentional misdoings and also accidental mistakes. It is not based on the idea that our staffs are out to do us in; rather that very best internal controls do not rest on that trust. A well thought out system which puts in place the right structures will see to it that our key financial functions are looked at by independent parties.

Four Main Roles in Segregation of Duties

Authorization which includes to approve transactions or to decide which actions should take place, Custody which is in charge of physical or electronic care of assets like cash, inventory, payment instruments or valuable documents, recording which consists of putting transactions into the accounting systems and maintaining financial records, Reconciliation and review which is to compare records against independent sources and look into differences. In the best control environment no single person has all four roles. For example the person which has the cash may not also be the one which reconciles the cash records. Also the person which inputs payroll changes should not have full authority to approve those changes and release the payroll payment.

The main reason we divide responsibilities is to put in place a control structure which in general terms requires more than one person to go along with improper action. This in turn greatly increases the issue and the fact of fraud. Take for instance a simple procurement transaction. An employee may have a valid business case for wanting office equipment but does not in fact require they be the one to choose the supplier, to put in the purchase order, receive the equipment, put in the invoice, or to go ahead with payment out. Each additional separate step introduces a check. In the procurement example a manager may look at what is asked for, accounts will check what was ordered against what was received, and finance will check the payment out. Also these controls serve to increase the operational accuracy as it is more likely that errors will be found out when the steps of a transaction are separated between different people.

Four roles of segregation of duties: authorization, custody, recording, and reconciliation

Why not have one Person in Charge of a whole Financial Process.

Giving out total responsibility to one employee in a financial process we see at times to be what is known as a control concentration risk. That is not to say the issue is just that the employee may be a thief. What also happens is that the employee may put in transactions, change supporting info, and cover up what they did. For example an employee who handles all of accounts payable and the bank reconciliation may run a payment which is not authorized and then not report it during the reconciliation. Also an employee that does payroll data input and also does payroll approval may add in a fake employee and pay out salaries to that person. When the same person has charge of the employee mainframe, payroll processing and payment release the issue is magnified. By separating out these roles what happens is that one person’s work is reviewed by another which in turn makes it less likely for unauthorized action to go through and also makes it hard to cover up.

SOD also puts in place for organizations what is at times a forgotten element in fraud prevention. Employees may make input errors with bank info, calculation of amounts, choice of suppliers, processing of payroll changes, or reporting of accounting transactions. If the same employee does all of the steps in a process that SOD breaks up into many steps, an error may go by the wayside as there is no one else to check the work. A second person looking over the transaction can see out of place numbers, repeat payments, unusual vendors, lack of documentation, or that which is inconsistent before it snowballs into a bigger issue. Also, SOD does not play out only in the field of fraud prevention. It improves the quality of the financial info we put out there, strengthens accountability, and gets employees to fall in line with what is asked of them. In this sense, SOD is more than just a security measure; it is a core element of good financial management.

Implementing Segregation of Duties in Payroll

Payroll is a very key area for SOD as it includes repeat transactions, very private employee info, and access to company funds. We see that which a robust payroll controls system which divides out responsibility between employee data management, payroll preparation, payroll approval, payment processing, and reconciliation. For instance the human resources department may handle what is a real employee’s start and end dates, changes in salary, and other personnel files. A payroll officer may use that approved info to put together the payroll which in the meantime a manager or finance head will go over the payroll report before payment is made. After payment is made yet another employee does the payroll register with the bank statement and general ledger. This structure greatly reduces the chance of a single person creating a fake employee, blowing out a salary without permission, or shifting payments without notice.

Organizations should also focus on access controls in payroll systems. We see that duty segregation breaks down when an employee has what is meant to be a pay roll preparation role but at the same time is able to change employee records, approve their own changes, and run payment out through open access to the system. Access should instead be given out based on job function, what is really required to get the job done. Also we should see that employees have only the access they need. As for changes to employee bank info, salary, tax info, or employment status we should have supportable documentation for them and where we can have independent review. We also should be looking at pay roll reports for atypical changes, duplicate bank accounts, payments to terminated employees, unexpected salary hikes and other anomalies. Also we should be doing regular reconciliation between pay roll records, account records, and bank transactions which adds another layer of protection.

Segregation of Duties in Procurement

Procurement is also a field in which SOD has great success in reducing fraud. In a typical procurement process we see that which goes into it a need is identified, a purchase is requested, a supplier is chosen, the purchase is approved, we have the goods or services received, the invoice is verified, the liability is recorded, and payment is made out. These should not all be under one person’s control, for instance a department employee may put out the request for what is needed as he or she is closest to the operation. At the same time an authorized manager will look at the purchase and give the go ahead. A procurement person may be the one to do the supplier research and issue the purchase order, a receiving person will confirm that what was ordered was what was delivered, and an accounts payable person will check out the invoice before payment is made. By this division we see many independent checks which in turn make it harder for unauthorized purchases and fake transactions to go through.

In many cases we see that which is very useful in procurement is the three way match system in which accounting looks at the purchase order, the receipt documentation, and the supplier invoice before payment is made. The purchase order details what was authorized, the receipt report what was in fact delivered, and the invoice what the supplier is to be paid. Should one person be in charge of all three records there is great opportunity for manipulation. But when functions are separated it is easier to see irregularities. For example accounting may find that an invoice reports ten items were delivered when in fact the receipt report shows only six. In which case a review can then be done before the company’s money leaves. Also companies should put in place approval tiers so that large purchases get extra management review as opposed to being left to the decision of a single employee.

Segregation of Duties in Cash Handling

Cash has very strong control requirements as it is very liquid and at the same time easy to lose trace of when put to unauthorized use. In which we see businesses that handle physical cash also separate the functions which handle and hold cash from the record transactions and reconcile cash balances. For instance a cashier which may collect customer payments and issue receipts, and an accountant which records the transaction and also a different person which does the independent reconciliation of the cash register with the account records and bank deposits. At the end of a shift or business day the cash is counted out and checked against what we are to expect in terms of receipts, which large variances are looked into and documented. Such controls create a trail for auditors and also dissuade a staff member from removing cash and at the same time make it hard for them to also alter the records to cover up the loss.

The same holds true for electronic cash and for bank transactions. As it stands now employees that put together payment instructions do not have to be the same that authorizing payments or reconciling bank accounts. We should see bank access given out according to job functions and also that payment approvals go through as far as the documented authorization goes. Also we should see regular bank reconciliations done by someone other than the one which did the initial transaction or which approved it. Also included in this is that businesses should watch out for atypical transfers, repeat payments, out of the blue beneficiaries, and transactions which do not fit in with what is usual. Also where it is practical we can see a dual approval for large scale payments so that one person isn’t the sole agent in moving large sums of money. These are of great value to small and medium sized businesses in which financial losses may greatly affect the go of the company and cash flow.

How SOD Plays a Role in Deterring Fraud and Collusion.

One of the primary benefits of segregation of duties is that it decreases the chance that a single employee will carry out and cover up fraud. Generally fraud needs an opportunity, and in depth access can present that chance. By separating roles, we see that an employee who tries to abuse company resources will run into another employee who has to approve, verify, record, or sort out the transaction. This does not do away with fraud totally, but does increase the issue of performing it successfully and at the same time increases the chances of it being detected. SOD also plays a role in a total fraud risk management system which includes management oversight, approval controls, reconciliation, audit procedures, access restrictions, whistle blower policies, and regular review. The goal is not to foster a culture of distrust but to put in place systems which make improper action hard to carry out and easy to identify.

However, we see that which issues of duty separation are not resolved by full elimination of the risk of collusion. In some cases what we have is two or more staff working in concert to get past controls especially when they have joint access or influence over different elements of a process. Also it is important for organizations not to put all their faith in SOD as a fraud prevention solution. We see that independent audits, management reviews, data analysis, exception reports, and surprise checks can play a very important role also. For instance, while purchase and accountabilities may be separated, management still may look at supplier data for duplicate addresses, at atypical payment trends, or at transactions which are just under the approval threshold. By combining SOD with independent monitoring we see that we create a stronger control environment in which staff can’t count on the fact that collusive effort will always pay off. Also we note that which out of duty separation is but a piece of the puzzle.

How SOD Reduces Human Error

Fraud deterrence is but one issue which organizations should pay attention to when they put in place segregation of duties. Also the practice of separating duties improves the accuracy and the dependability of business processes. When separate individuals are charged with carrying out a transaction and its review the second party may bring to light errors the first did not. This is very much the case in areas like payroll, accounts payable, inventory management, tax reporting, and financial close which see a small error go on to affect many records. Independent review brings in a fresh set of eyes which in turn creates a structure for error correction. For example an employee may put in 500,000 instead of 50,000 in a payment request. If that same employee also has go ahead authority to release the payment to the bank that error may go through. But if a separate employee has the duty to review and approve the transaction that atypical amount is more likely to be brought to question.

SOD also has the effect of getting employees to maintain better records which is a result of transactions being passed between many people and stages of a process. When employees know that their work is going to be looked at by another person they are more likely to include support documentation, to go through the approval processes, and to put forth explanations for out of the ordinary transactions. This in turn improves the organization’s audit trail which in turn makes it easier to do an investigation when something does go wrong. Also a strong control environment should present SOD as both a preventive and detective measure. That is to say certain employees are kept from too great authority which at the same time increases the chance that errors or unauthorized actions will be detected. The result is a more reliable financial process in which responsibilities are clearly defined and important decisions are put under the right level of review.

Implementing SOD in Small Businesses

Large enterprises will see that their staff base is sufficient for individual responsibilities but in the case of small businesses they often find that it is not practical at all. A small firm may have one finance manager, one admin assistant, and also the role of business owner, which means that full separation isn’t possible. Also true is the fact that this doesn’t mean that Separation of Duties (SOD) should be given up. In fact small organizations can use compensating controls instead. For example the owner can do the bank statement and payroll report reviews, approve major issues, get into the evaluation of new suppliers, and check out irregular transactions as one employee fulfills many functions in accounting. What is key is the fact that the individual processing of finance transactions must not have total control at every step out which there is no outside input.

Technology also has a role in what we see in smaller organizations in terms of the implementation of the concept of segregated duties. In most accounting and enterprise scale systems which businesses use there is the option to put in place diverse user roles, approval processes, and access permissions. A finance person may put together a payment without also having the go ahead to OK it and at the same time a manager is able to OK the payment but not to change that payment’s info. Also we see that automated alerts are put in for managers regarding large out of the blue transactions, changes to supplier information, or changes to payroll info. Also it is also a good idea to do regular access reviews because staff roles change and they may end up with different permissions then what is required. SOD should be a living breathing thing and not a onetime event. As transaction volume, staff levels, and technology based systems change management should reevaluate if present responsibilities still provide the needed level of control.

Common Issues in Segregation of Duties Implementation

One issue we see is that between the lines there’s a failure to separate out job roles in actuality from system level permission structure. For example a company will have the accounts payable and also the purchase teams reported as separated out but they in fact have full run of the same systems. The put forth separation is perhaps not what it seems. Also a lot of times the review process for those who have privileged access is missed, in particular the system admins who by design have the ability to go around the normal rules. What we find is that companies don’t have a very clear picture of who has what in terms of input into the system who can add new vendors, changing bank info, enter in the invoices, OK the payments, do the payroll, change personnel info and balance the books. Also not enough time is spent to see if these access sets together create an issue. Also very often employees are allowed to do the approval of their own transactions or which pertain to very close friends or family. That which we see is the policies should be very clear on this point and also to have a set of procedures for when conflicts do come up.

Businesses also should stay away from controls which are needlessly complex or which employees are unable to live up to on a regular basis. An effective SOD structure should fit the organization size, risk profile, transaction volume, technology, and staff setup. If a control calls for five separate approvals for each small scale purchase, employees may start to go around the system because it is too great a burden. Instead we see to it that there is a risk based approach to control design in which large value or high risk transactions get more review and out of the routine low risk activities we put in place simpler procedures. Also management should put in place a program of which the controls which are in place are really working as they are supposed to. Internal audit, management’s own tests, exception reports, and transaction sampling will tell us if employees are in fact following what is put forth or if we have developed workarounds which are in fact breaking down the control structure.

Creating an Effective SOD Framework

In the first place it is up to management to map out key business processes from start to finish in the design of a strong segregation of duties framework. Management should put forth to determine which roles initiate, approve, process, record, hold, and review each type of transaction. Also, we see that it is a task of management to identify which functions should not usually be performed by the same person. For example authorization and payment release may be best kept separate as may cash custody and bank reconciliation. Also we recommend that organizations put in place policies, procedures, job descriptions, and system access rules which document these responsibilities. A responsibility matrix may be what makes the structure of SOD easy to see which employees or which departments perform each stage. Also management should put in place what we term compensating controls where full segregation is not possible. This approach turns SOD from a broad principle into a practical control which employees may follow.

After implementation it is up to organizations to constantly review the performance of their SOD framework. Employee turnover, promotions, organizational restructurings, introduction of new accounting software, acquisitions and changes in business operations may bring about new issues. To that end access rights should be reviewed regularly which is better than only at the time of a control failure. Managers should look into unusual transactions and exceptions which may require investigation as opposed to going ahead and approving them. Also it is the role of internal auditors to determine if incompatible functions are being performed by the same person and that system permissions are in fact what is put forth in the job descriptions. When we find out what the weaknesses are they should be fixed right away and we should also look at past transactions to see if they also were affected. Continuous monitoring is essential to the growth of the organization and as financial processes become more complex.

Conclusion

Segregated roles is a basic element of internal control which puts up that one person doesn’t have total control over a full financial transaction. By which we mean to say that through putting authorization, safe keeping, record keeping, and reconciliation functions in different hands we see to it that organizations put in place what we may term as a system of checks and balances which in turn reduces the chance of fraud and at the same time improves the chance that errors will be found out and put right. Payroll, procurement and cash management are very key areas for Segregation of Duty because they have to do with access to company funds, very private info, or large assets. While full Separation may be a challenge for small companies, we see to it that which we put in place are what we may term as compensating controls such as owner review, independent reconciliation, set approval limits, system access restrictions and regular audits which do in fact provide good enough protection. At the end of the day Segregation of Duty is not a sign of a lack of trust in our people. It is a professional way of risk management that which protects our people and our organizations. When roles are properly broken up and supported by independent review we see that businesses are able to put in a better financial control system, reduce fraud chances, improve report accuracy and in the process build greater trust in the integrity of their operations.

Get more well researched information about Segregation of Duties here.

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
0
Would love your thoughts, please comment.x
()
x