Why Segregation of Duties is Essential for Internal Control

by Samantha Schmitt, CPA, Withum – September 23, 2024
Why Segregation of Duties is Essential for Internal Control

The foundation for having optimal performance and reduction of risks is to ensure that there are adequate internal controls. These are processes designed to provide reasonable assurance about the achievement of the company’s objectives with regard to the reliability of financial reporting, effectiveness and efficiency of operations, and compliance with laws and regulations. Segregation of duties is a key internal control that involves assigning responsibilities to more than one individual so that no single individual has sole control over an entire process. As such, no single individual can initiate, authorize, record and review a transaction without the involvement of another individual. Proper segregation of duties is key to ensuring critical safeguards over internal controls and minimizes the risk of errors, conflicts of interest, theft and fraudulent activity. Although segregation of duties can cause bottlenecks and lead to inefficiencies, it is a best practice and prevents bigger issues from arising.

COSO Framework

The COSO (Committee of Sponsoring Organizations) framework is a set of guidelines for companies to implement internal controls to manage, prevent and detect fraud risk. There are five components of the COSO framework:

  • Control environment — sets the tone of the company and its employees and includes the integrity, ethical values and management’s attitude and operating style.
  • Risk assessment — the identification of relevant risks within a company and how those risks should be managed to achieve the company’s objectives.
  • Control activities — the policies and procedures enforced to ensure management directives are implemented.
  • Information and communication — relevant and significant information must be identified, captured and communicated in a timely manner to internal parties, such as management, and external parties, such as vendors.
  • Monitoring activities — internal controls should be continuously monitored to assess whether they are working effectively.

Implementation

There are two steps to implementing segregation of duties. The first step is to establish and create policies and procedures for each department. Management should determine what key controls are relevant and significant to the company to ensure proper safeguards. Creating a standard operating procedure (SOP) on the processes and controls will allow all individuals to understand the necessary responsibilities by department and by individual. When creating the SOP, management should build a segregation of duties matrix, listing out all the responsibilities by department and by individual to properly ensure there are no conflicts where individuals have access to several different areas.

The second step is to monitor and manage how it is functioning. Management should periodically monitor how the departments are operating with these procedures and oversee whether the segre­gation of duties is being implemented and maintained. If controls are not effectively working, management should determine the root cause and find a solution.

Common Examples

Some common examples of proper segregation of duties include the following:

  • Cash receipts and revenue process: No single individual should have the ability to collect, deposit, record and reconcile cash receipts. The individual collecting and recording the cash receipts should not be the same indi­vidual who is making the deposit to the bank. Another individual (who is independent of the individuals who are collecting and recording and depositing the cash receipt) should reconcile the deposit to the general ledger through bank reconciliations, and another separate individual should review the reconciliation.
  • Purchasing process: The individual initiating a purchase order for goods should not be the same individual approving the purchase. The individual approving the purchase of the goods should not be the same individual who initiates payment for those goods. Additionally, the individual initiating the payment for the goods should not be the same individual with custody of the checks.
  • IT systems: Individuals should have the appropriate access to systems and the level of access given (e.g., review only, super admin) should be commensurate with their respective job responsibilities.

Companies should regularly evaluate which controls are the most critical and the key areas in which there should be proper segregation of duties including the authorization of transactions, custody of assets and reconciling/reviewing of transactions. All in all, proper segregation of duties helps ensure errors, whether unintentional or intentional, are detected by another individual. 


Samytha Schmitt

Samantha Schmitt, CPA, is a member of the NJCPA.

More content by Samytha Schmitt:

 

 

Related events

January 16, 2025Paramus
January 17, 2025Red Bank & Live Webcast
January 17, 2025Webcast Replay
January 22, 2025Live Webcast
January 23, 2025Webcast Replay
January 23, 2025Live Webcast
January 23, 2025Live Webcast
January 31, 2025Webcast Replay
February 5, 2025Linwood
Atlantic/Cape May Chapter
Federal & State Tax Update
February 6, 2025Paramus
Bergen Chapter
Special Topics
February 6, 2025Haddonfield
Southwest Jersey Chapter
Technology Update
February 12, 2025Live Webcast
February 19, 2025Live Webcast
February 24, 2025Webcast Replay
February 25, 2025Live Webcast
March 4, 2025Webcast Replay
March 19, 2025Live Webcast
March 20, 2025Live Webcast
March 27, 2025Live Webcast
April 16, 2025Live Webcast
April 21, 2025Live Webcast
April 22, 2025Clark
April 25, 2025Roseland
April 25, 2025Live Webcast
April 29, 2025Webcast Replay
May 1, 2025Webcast Replay
May 6, 2025Live Webcast
May 7, 2025Northfield
Atlantic/Cape May Chapter
Estate Planning
May 8, 2025Haddonfield
Southwest Jersey Chapter
Nonprofit Update
May 9, 2025Live Webcast
May 16, 2025Webcast Replay
May 20, 2025E. Brunswick
Middlesex/Somerset Chapter
New Jersey Law and Ethics
May 21, 2025Live Webcast
June 3 - 6, 2025Atlantic City
June 25, 2025Live Webcast
July 23, 2025Live Webcast
August 5, 2025Live Webcast
August 13, 2025Live Webcast
August 18 - 20, 2025Atlantic City
August 26, 2025Live Webcast
September 17, 2025Live Webcast
October 22, 2025Live Webcast
October 29, 2025Live Webcast
November 4, 2025Live Webcast
November 13, 2025Live Webcast
November 19, 2025Live Webcast
November 19, 2025Live Webcast
December 3, 2025Live Webcast
December 11, 2025Live Webcast
December 17, 2025Live Webcast
January 6, 2026Live Webcast
February 4, 2026Live Webcast
March 8, 2026Live Webcast