Why "we trust each other" stops being a control
At two people, trust works fine - you both see everything. Past that, nobody sees everything anymore, and "trust" quietly becomes "hope nothing goes wrong." Financial controls aren’t an accusation that someone will steal from the business - most control failures are honest mistakes, not fraud. But the two look identical from the outside until you have a system that catches both.
Segregation of duties: the core idea
The principle is simple: no single person should be able to both initiate a financial action and be the only one who confirms it happened correctly. Applied well, it doesn’t mean slower work for everyone - it means the specific handful of actions that move money have a second set of eyes, while everyday work stays fast.
| Role | Can do | Shouldn’t also be the one who |
|---|---|---|
| Requester | Create a bill or purchase order | Approve their own request |
| Approver | Approve requests within their limit | Also process the resulting payment unsupervised |
| Payment processor | Execute an approved payment | Approve the request that authorized it |
| Reconciler | Match bank activity against records | Have created or approved the transactions being reconciled |
A simple segregation-of-duties split
Maker-checker: the simplest real control
Maker-checker means exactly what it sounds like: one person creates ("makes") a transaction, and a different person reviews and approves ("checks") it before it takes effect. It’s the single highest-leverage control a growing business can add, because it catches both categories of problem at once - genuine fraud attempts, and the far more common case of an honest typo or duplicate entry.
What it catches in practice
A vendor bill entered for $45,000 instead of $4,500 sails through unnoticed in a one-person workflow. A checker reviewing it against the original invoice catches it before payment goes out - not after, when getting the money back becomes a very different conversation.
Spending limits, not blanket permission
The alternative to "everyone can approve anything" isn’t "only the owner can approve anything" - that just moves the bottleneck without fixing the risk. Per-role or per-person approval limits let most day-to-day spending move fast while anything above a threshold automatically requires a second (or third) approver.
Set limits by role, review them quarterly
A limit that made sense at 10 employees is often wrong at 40. Revisit approval thresholds as the business and its typical transaction sizes grow - a stale limit either bottlenecks routine spending or stops meaning anything.
Scoping access for multi-branch or multi-warehouse teams
A team spread across multiple branches, warehouses, or regions adds a second dimension to access control beyond "what can this role do" - namely "where can this person do it." A warehouse manager approving inventory adjustments for a location they don’t work at is either a data-entry mistake or worth investigating; scoping roles to specific locations prevents the first case entirely and makes the second easy to spot.
The audit trail: your only real answer to "who did this, and when"
Controls prevent most problems; an audit trail is what lets you actually investigate the ones that get through. Without one, "who changed this invoice" is a question you answer by asking around and hoping someone remembers. With one, it’s a lookup.
What a real audit trail should capture
- Who performed the action - a real identity, not a shared login
- What changed - the before and after values, not just "record updated"
- When it happened - a timestamp you can trust, not a self-reported date
- What triggered it - manual entry, an approval, an automated process
- Whether it can be edited or deleted after the fact - it shouldn’t be
Right-sizing controls: a 3-person team vs. a 30-person team
The same principles, different weight
Small team (2–10 people)
- One or two approval tiers is usually enough
- A single shared spending limit above which the owner reviews personally
- Focus on catching mistakes - fraud risk is lower with full visibility
Growing team (30+ people)
- Role-based limits, tiered by seniority
- Location or department scoping becomes necessary, not optional
- A real audit trail stops being optional - nobody sees everything anymore
Isn’t maker-checker just bureaucracy that slows everyone down?
Applied to every single action, yes. Applied only to the transactions that actually move money above a sensible threshold, it adds seconds to the few things that matter and nothing to everything else.
What’s the minimum viable control setup for a very small team?
At minimum: nobody approves their own requests, there’s one spending threshold above which a second person signs off, and every change to a financial record is logged with who and when. That alone catches the majority of honest mistakes.
Do these controls only matter for preventing fraud?
No - in most small and mid-sized businesses, the controls above catch far more honest errors (duplicate bills, typo’d amounts, wrong vendor) than actual fraud. Preventing fraud is a real benefit, but it’s not the main day-to-day payoff.
Controls aren’t there because you don’t trust your team. They’re there because "trust me" doesn’t scale past the number of people who can see everything.
Resources
Was this guide helpful?