Segregation Of DutiesChurch Extension FundsInternal ControlsFinancial ComplianceCEFCore

What Is Segregation of Duties: A Church Funds Guide

By 13 min read
What Is Segregation of Duties: A Church Funds Guide

A loan disbursement is ready to go. The investor note has been issued. The general ledger entry is waiting, and the bank reconciliation is due before month-end. On a small Church Extension Fund team, the same employee may touch several of those steps because that person knows the process and has the system access. Nothing improper may be happening, yet the arrangement can still leave the fund unable to prove that transactions were independently authorized, recorded, and reviewed.

That's the practical starting point for what is segregation of duties. It's a control design that divides high-risk work so one person can't initiate, approve, record, and conceal the same transaction from beginning to end. For a CEF balancing affordable church lending with investor protection, SoD supports reliable reporting, cleaner audits, and confidence in the stewardship of entrusted funds.

The Hidden Cost of Unchecked Access

A small CEF team may assign loan setup, construction-draw processing, payment posting, and reconciliation to one experienced employee. The arrangement works until a borrower's draw is entered for the wrong amount, an investor note is posted to the wrong account, or a transaction is adjusted after the supporting documentation has been filed. If the same person can approve the change and reconcile the resulting balance, the error may remain undiscovered until an audit or investor inquiry exposes it.

The concern isn't that employees are presumed dishonest. Internal controls exist because capable people make mistakes, responsibilities change, and unchecked access can be misused. The purpose of SoD is to ensure that no employee can both perpetrate and conceal an error or fraud through the normal course of work. The core incompatible functions are authorization, custody of assets, recording transactions, and reconciliation or other control activity, as described in operational internal controls guidance from the University of Pennsylvania.

A stressed man sitting at a desk overflowing with financial documents and papers while looking at paperwork.

Where the exposure appears

Consider a typical lending and investor cycle:

  • Loan disbursement: A loan officer prepares a construction draw, approves it, releases funds, and posts the accounting entry.
  • Investor notes: A staff member opens the note, receives the funds, records the liability, and prepares the investor statement.
  • Cash operations: A treasury employee initiates an ACH transaction and later performs the bank reconciliation.
  • General ledger: The person who posts a manual journal entry also reviews the subledger balance that should validate it.

Each workflow contains a point where another person should provide an independent check. Without that check, an incorrect borrower balance can affect interest accrual, cash reporting, investor statements, and financial reporting at the same time.

Why auditors notice

Audit readiness depends on more than producing a report. Auditors need evidence that the person who performed a control was authorized to do so, that the reviewer was independent, and that the record wasn't altered without detection. A spreadsheet with an approval column may show that someone typed “approved,” but it may not establish who approved the transaction, when the approval occurred, or whether the approver could also change the underlying record.

For CEF leaders, the hidden cost is therefore broader than a possible loss. Weak SoD can create unreliable financial information, longer audit preparation, unresolved investor questions, and avoidable pressure on a mission-focused staff. A useful companion resource for considering these connected exposures is Blocsys Technologies' risk management guidance, particularly when financial controls depend on technology and user access.

Understanding Core Segregation of Duties

The clearest way to understand SoD is to examine the four functions that appear in a high-risk transaction. A practical rule used in control design is that one person should perform no more than two of the four core functions, with three people ideally covering the four functions, according to the COSO discussion summarized by KnowledgeLeader's COSO overview.

A diagram illustrating the four core segregation of duties functions: authorization, custody, recordkeeping, and reconciliation.

The four functions in a CEF workflow

Function What it means CEF example
Authorization Deciding that a transaction is permitted Approving a loan draw or investor-note issuance
Custody Controlling the asset or payment mechanism Accessing operating cash or releasing an ACH
Recordkeeping Entering and maintaining the official record Posting the loan, note, cash, or journal entry
Reconciliation Comparing records and investigating differences Matching bank activity to the cash ledger

Authorization answers, “Should this happen?” A lending manager may approve a draw after confirming the borrower's request and documentation. That manager shouldn't also be the person who releases the funds and posts the final accounting entry.

Custody answers, “Who controls the asset?” In a CEF, custody can involve cash, payment credentials, investor funds, or access to a system that can move money. NIST gives the simple example that the person authorizing a paycheck shouldn't also be able to prepare it, because the combination gives one user excessive control. Its guidance on separation of duty also distinguishes between preventing conflicting roles from being assigned and enforcing separation when a user attempts an action.

Recordkeeping creates the evidence. The employee who prepares a note issuance or posts a borrower payment should work from approved documentation and shouldn't be able to approve their own entry. Reconciliation then provides the independent challenge. A reviewer compares the bank, subledger, investor, and general ledger records, investigates exceptions, and documents resolution.

Translating the principle into access

A written policy won't protect a process if the system grants broad permissions. Role-based access should reflect actual responsibilities, not seniority or convenience. A treasury role may initiate payments, while a separate authorized reviewer approves them. A staff role may enter data but not change approval rules or delete audit history.

For practical guidance on designing permissions around responsibilities, see role-based access control best practices. The strongest design combines policy, system permissions, workflow approval, and evidence of review. If any one of those pieces is missing, the organization may have separation on paper without separation in practice.

Why Segregation of Duties Matters for Church Extension Funds

A CEF can have accurate policies and still expose investor funds if one employee controls too much of a transaction. The fund receives investments from individuals and congregations, lends those resources to churches, maintains borrower and investor records, calculates interest, manages cash, and reports financial activity. A failure in any connected process can affect investors who entrusted the organization with savings, churches waiting for funding, and boards accountable for stewardship.

The control principle has a long place in financial governance. COSO issued its original Internal Control, Integrated Framework in 1992, updated the framework in January 2013, and addresses the issue in Principle 10. Management should separate incompatible duties and use alternative control activities when a small team cannot divide them fully. That approach supports reliable financial reporting, audit readiness, and SOX-style compliance, even when a CEF operates under state securities requirements rather than federal deposit insurance.

The evidence points to a recurring weakness

Quantitative evidence explains why auditors continue to examine SoD. In fiscal year 2016, 1,234 management-only filers, or 36.9%, reported ineffective internal controls, and 860 of those filers, or 70%, specifically cited segregation-of-duties weaknesses, according to the research record available through NSF PAR. The concentration identifies SoD as a recurring source of financial reporting breakdowns.

The same source references an operational risk finding: organizations with strong SoD controls detected fraud 50% faster than organizations without them. For a CEF, that means separation can limit both the opportunity to misappropriate funds and the time an irregularity remains hidden. Early detection also preserves records and gives management a better chance to investigate and correct the issue.

Trust is part of the control objective

A CEF control failure affects more than a financial statement. Investors expect accurate statements and timely tax reporting. Borrowers depend on correct loan balances, payment applications, and construction draws. Boards expect management to protect restricted processes without burdening a small, mission-driven staff with unnecessary approvals.

State securities laws, IRS reporting requirements, and GAAP-based financial reporting all depend on reliable underlying records. A policy alone does not meet those obligations. The fund must show that transactions had supporting documentation, approvals came from authorized personnel, records were complete, and exceptions received independent review.

Small teams may need compensating controls, such as board oversight, scheduled reconciliations, or documented post-transaction review. The objective is workable risk reduction, not a large-bank staffing model.

Board-level test: Ask whether one user can move money, change the related record, and certify the result. If yes, the control design needs attention.

Common Segregation of Duties Patterns and Risks

CEF risk often appears in familiar combinations rather than dramatic policy violations. A loan officer may originate and approve a loan because that person knows the borrower best. A treasurer may receive cash, post receipts, and reconcile the bank because the team has limited coverage. A system administrator may grant access, change workflow rules, and review the logs that record those changes.

The right response isn't to force every organization into a large-bank staffing model. It's to identify which combinations create the greatest exposure and decide where a second person, technical restriction, or independent review can reduce it.

Common patterns side by side

Workflow Risky combination More defensible arrangement
Loan origination One employee structures, approves, and records the loan Originator prepares, lending authority approves, accounting records
Construction draws One employee validates documentation and releases funds Operations verifies support, authorized approver releases payment
Investor notes One employee opens the note, receives funds, and reconciles the liability Note staff records issuance, treasury confirms funds, accounting reconciles
Cash management One employee initiates payments and performs the bank reconciliation Treasury initiates, separate reviewer approves, accounting reconciles
System administration One administrator assigns access and changes audit settings Access owner approves, administrator provisions, independent reviewer checks

NIST describes static separation as preventing a user from holding conflicting roles. Dynamic separation enforces the control when the user attempts to perform an action. Both matter. Static design prevents role accumulation, while dynamic enforcement can stop a transaction even when a user's permissions have become too broad.

The cloud boundary problem

A user may appear properly separated inside the loan system while holding conflicting permissions across identity management, privileged-access management, and SaaS administration tools. That creates an architectural SoD failure. Each application can look controlled on its own, yet one person may still be able to approve a request in one system, alter the supporting record in another, and administer the access that makes both actions possible.

This cross-application issue deserves a process-level review, not only an application-level review. Modernizing segregation of duties provides useful context for finance and internal audit leaders assessing conflicts across cloud workflows.

For related fraud-control considerations, the explanation of what is forensic accounting can help board members understand how transaction evidence is examined after an irregularity. Preventive SoD should come first, but a clear audit trail supports investigation when something still goes wrong. CEF teams can also use fraud risk controls for CEF operations to identify warning signs in lending, investor, and cash processes.

Practical Policies and CEFCore Control Mappings

A workable SoD policy starts with the transaction, not the software menu. List the actions that can create financial exposure, assign each action to one of the four core functions, and identify where the same user currently performs conflicting work. Then define the approval, exception, and evidence requirements in language employees can follow.

A policy for construction draws might read: “The employee preparing a draw may not approve or release the draw. The approver must review supporting documentation and approve through a recorded workflow. Any emergency release requires documented management review and post-transaction reconciliation.” That statement is more useful than a general requirement to “maintain adequate internal controls.”

A diagram illustrating the four-step mapping process from a policy requirement to an audit trail.

Map the policy to the operating process

Use a simple four-part mapping:

  1. Policy requirement: Define the prohibited combination, such as preparation and approval of a disbursement.
  2. Assigned role: Give preparation and approval to different users or role groups.
  3. Workflow action: Require the second user to approve before funds can be released.
  4. Evidence: Preserve the request, approval identity, timestamp, changes, and reconciliation result.

A purpose-built platform such as CEFCore can support this model with granular role-based permissions, maker-checker approvals for high-risk transactions, and immutable audit trails across loan, investor, cash, and ledger workflows. The same mapping can be built with other systems, provided the organization can restrict access and produce reliable evidence.

Compensating controls for lean teams

Perfect separation may not be feasible in a small finance department. Guidance on ISO 27001 control 5.3 and compensating measures notes that full separation is often difficult in teams under 20 and that organizations need alternative safeguards. Those safeguards should be specific:

  • Independent review: A board treasurer, executive director, or external accountant reviews high-risk transactions and supporting documentation.
  • Enhanced logging: Preserve system and bank activity so management can examine every action by the employee with combined duties.
  • Dual authorization: Require two authorized people for fund movements or sensitive changes.
  • Post-use review: Examine break-glass access after the emergency and document the reason, duration, actions, and resolution.
  • Reconciliation: Ensure someone independent of transaction preparation reviews the resulting balances.

For a broader framework for documenting ownership, control objectives, and evidence, use this internal controls framework for CEF organizations. A finance governance overview such as DevArmor's fintech GRC overview can also help connect financial controls with technology, risk, and compliance responsibilities.

Building a Sustainable SoD Culture

Segregation of duties becomes sustainable when employees understand it as a protection for the mission, not an accusation. A loan operations employee shouldn't feel distrusted because another person approves a draw. The approval protects the borrower, the fund, the investor, and the employee who prepared the transaction.

The control should also survive vacations, turnover, role changes, and urgent requests. A process that works only when one experienced employee is present isn't a control system. It's institutional memory with a single point of failure.

A diverse team of professionals collaborating and brainstorming ideas during a business meeting in an office.

A practical review rhythm

Start with the processes that can move money or change financial records:

  • Inventory access: List users who can create or modify loans, notes, payments, journal entries, bank instructions, and reporting data.
  • Identify conflicts: Compare each user's permissions against authorization, custody, recordkeeping, and reconciliation responsibilities.
  • Rank exceptions: Give immediate attention to combinations that allow end-to-end control or changes to audit evidence.
  • Assign safeguards: Add a second approver, independent review, enhanced monitoring, or a restricted emergency process.
  • Recertify access: Have process owners confirm that each permission remains necessary after role changes and staff departures.
  • Train for escalation: Teach employees how to challenge unusual requests, report access concerns, and document exceptions.

COSO's Principle 10 supports this practical approach. If incompatible duties can't be separated, management should deploy alternative control activities rather than accept unchecked access. NIST similarly describes SoD as a way to reduce abuse of authorized privileges and collusion, with duties documented and access authorizations aligned to those duties through account, access, and identity management controls.

Strong SoD doesn't require a perfect org chart. It requires clear ownership, visible evidence, and an independent challenge where risk is highest.

The most effective CEF programs review SoD when a new workflow is introduced, a system changes, an employee changes roles, or an audit identifies a gap. That cadence turns a one-time policy into an operating discipline. It also lets leadership improve controls without imposing unnecessary work on every transaction.


CEFCore brings loan management, investor notes, general ledger, cash and ACH operations, reporting, and role-based workflows into one financial platform, with maker-checker approvals and immutable audit trails that support practical SoD. Visit CEFCore to see how its tools can help your team document responsibilities, control high-risk actions, and strengthen evidence for board and audit review.

CEF

CEF Core Editorial Team

Written and reviewed by CEF Core's treasury, fund-accounting, and compliance team — the people who build the financial management platform purpose-built for Church Extension Funds. Learn more about CEF Core.