Why every business should think seriously about segregation of duties
Before getting into what segregation of duties (SoD) is and how organisations should approach it, it’s worth briefly revisiting a story that illustrates how control failures tend to emerge — quietly, gradually, and often without malicious intent.
Collins Street Bakery was a long-established business with more than a century of history and a strong culture of trust. Sandy Jenkins, the company’s accountant, was given broad responsibility across the organisation’s finances. What began as small misuse of petty cash gradually escalated into cheque fraud and unauthorised payments. Over a period of nine years, Jenkins embezzled more than $16 million before the activity was finally uncovered.
The fraud persisted for so long not because the company lacked integrity, but because trust had quietly replaced basic controls. One individual had end-to-end responsibility for financial activities — including investigating why the company was losing money. It was only when a new joiner in the accounting team began questioning transactions that didn’t make sense that the scale of the fraud came to light.
The full story is available here:
https://collinstreet.com/blogs/stories/the-sandy-jenkins-embezzlement-scandal
Most public companies are familiar with the need for financial controls, but smaller or privately owned organisations often operate more informally. Trust replaces structure, and controls are assumed to be unnecessary. This is precisely the environment in which opportunity is created — and where motivated individuals can exploit it for long periods without detection.
It’s also worth noting that motivation is rarely as simple as greed. In some cases it is, but more often it reflects personal pressure, perceived entitlement, financial stress, or the gradual normalisation of behaviour that initially felt minor or justified. Most control failures are not driven by overtly malicious intent, but by situations where opportunity, motivation, and insufficient oversight quietly align over time.
This is where segregation of duties comes in.
SoD is not a technical concept; it arises from a simple risk assessment. The question being asked is: what combinations of responsibility, if held by a single individual, create an unacceptable level of risk?
For example, allowing the same person to manage suppliers, change bank account details, and process invoices or payments creates a clear opportunity for abuse. It’s often argued that suppliers would quickly notice something was wrong, but the key point is that the opportunity exists — and where opportunity exists, motivated individuals will find ways to exploit it.
From this assessment, rules are established. A simple one might be that the same individual cannot both manage suppliers and process payments. This is the essence of SoD. Defining these rules takes time, and implementing them — particularly in ERP systems — can be effort-intensive.
Unsurprisingly, businesses often perceive SoD as friction. There will be resistance. In some cases, legitimate operational constraints mean SoD cannot be fully maintained. Where that happens, mitigating controls must be designed and formally reviewed to ensure the risk remains understood and controlled.
Another common source of resistance comes from so-called “super users”. These are individuals who argue they need broad access because they support others, resolve issues, or understand the system better than anyone else. Support teams often make similar arguments: we can’t help unless we can see and do everything. These justifications frequently go unchallenged because they sound reasonable — or because challenging them feels like too much effort.
For CIOs and those responsible for ERP programmes, these are exactly the issues that need to be addressed early. Designing segregation of duties and control frameworks from the outset makes business acceptance easier, reduces downstream remediation, and significantly smooths post-deployment audit scrutiny. Most importantly, it demonstrates that both IT and the business have a clear, shared understanding of the risks they are managing.
Most control failures aren’t the result of bad intent, but of good people operating in systems that allow risk to accumulate quietly over time.