Segregation of Duties in a Four-Person Finance Office: What AI Can and Cannot Cover
Every internal controls guide says the person who approves a payment should not be the person who makes it, and neither of them should be the person who reconciles the account afterward. That requires four pairs of hands doing four different jobs. A great many nonprofits have one bookkeeper, one finance director who is also the operations director, an executive director who signs everything, and a board treasurer who looks at a statement once a quarter. This article is about what you honestly do in that situation, which parts of the problem AI can take, and which parts it absolutely cannot.

Segregation of duties is the single most frequently recommended internal control in the nonprofit sector and the single most frequently unachievable one. The recommendation assumes a finance function with enough people to divide work into independent roles. The reality in a large share of the sector is an office where one person does nearly everything financial because there is nobody else to do it, and where asking for more separation means asking for a position the budget does not contain.
This is not a marginal problem. The Association of Certified Fraud Examiners analyzed 2,402 occupational fraud cases across 143 countries for its 2026 Report to the Nations, and found a median loss of $104,000 per case, a median scheme duration of twelve months before detection, and that more than half of all cases involved either a lack of internal controls or an override of existing controls. The same report found that tips remained the leading detection method at 43 percent of cases, which is a quiet way of saying that in many organizations the control system did not catch the problem and a person did.
Into this gap arrives a genuinely appealing idea: if the constraint is headcount, and AI can read, summarize, flag, and check faster than a person, perhaps AI can be the missing second pair of hands. That idea is half right and half dangerous, and the two halves need separating carefully. AI is extremely good at the documentation and pattern-surfacing work that surrounds internal control, which is work small finance offices chronically fail to do because nobody has the hours. AI is not an independent party, cannot be held accountable, provides no deterrence, and cannot perform a review in the sense that word carries in a control framework.
What follows works through the standard control matrix, explains precisely why a four-person office cannot satisfy it, covers the compensating controls auditors actually accept in place of full separation, and then draws a clear line between the AI applications that strengthen a small finance office and the ones that create a false sense of security. The conclusion will be partly unsatisfying, because the honest answer to a four-person finance office is partly organizational rather than technological, and no tool changes that.
What Segregation of Duties Actually Means
Segregation of duties is not a rule about org charts. It is a rule about a single transaction. The principle is that no one person should be positioned to both commit an error or a theft and conceal it in the normal course of their work. That phrase, in the normal course of their work, is the operative part. A control framework does not assume anyone is dishonest. It assumes that if a mistake or a misappropriation requires no unusual behavior to hide, it will eventually go unnoticed, whether anyone intended it or not.
Practitioners typically break a financial transaction into four functions. Authorization is the decision that a transaction should happen, which means approving the purchase, the payment, the payroll change, or the journal entry. Custody is physical or electronic control of the asset itself, which means handling cash and checks, holding the bank credentials, having the ability to initiate an ACH or a wire. Recording is entering the transaction into the accounting system, which includes posting the entry, coding the expense, and issuing the invoice. Reconciliation and review is the independent verification that what was recorded matches what actually happened at the bank and in the supporting documents.
The textbook requirement is that no single person performs more than one of these functions for the same transaction. Guidance published by state charity regulators frames the same idea in terms of people rather than steps. The Oregon Department of Justice, in its financial control recommendations for small nonprofits, describes separating duties among individuals with access to assets, individuals with access to accounting systems and records, individuals in management or control positions, and individuals exercising independent oversight such as board directors. That last category matters more than small organizations usually realize, because it is the one that stays available to you when the first three collapse into two people.
The reason this framework is so durable is that each pairing it forbids maps to a specific, well-documented failure. Custody plus recording lets someone take a check and alter the books so the receivable looks collected. Authorization plus custody lets someone approve a payment to themselves and then make it. Recording plus reconciliation lets someone post a wrong entry and then sign off that the account agrees. The National Council of Nonprofits summarizes the broader category of practices in its guide to internal controls for nonprofits, and the recurring theme is the same: the point is not to catch a thief, it is to make concealment require effort that leaves a trace.
The four functions, and the pairings that create exposure
What the control matrix is actually trying to prevent
- Authorization: deciding the transaction should happen, including approvals and thresholds
- Custody: holding the asset, the checkbook, the bank credentials, or payment initiation rights
- Recording: posting the entry and coding it in the general ledger
- Reconciliation and review: independent verification against the bank and the documents
- The forbidden pairings: custody with recording, authorization with custody, recording with reconciliation
Why a Four-Person Office Structurally Cannot Get There
Write out your actual finance office against the four functions and the arithmetic becomes obvious. Suppose the office consists of a bookkeeper, a finance director, an executive director, and an operations manager who handles some purchasing. The bookkeeper enters bills, cuts checks, posts deposits, and reconciles the bank, because that is what bookkeepers in small organizations do. The finance director approves payments, reviews the reconciliation, prepares the financial statements, and holds administrative access to the accounting system. The executive director signs checks, approves the finance director's own expenses, and has authority over everything. The operations manager buys things and sometimes receives cash at events.
Now check the pairings. The bookkeeper has custody, recording, and reconciliation for the same transactions, which is the most commonly flagged deficiency in the sector. The finance director has authorization and review over work they also help prepare, and holds the system access that would let them alter either. The executive director has authorization over payments to the people who authorize payments. And there is nobody at all in the fourth regulatory category, independent oversight, because the board treasurer is a volunteer who sees a summary statement at a quarterly meeting.
This is not a failure of diligence. It is a structural consequence of headcount, and it gets worse rather than better in the smallest organizations, because the sequence of roles that disappear as a finance office shrinks is predictable. First the dedicated reviewer goes, so the preparer reviews their own work. Then the separate custodian goes, so the person who records also handles. Then the separate authorizer goes, so the person who spends also approves. By the time an organization is down to one finance staff member plus an executive director, the only genuine separation left is between staff and board.
There are three further complications that small offices often miss. The first is system access, which quietly undoes separation that looks fine on paper. If the bookkeeper does not sign checks but does hold administrator rights in the accounting system and online banking, the separation is nominal, because administrator rights include the ability to add a vendor, change a bank account, and delete an audit trail. The second is coverage, meaning what happens during vacation, illness, and parental leave. Many organizations have beautiful control documentation that is suspended for three weeks each August when the only backup is the person being controlled. The third is the lifecycle problem: someone who has held the same finance role for fifteen years without a period of absence has never had their work independently looked at by a fresh set of eyes, and long tenure plus total trust plus no separation is the pattern that shows up in nearly every sector fraud story.
The separations that quietly fail in small offices
Gaps that documentation often hides rather than reveals
- Administrator rights in the accounting system or online banking held by the person being separated
- Vendor master file changes, where adding a payee is as powerful as approving a payment
- Coverage during leave, when the only backup is the person the control exists to check
- The executive director's own expenses, approved by a subordinate or by nobody
- Long tenure with no absence, which means no fresh eyes have ever crossed the work
The Compensating Controls Auditors Actually Accept
Auditors are not naive about this. The professional standard on communicating internal control matters, AU-C section 265, lists absent or inadequate segregation of duties within a significant account or process as an indicator of a control deficiency, and requires material weaknesses and significant deficiencies to be communicated in writing to those charged with governance. What experienced auditors look for in a small entity is not the impossible separation. It is evidence that leadership understands where the gap is and has put something real in its place. A finance office that can name its gaps and show the compensating controls it operates is in a materially different conversation from one that has never thought about it.
Compensating controls work by substituting oversight for separation. The most important one is independent reconciliation review. Regulatory guidance for small charities is consistent that bank statements should be reconciled monthly by someone who does not issue or sign checks, and where staffing makes that impossible, the compensating version is that the completed reconciliation and the statement are reviewed by a second person who is not the preparer. In the smallest organizations that second person is a board member, usually the treasurer. For that review to count, it must be real: the reviewer sees the statement itself rather than a summary, looks at the actual cleared items, initials and dates what they reviewed, and the record is retained.
Dual signature requirements above a threshold are the classic authorization compensator, and their value is as much psychological as procedural. A second signature means a second person must be persuaded, which is a meaningful deterrent even when the second signer reviews quickly. Banking controls do similar work through the payments channel rather than the people. Positive pay has staying power as a control because it checks every presented item against the file of checks you actually issued, and the 2026 payments fraud outlook from the Association for Financial Professionals notes that positive pay, vendor notifications, and bank alerts are among the most common triggers for fraud detection. Automated alerts on transactions above a dollar threshold, on new payees, and on changes to banking details are cheap, immediate, and route outside the finance office when they are sent to a second person's phone.
Two further compensators are underused. Surprise review means that at an unannounced interval, someone outside the finance function examines a sample: a month of bank activity, a selection of check images, the vendor list, or a payroll register. Its power is that it cannot be prepared for, and the sector guidance on internal controls for the very small nonprofit has long recommended exactly this kind of unscheduled look at how cash and checks move through an organization. Mandatory rotation and enforced absence does something similar by making sure that at least once a year, another person must touch the work in order for operations to continue. Finally, remember the ACFE finding that tips are the leading detection mechanism. A small organization that has a usable way for a staff member, a volunteer, or a vendor to raise a concern without going through the person they are concerned about has added a control that costs almost nothing.
Compensating controls worth operating
Substituting oversight where separation is impossible
- Board treasurer review of the actual statement and reconciliation, initialed and dated
- Dual signatures or dual payment release above a written threshold
- Positive pay, plus bank alerts for large items, new payees, and banking detail changes
- Unannounced surprise review of a sample by someone outside the finance function
- Mandatory leave and role rotation, so another person must touch the work annually
What makes a review count
The difference between oversight and a signature
- The reviewer sees source material, not a summary prepared by the person being reviewed
- The reviewer has the standing and the time to ask a question and stop a payment
- The review is evidenced with a date, a name, and what was examined
- The reviewer receives statements through a channel the preparer does not control
- The review happens on a stated frequency, not when someone remembers
Where AI Genuinely Helps
Notice what all of the compensating controls above have in common. Each of them depends on documentation that does not exist, preparation work nobody has time for, or a volunteer reviewer who is being handed material they cannot efficiently digest. That is precisely the shape of problem a language model addresses well, and it explains why AI is useful here in a way that has nothing to do with replacing a person.
The first and highest-value application is producing a documented control matrix. Most small organizations have never written one, because the format is unfamiliar and the exercise feels bureaucratic. The work is largely structuring what people already know. Describe your transaction cycles in plain language, say who does what in each one, and ask a model to lay it out as a matrix of functions against people, then to identify every place where one person holds two incompatible functions, and every place a stated control has no named owner or no evidence trail. The output is a draft that your finance director and treasurer correct. The value is not the document, it is that the exercise names gaps the organization had stopped seeing. Regulatory guidance for small charities emphasizes documenting control procedures in writing, and this is the cheapest path from nothing to a first real draft. The same structuring instinct applies to a risk register your board can actually use, which is where control gaps belong once named.
The second application is making a reviewer's job possible. Board treasurer review fails in practice not because treasurers are negligent, but because they are handed a forty-page bank statement and a reconciliation report at ten at night before a board meeting, with no realistic way to know where to look. AI changes the economics of preparation. A model can turn a month of transaction activity into a reviewer-oriented summary: total inflows and outflows by category, every item above a threshold listed individually, payees that did not appear in prior months, round-dollar payments, transactions just under an approval threshold, weekend and after-hours activity, and any payee whose name resembles another payee. That is a one-page document a volunteer can work through in twenty minutes and come to with questions. It does not perform the review. It makes the review feasible, which is the difference between a control that exists and one that only appears in a policy.
The third is pattern flagging for human inspection, and the wording matters. A model reading a transaction log can surface anomalies worth a look: duplicate invoice numbers, a vendor whose payment frequency changed, an expense category that moved sharply against budget without explanation, reimbursements that cluster just below the documentation threshold, a credit memo issued in the same period as a deposit shortfall. None of these findings is a conclusion. Each is a prompt for a person to go and look at the underlying document. Treat the output as a worklist rather than a verdict, and the technique is sound. The adjacent discipline of a disciplined close, covered in our article on the month-end close in a small nonprofit bookkeeping function, is what gives this flagging something consistent to work against.
The fourth is checklists and procedure documentation. Reconciliation checklists, disbursement procedures, month-end close sequences, payroll change procedures, and a surprise review protocol are all documents a small office needs and rarely writes. A model drafts them quickly from your description of how the work actually happens, which makes the real bottleneck the interview rather than the writing. The fifth is the control narrative an auditor asks for, discussed in its own section below. Expense and receipt handling, where documentation gaps are usually worst, benefits from the same approach described in our piece on expense reports and receipts. And because payment fraud against small organizations most often arrives through impersonation rather than through the ledger, the controls described in defending against phishing and wire fraud belong in the same conversation as segregation of duties.
Five jobs AI does well in a small finance office
All of them documentation, preparation, or surfacing, none of them deciding
- Draft the control matrix from how the work actually happens, then name every incompatible pairing
- Summarize transaction logs for a reviewer so a volunteer treasurer knows where to look
- Flag unusual patterns as a worklist for a person to inspect against source documents
- Generate reconciliation and procedure checklists that make the work repeatable by a successor
- Write the control narrative your auditor requests, for finance leadership to correct
Where AI Is Not a Substitute for a Second Human
This is the section that matters most, because the temptation in a four-person office is real and the failure mode is quiet. An organization adds an AI review step, writes it into the policy, tells the auditor about it, and feels better. Nothing about the actual exposure has changed, and the organization has lost the discomfort that was motivating it to fix the structure. There are four distinct reasons AI cannot take the place of a second person in a control, and they are worth stating separately because they fail in different ways.
AI is not an independent party. Independence in a control framework is a relationship, not a capability. The reviewer must be structurally outside the thing being reviewed, with their own standing and their own exposure if they sign off on something wrong. A model operates entirely inside the process, on the data it is given, by the person it is given by. If the person who prepares the reconciliation also chooses which transactions to feed the model, writes the prompt, and reads the output, then the model is an extension of the preparer rather than a check on them. Nothing in the architecture creates the separation. The same point applies to tools embedded in an accounting system: a feature operated by the person holding administrator rights inherits that person's position in the matrix.
AI provides no deterrence. A large share of the protective value of a second signature has nothing to do with detection. It comes from the fact that a person contemplating something improper knows a colleague will see it, will possibly ask about it, and will remember it. That knowledge changes behavior before anything happens. An automated check creates a different calculation, because systems can be learned, thresholds can be inferred, and anything deterministic can be structured around. A person who knows the dollar threshold at which a flag fires can keep transactions underneath it, which is why that pattern appears on the anomaly lists in the first place. Human unpredictability is a feature of the control, and automation removes it.
AI cannot be held accountable. Controls rest on named responsibility. When something goes wrong, the question is who approved it, on what basis, and with what information, and the answer has to be a person who can be asked. A model cannot be interviewed about its reasoning, cannot be found to have been negligent, cannot be removed from a role, and cannot bear the duty of care a board member or officer carries. Your auditor, your insurer, and your board are all ultimately asking the same question, which is who is responsible. The answer cannot be a tool. This is also why AI output belongs under a named human owner in your written policy, a point that generalizes across the whole subject of AI policies for small nonprofits.
An AI-generated review is not a review. A review is a person forming a judgment with the information, the time, and the authority to act on it. A summary produced by a model and then approved without scrutiny is a signature, not oversight, and the governance literature on human involvement in automated processes is increasingly blunt that assigning someone to approve an output does not demonstrate that the person could detect an error, had time to investigate it, or had authority to stop it. Automation bias makes this worse under time pressure, because fluent output invites approval. If your board treasurer initials an AI summary without ever seeing a bank statement, you have replaced a weak control with a weaker one that looks stronger on paper. The right framing is that AI prepares material for a review that a human still performs.
Four things AI cannot do in a control framework
Not pending better technology, but structurally
- Be an independent party, because it operates inside the process on data the preparer supplies
- Deter, because a known automated threshold can be structured around and a colleague cannot
- Be accountable, because no tool can be interviewed, found negligent, or removed from a role
- Perform a review, because a review is a judgment made by someone with authority to stop things
- Hold administrator access safely, because tool access inherits its operator's position in the matrix
Writing the Control Narrative Your Auditor Asks For
Somewhere in audit planning, your auditor will ask you to walk them through how a disbursement happens from request to reconciliation, and who does each step. Small organizations handle this badly, not because their controls are bad, but because nothing is written down and the answer comes out as whoever happens to be in the room remembering it differently. An auditor who has to reconstruct your process from three inconsistent verbal accounts will extend testing, which costs you money, and will reasonably conclude the control environment is informal.
A control narrative is just a clear written description of each significant process: the steps in order, who performs each one, what document or system record evidences it, what the approval thresholds are, and what happens when the usual person is unavailable. Writing one is an afternoon of structuring, and it is a near-ideal use of AI. Describe the process out loud or in rough notes, let a model produce the narrative in the conventional structure, then have your finance director correct it against reality and your treasurer read it for anything surprising. The corrections are where the real value appears, because people discover that two staff believed different things about who approves what.
Be deliberate about tone in that narrative. Do not overstate. If a separation does not exist, say so and say what you do instead, because an auditor who discovers that a documented control is not operating is in a much worse mood than one who was told the truth in planning. Write the gap and the compensating control as a pair: the bookkeeper performs the reconciliation because there is no second accounting staff member, and the completed reconciliation with the original statement is reviewed, initialed, and dated monthly by the board treasurer, who receives statements directly from the bank. That sentence tells an auditor that you understand your own exposure, which is the single most useful thing a small organization can communicate. Our broader guide to preparing for an audit with AI support covers the rest of the planning cycle, and the same honesty principle applies to how you present restricted fund tracking and other areas where a small office is doing its best with limited separation.
One caution on using AI here. Do not ask a model whether a particular arrangement constitutes a material weakness or a significant deficiency, and do not put its answer in a document. That determination belongs to your auditor applying professional judgment to your specific circumstances, and a confidently wrong classification in your own narrative is worse than no classification. Use AI to describe what you do. Let the professional characterize it.
What belongs in a control narrative
One page per significant process, honest about the gaps
- The steps in order, with the named role performing each one
- The document or system record that evidences each step actually happened
- Approval thresholds in dollars, and who approves above each one
- Each separation that does not exist, paired with the compensating control you operate
- What happens during absence, and who covers without collapsing the separation
The Part of the Answer That Is Organizational, Not Technological
Here is the uncomfortable part. If your constraint is that there is no second independent person, then the solution involves finding a second independent person, and that is an organizational decision rather than a software purchase. The good news is that the second person does not have to be a new hire, and most of the available options cost far less than one.
The board treasurer is the most underused control resource in the sector. A treasurer who reviews the monthly reconciliation against the actual statement, examines a sample of cleared check images, receives automated bank alerts directly, and conducts one unannounced review a year is operating a genuine control with no payroll cost. What stands in the way is usually not willingness but clarity, because treasurers are frequently appointed without any written description of what the role involves beyond attending meetings and presenting a report. Writing a one-page treasurer control role, listing exactly what they look at and how often, converts goodwill into oversight. Giving them material they can digest, which is where the AI summarization work above earns its place, converts intention into practice. The same reasoning drives better board meeting packets, where the goal is a volunteer who arrives able to ask a sharp question.
A finance committee of two or three people with some relevant background distributes that load and removes the single point of failure if the treasurer leaves. Outsourced bookkeeping or a part-time contract controller is the other common route, and it is genuinely effective because it creates real separation: the external bookkeeper records, your staff authorizes, your bank holds custody, and the external party's own professional standing is at stake. It often costs less than a staff position and brings a review discipline a small office struggles to generate internally. Shared back-office arrangements between several small organizations work on the same principle, and a volunteer from a local accounting firm conducting an annual surprise review is another workable form of independence.
Finally, use the controls that come free with your bank and your systems, because they do not require headcount at all. Positive pay, dual release on ACH and wires, transaction alerts routed to someone outside the finance office, read-only access for the treasurer so they can look whenever they want, separate administrator and operator accounts, and the system audit log reviewed periodically for deletions and backdated entries. Each one shifts a little authority outside the office without adding a person. None of them removes the need for human review, and that is the honest summary of this whole article: technology can carry the preparation, the structuring, and the surfacing, and a person still has to look.
Finding the second person
Independence without a new salary line
- A board treasurer with a written control role, not just a reporting role
- A finance committee of two or three, so oversight survives one departure
- Outsourced bookkeeping or a part-time controller, creating real external separation
- A shared back office across several small organizations in your area
- An annual surprise review by a skilled volunteer from outside the organization
Controls that need no headcount
Available from your bank and your systems today
- Positive pay on checks and dual release on ACH and wire payments
- Alerts for large items, new payees, and banking detail changes, sent outside finance
- Read-only bank and ledger access for the treasurer, usable at any time
- Separate administrator and operator accounts, with admin rights held outside bookkeeping
- Periodic review of the system audit log for deletions and backdated entries
A Practical Sequence for a Four-Person Office
Order matters, because the common failure is to start with the most visible item rather than the one that unlocks the rest. Begin by mapping what you actually do, using AI to structure the matrix from your own description, and resist the urge to describe the process you wish you had. The map is the diagnostic, and it takes a single working session. Second, close the system access gaps, because these are free, immediate, and usually the largest real exposure. Move administrator rights out of the hands of the person who records transactions, separate administrator from operator accounts, and give the treasurer read-only access.
Third, turn on the banking controls. Positive pay, dual release above a threshold, and alerts routed to a phone outside the finance office are a short call with your relationship manager and shift genuine authority outside the office. Fourth, make the treasurer review real, which means a written description of what they look at, statements delivered through a channel the preparer does not control, a monthly reviewer summary prepared for them, and a record of what they reviewed and when. Fifth, schedule the surprise review for the year, naming who conducts it and what sample it covers, without announcing the date internally.
Sixth, write the documentation: the control narrative per process, the reconciliation checklist, the disbursement procedure, and the absence coverage plan. This is the bulk of the writing, it is where AI saves the most time, and it must be reviewed by the people who do the work. Seventh, put the remaining gaps on the board agenda as a standing item with owners and target dates, rather than leaving them in a finance director's head. And eighth, revisit the matrix annually, because every staffing change quietly redraws it, and a control map that was accurate two reorganizations ago is a liability rather than an asset.
Two habits make the difference between a plan and a binder. Keep the artifacts in formats a successor can pick up, meaning documents and spreadsheets in a shared location rather than chat histories or one person's drive. And evidence everything, because an unevidenced control is indistinguishable from no control when an auditor or an insurer asks. A date, a name, and a note of what was examined is enough, and it is the cheapest credibility a small finance office can buy.
Five lines worth putting in your written policy
The boundary, stated so nobody has to infer it
- AI may prepare material for a review; a named person performs the review
- No AI output may be recorded as an approval, a sign-off, or an independent verification
- Flags are a worklist to inspect against source documents, never a conclusion
- Classification of a deficiency belongs to your auditor, not to a model or to staff
- Banking, payroll, and donor financial data stay out of unvetted consumer tools
Conclusion
A four-person finance office cannot satisfy the textbook control matrix, and pretending otherwise in a policy document helps nobody. What such an office can do is understand exactly where its separations fail, operate compensating controls that genuinely substitute oversight for separation, document all of it honestly, and move as much authority as possible outside the office through its bank, its systems, and its board. That combination is what experienced auditors are looking for in a small entity, and it is achievable this quarter without a new hire.
AI belongs squarely in the middle of that work, and nowhere near the parts that require a person. It drafts the control matrix nobody had time to write. It turns an indigestible bank statement into a one-page summary a volunteer treasurer can work through before a board meeting. It flags the duplicate invoice number, the new payee, the cluster of reimbursements just under the threshold, and hands them to a human as a worklist. It produces the reconciliation checklists, the disbursement procedures, and the control narrative your auditor asks for in planning. Every one of those outputs recovers hours that a small finance office does not have, and every one of them makes human oversight more likely to actually happen.
What AI cannot do is be the second person. It is not independent, because it works inside the process on data the preparer selects. It does not deter, because a known automated threshold is something to be structured around rather than someone to be persuaded. It cannot be accountable, because no tool can be asked why it approved something. And an approval of an AI summary is a signature, not a review. If an organization writes an AI step into its controls and stops worrying, it has traded a known weakness for a hidden one, which is a worse position than it started from.
So the honest answer to the four-person finance office is partly organizational. Give the treasurer a written control role and material they can actually use. Call the bank about positive pay and dual release. Move administrator rights away from whoever records transactions. Schedule a surprise review and do not announce the date. Consider outsourced bookkeeping as the separation it genuinely is rather than as an expense. Then let AI do the writing, structuring, summarizing, and flagging that makes all of that sustainable with the people you have. The technology buys back the hours. The judgment stays with a person, and it should.
Document the Controls You Actually Operate
We help small nonprofit finance offices map their control matrix, build reviewer summaries a board treasurer can use, and write the narratives and checklists an auditor asks for, with a clear line around what stays with a person.
