Finance & AccountingFree
Segregation of Duties Matrix Template
The conflicts that only appear once you combine every role a person holds, each one priced by the dollars it exposes.
River's segregation of duties review reads the real user and permission export out of your accounting system and rebuilds it one person at a time. Every role somebody holds collapses into a single effective permission set, so a conflict surfaces whether it sits inside one role or falls out of two. Each one comes back with the transactions it exposes, the dollars that moved through those transactions last year, and a call on whether your headcount can separate it at all.
Unlike a grid you fill in from the org chart, nothing here rests on what a job title suggests somebody does. A downloadable matrix asks you to mark cells red or green from memory, so it inherits every assumption you already had about who does what. This starts from what each login is actually permitted to do, which is frequently more than the person using it realises. The trial balance normalizer takes the same approach to a chart of accounts nobody documented.
Written for the controller or fractional CFO whose auditor, lender or new board member has asked for a duties matrix. Reach for it after a permission change, before fieldwork, or when a five-person team has to explain in writing why one person still does two things. Conflicts around who releases money sit next to the weekly payment run, and the reconciling half of most of them lives in the bank reconciliation pack. Those conflicts sit on the steps the internal controls narrative pack numbers by cycle.
A conflict belongs to a person, not a role
Almost every duties matrix is drawn with roles down one axis and duties across the other, and that geometry hides the most common conflict there is. Sage Intacct's own documentation states that a user's permissions are a superset of the permissions from all of the roles they hold. So two roles that are each clean on their own combine into a live conflict on whoever holds both. A role-versus-role grid has no cell where that could appear, because the unit of analysis is the login rather than the job title.
Take a nine-user export from a contract manufacturer: fourteen roles, 212 permissions. Read role by role and two roles carry both halves of a conflict inside them, worth 1,043,400 of cash journal entries and 41,600 of petty cash. Read person by person and there are seven. The largest is an AP clerk who can create a payee and release a payment batch. That is the entire disbursement population, 3,182 payments and 8,412,700, out of two roles the grid passes. Same export, eleven percent of the exposure found.
When a duty genuinely cannot be separated, the standard does not ask you to pretend otherwise. GAO's Green Book requires that where segregation is impractical because of limited personnel, management designs alternative control activities instead. It names four of them: extra levels of review, randomly selected transactions read with their supporting documentation, periodic asset counts, and checking supervisor reconciliations. Size the one you choose by the population it covers. That AP clerk keeps both roles, and what offsets her is the new-payee report, 34 names last year.
How it works
Export the permissions
The user list with its roles column, plus whatever report maps each role to its permissions.
Add last year's volumes
Payment counts and totals, the journal entries that touched cash, expense claims, and credit memos.
River reads per person
Roles collapse into effective permissions, conflicts surface at the login, and each gets a dollar figure.
Work the exceptions
Say which duties you can genuinely staff apart, and the compensating controls get rewritten around the rest.
What you get
- Every person's effective permissions, collapsed from all the roles they hold into one set
- Conflicts that exist only because two individually clean roles landed on the same login
- Each conflict priced by the transactions it exposes and last year's dollars through them
- The permissions that let a holder quietly grant themselves any other row, flagged first
- A compensating control per unresolved conflict, sized by how many items somebody reviews
- Remediation ordered by dollars exposed rather than by a high, medium or low label
Common questions
My auditor asked for a segregation of duties matrix. Is this that?
Yes, plus the evidence underneath it. What goes in the file is the matrix, but what an auditor tests is whether it matches the system, so every row cites the role that granted each half. It arrives as one numbered line on the audit preparation request list, alongside the audit confirmation tracker and the balance sheet substantiation pack.
There are five of us in finance. Isn't this exercise pointless at our size?
The opposite, because the answer is not to hire. GAO's Green Book says a smaller entity faces greater difficulty here and responds by designing alternative controls. So the output is a short list of the conflicts you keep and what offsets each one. In the worked example above, four of six conflicts stay and cost 128 review items a year.
Our controller is also the system administrator. Does that invalidate the rest?
It changes the order rather than the answer. A login that can assign permissions can grant itself any other row and remove the grant afterwards, so that finding is read first and everything else is read against it. NIST's access control catalogue makes the same separation explicit: whoever administers access should not also administer the audit function.
Where do the dollar figures actually come from?
From the volumes you paste in, mapped to the transaction population each conflict reaches. Vendor payments price a payee-plus-payment conflict, cash journal entries price a post-plus-reconcile conflict. Where you have not supplied a population, the row says so and carries a count instead of a currency figure, rather than an estimate dressed up as one.
Do I need an ERP, or does this work on QuickBooks or Xero?
Any system that can list its users and what each one may do. Sage Intacct and NetSuite print a role-to-permission report directly. QuickBooks Online and Xero expose access levels per user instead, which is coarser, so conflicts come back at the level the system actually enforces rather than invented detail.
What happens to a conflict I genuinely cannot fix?
It stays on the list with a compensating control and the size of that control's review population, since a control nobody performs is worse than a documented gap. Reviewing 34 new payee names a year is a real commitment. Reviewing 3,182 payments is not, and the card statement and receipt matcher is what makes the expense half of that sampling tractable.
Segregation of Duties Matrix Template
Fill in the form and your workspace opens with the work already underway.