Account Cloud Inc
Nonprofit Finance

Segregation of Duties When You Have Two People in Finance: A Practical Guide

The textbook version of internal controls assumes a finance team you don't have. Here's how small nonprofits build real controls around the staff they actually employ.

Luke Loescher · July 31, 2026 · 6 min read

Every nonprofit finance training says the same thing: segregate duties. The person who approves a payment shouldn’t be the person who cuts the check. The person who reconciles the bank statement shouldn’t be the person who makes the deposits. It’s good advice. It’s also advice written for a finance department of six, and you have a bookkeeper and an executive director who also does payroll on Fridays.

So you sit through the training, nod along, and go back to an organization where one person still touches almost every dollar that moves. Then your auditor’s management letter shows up with “lack of segregation of duties” as a finding — again — and it feels like being graded against a staffing level you were never going to have.

That gap between the textbook control environment and the real one is where most small nonprofits actually live. The good news: segregation of duties by headcount is only one way to build controls. It’s not the only way, and for a two- or three-person finance function, it’s usually the wrong one to chase.

Why the Classic Model Doesn’t Fit

Classic segregation of duties splits four functions across different people: authorization, custody, record-keeping, and reconciliation. In a large organization, that’s four different staff members, each with a narrow lane, none of whom can complete a fraudulent transaction alone without collusion.

In a nonprofit with one bookkeeper and one executive director, you have two people covering four functions. Something has to double up. The question isn’t whether you can achieve textbook segregation — you can’t, not without adding headcount most small nonprofits can’t justify. The question is which combination of overlapping duties creates the least risk, and what compensating controls close the gap the overlap leaves open.

The Real Risk Isn’t (Usually) Fraud

It’s worth naming the internal problem directly: most small nonprofit finance leads don’t lose sleep over the idea that their bookkeeper is embezzling. They lose sleep over the audit finding itself — the discomfort of an outside party looking at their organization and writing down, in a document the board reads, that the controls are inadequate. It feels personal, even when it isn’t.

Here’s the more useful reframe: segregation of duties isn’t really about catching a bad actor. In a small, trusted team, it’s much more often about catching an honest mistake before it becomes a six-month-old error nobody remembers making. A duplicate payment. A transaction posted to the wrong fund. A vendor added to the system with the wrong bank details. These happen far more often than fraud, and they’re exactly what a control gap lets slip through.

Building Controls Around the Team You Have

1. Separate the highest-risk pairing first. If you can only fix one thing, fix this: the person who can add or edit a vendor in your accounting system should not also be the person who approves payments to that vendor. This single pairing — vendor master file access plus payment approval — is where most nonprofit payment fraud and duplicate-payment errors originate. If your bookkeeper does both today, even a lightweight secondary approval (the ED reviews and approves the vendor list monthly) closes most of the exposure.

2. Use the board or a committee as a compensating control. When you don’t have enough staff to segregate, you can segregate up. A finance committee or treasurer who reviews the bank reconciliation, or who receives a monthly transaction detail report independent of the person who prepared it, is functioning as the second set of eyes your staffing doesn’t provide. This is a legitimate, auditor-recognized compensating control — document it as a formal policy, not an informal habit.

3. Let the system do what a second person would do. A unified accounting system with real-time budget-to-actual visibility, automated approval routing, and an audit trail that shows who touched what and when reduces the number of places an error can hide, even with the same two people. This doesn’t replace segregation of duties — it’s a compensating control, and it should be documented as one — but it closes a meaningful part of the gap that headcount alone can’t.

4. Rotate what you can, when you can. Even in a two-person shop, periodically swapping who reconciles the bank statement, or having the ED spot-check a sample of transactions each quarter instead of every one, breaks up the pattern of a single person controlling an entire process end to end without any visibility from anyone else.

5. Put it in writing. An internal controls policy — even a one-page document — that names who does what, who reviews what, and how often, is what turns “we’re just careful” into a control an auditor can actually test and sign off on. Auditors don’t expect small nonprofits to have a large finance team. They expect small nonprofits to have thought about the risk and documented a reasonable response to it.

What Happens If You Don’t Address It

An unaddressed segregation-of-duties finding doesn’t just sit quietly in last year’s management letter. It repeats, year over year, until it starts to read less like a staffing constraint and more like an organization that isn’t taking financial oversight seriously — which is not the reputation you want in front of a board, a major funder, or a grantor evaluating whether to renew. Some funders now ask directly, in grant applications, how an organization has addressed known control gaps. “We’re aware of it and haven’t done anything” is a materially worse answer than “here’s our documented compensating control.”

What Good Looks Like

A small nonprofit with strong controls doesn’t look like a large one with fewer people. It looks like an organization that has honestly mapped its highest-risk gaps — usually vendor management and payment approval — and closed them with a mix of board oversight, system-enforced approval routing, and a written policy that survives when any one person is out sick or leaves. The auditor’s management letter, if it mentions controls at all, describes what you’re doing about the gap rather than simply noting that the gap exists.

The Bottom Line

You don’t need a finance department of six to have real internal controls. You need to know exactly where the highest risk sits in your two- or three-person structure, close that gap with a compensating control you can actually sustain, and write down what you’re doing so it survives staff turnover and satisfies your auditor. That’s a control environment a small nonprofit can genuinely maintain — not an aspirational one borrowed from an organization ten times your size.

Account Cloud Unity builds compensating controls into the system itself — role-based approval routing, a full audit trail on every transaction, and vendor and payment permissions that can be separated even when the people behind them can’t be. If you’re a small finance team trying to close a real gap without a real budget for new hires, it’s worth a look.

More on Nonprofit Finance