Skip to main content

Enforcing separation of duties for approvals

Setup audit passing and fraud reducing controls.

Written by Matt Spurr

Separation of duties (sometimes called segregation of duties) is a control that stops one person from both taking a money-related action and approving it themselves. When it's on, ImpactGraph checks who touched a bill pay or a manual journal entry before letting that same person approve it.

What it checks

With Enforce separation of duties turned on, three things are checked before someone can approve, deny, or return a bill pay, or approve a journal entry:

  • Who submitted the bill pay. The person who sent a bill for approval can't be the one who approves, denies, or returns it, even if their role would normally let them.

  • Who last edited the vendor's payment details. If someone changed a vendor's bank account or routing info, directly or by sending the vendor the link they used to fill it in themselves, that person can't approve a payment to that vendor until someone else has reviewed the change.

  • Who created a manual journal entry. If you type a journal entry directly into the ledger, you can't be the one to approve it for sync. This only applies to entries you create by hand. Entries generated from coding a transaction or from a bill pay aren't affected.

Turn it on

  1. Go to Settings > Accounting Settings.

  2. Find the Separation of Duties section.

  3. Turn on Enforce separation of duties.

The setting applies right away. It covers bills and journal entries that are already waiting for approval, not just new ones.

What people see

If someone is excluded from approving a bill pay, they see a message instead of the Approve and Deny buttons: "You submitted this bill pay, so another approver must review it," or "You last edited this vendor's payment details, so another approver must review it."

For journal entries, the Approve option won't appear on an entry you created yourself.

Good to know

  • You can still submit or resubmit your own bill pay. The rule only blocks the approval steps after that, not the submission itself.

  • Turning this on doesn't change your existing approval rules or who's assigned to review things. It just adds this one more check.

  • You can turn it off the same way, at any time.

Related articles

  • Using Bill Pay for vendors & reimbursements

  • How spending is controlled

  • Managing merchants & vendor tax documentation

Did this answer your question?