Why should the person approving a vendor payment never be the one who releases it?
One person controlling both approval and release removes the second set of eyes segregation of duties exists to provide — GAO's Green Book names segregation of duties as a core internal-control activity precisely so no single individual can both authorize and complete a transaction. In AP specifically, the FBI names it directly as a fraud defense: separate vendor setup from payment release.
Part of the accounts payable and invoice processing guide.
| The principle | No single individual should control every step of initiating, authorizing, and completing a transaction |
|---|---|
| Where it's codified | GAO's Standards for Internal Control in the Federal Government (the Green Book), under Control Activities |
| AP-specific version | FBI fraud-prevention guidance names "separating vendor setup from payment release" directly |
| What collapsing the roles enables | One person could set up a fictitious or altered vendor and approve payment to it with no independent check |
| Minimum viable split | Vendor/banking setup, invoice approval, and payment release as three distinct roles or at least two different people |
What segregation of duties is actually defending against
GAO's Standards for Internal Control in the Federal Government — the Green Book, the authoritative federal internal-control framework — lists segregation of duties among its core control activities. The underlying logic is simple: if one person can both authorize a transaction and complete it, there's no independent check between intent and execution. That's true whether the risk is honest error or deliberate fraud; segregation of duties catches both, because a second person reviewing the same transaction has a real chance of noticing something wrong before money moves.
Why AP specifically calls this out
Accounts payable is where this abstraction becomes concrete. The FBI's own business-email-compromise prevention guidance lists separating vendor setup from payment release as a specific control — not a general best practice borrowed from elsewhere, but something named directly in fraud-prevention material because AP is where fraudulent vendor setups turn into actual disbursed cash. A person who can both add a vendor's banking details and approve a payment to that vendor has no one checking their work at the exact point where a fabricated or altered vendor record would otherwise get caught.
What the minimum split actually looks like
It doesn't require three separate departments. The floor is: the person who can create or modify a vendor's payment details isn't the same person who approves an invoice for payment to that vendor, and the person who approves isn't the same one who executes the payment run. Even a small AP team can maintain this by rotating who holds which role, as long as no single login or approval chain lets one person complete the whole cycle alone.
Next step
Map the finance workflow with the most exposure and prove the automation path.
Bring the invoice, contract, payment reconciliation, or customer finance workflow you have to defend at audit. Loopfour can map the trigger, controls, integrations, and approval loop.
Field mapping
Three AP roles that shouldn't collapse into one
| Role | What they control | What goes wrong if it's the only check |
|---|---|---|
| Vendor setup | Adding/editing vendor records and banking details | A fabricated or altered vendor goes unnoticed |
| Invoice approval | Authorizing that an invoice is legitimate and payable | A fraudulent invoice sails through with no second read |
| Payment release | Executing the actual disbursement | Approval and execution collapse into one unchecked action |
Frequently Asked Questions
Sources
Related
Topic
AP & Invoice Processing
Accounts payable and invoice processing is the set of steps a vendor bill goes through between arriving at a company and turning into a payment: capturing what the vendor sent, checking it against wha…
Read moreDiagnostic
What causes a three-way match failure between the PO, receipt, and invoice?
A three-way match compares the PO, the receipt (what was actually delivered), and the invoice on quantity, price, and charges. A failure means one of those three disagrees beyond tolerance — usually because the invoice bills a quantity that isn't fully receipted yet, the unit price differs from the PO, or the invoice adds a charge, like freight, the PO never included.
Read moreDiagnostic
Why did we pay the same vendor invoice twice?
Almost always one of two things: the vendor exists as two separate records in your vendor master, so a duplicate-invoice-number check that only compares within one vendor ID never sees the second copy — or the invoice was entered twice by different people, because it arrived through two channels and each assumed they had the only copy.
Read moreHow-to
How do I securely onboard a new vendor (W-9, banking details, verification)?
Collect a Form W-9 before the first payment — the IRS requires 24% backup withholding if a payee's TIN is missing or incorrect. Then verify banking details through a channel the vendor didn't provide: call a number from your existing vendor file, never one in a change-request email, which is the FBI's core defense against business email compromise.
Read more