Skip to main content

Why should the person approving a vendor payment never be the one who releases it?

One person controlling both approval and release removes the second set of eyes segregation of duties exists to provide — GAO's Green Book names segregation of duties as a core internal-control activity precisely so no single individual can both authorize and complete a transaction. In AP specifically, the FBI names it directly as a fraud defense: separate vendor setup from payment release.

Zuny FesterBy Zuny Fester, Head of Operations and Marketing
Reviewed by Zuny Fester
Published Last reviewed Editorial policy

Part of the accounts payable and invoice processing guide.

The principleNo single individual should control every step of initiating, authorizing, and completing a transaction
Where it's codifiedGAO's Standards for Internal Control in the Federal Government (the Green Book), under Control Activities
AP-specific versionFBI fraud-prevention guidance names "separating vendor setup from payment release" directly
What collapsing the roles enablesOne person could set up a fictitious or altered vendor and approve payment to it with no independent check
Minimum viable splitVendor/banking setup, invoice approval, and payment release as three distinct roles or at least two different people

What segregation of duties is actually defending against

GAO's Standards for Internal Control in the Federal Government — the Green Book, the authoritative federal internal-control framework — lists segregation of duties among its core control activities. The underlying logic is simple: if one person can both authorize a transaction and complete it, there's no independent check between intent and execution. That's true whether the risk is honest error or deliberate fraud; segregation of duties catches both, because a second person reviewing the same transaction has a real chance of noticing something wrong before money moves.

Why AP specifically calls this out

Accounts payable is where this abstraction becomes concrete. The FBI's own business-email-compromise prevention guidance lists separating vendor setup from payment release as a specific control — not a general best practice borrowed from elsewhere, but something named directly in fraud-prevention material because AP is where fraudulent vendor setups turn into actual disbursed cash. A person who can both add a vendor's banking details and approve a payment to that vendor has no one checking their work at the exact point where a fabricated or altered vendor record would otherwise get caught.

What the minimum split actually looks like

It doesn't require three separate departments. The floor is: the person who can create or modify a vendor's payment details isn't the same person who approves an invoice for payment to that vendor, and the person who approves isn't the same one who executes the payment run. Even a small AP team can maintain this by rotating who holds which role, as long as no single login or approval chain lets one person complete the whole cycle alone.

Next step

Map the finance workflow with the most exposure and prove the automation path.

Bring the invoice, contract, payment reconciliation, or customer finance workflow you have to defend at audit. Loopfour can map the trigger, controls, integrations, and approval loop.

Book a workflow review

Field mapping

Three AP roles that shouldn't collapse into one

RoleWhat they controlWhat goes wrong if it's the only check
Vendor setupAdding/editing vendor records and banking detailsA fabricated or altered vendor goes unnoticed
Invoice approvalAuthorizing that an invoice is legitimate and payableA fraudulent invoice sails through with no second read
Payment releaseExecuting the actual disbursementApproval and execution collapse into one unchecked action

Frequently Asked Questions

Yes — the Green Book is the federal standard specifically, but segregation of duties as a control activity is a widely adopted internal-control principle across private-sector accounting generally, and it's the same logic the FBI applies specifically to AP fraud prevention regardless of sector.

The minimum viable split is two people, not three — as long as the person who can alter vendor payment details is never the same person who approves or releases payment to that vendor, the core risk is addressed even on a small team.

Only if the roles are genuinely separated in who holds them — a workflow that technically requires two clicks but both come from the same person's various accounts, or where one person has override authority over the whole chain, doesn't provide the independent check segregation of duties is meant to guarantee.

Sources

Related

Topic

AP & Invoice Processing

Accounts payable and invoice processing is the set of steps a vendor bill goes through between arriving at a company and turning into a payment: capturing what the vendor sent, checking it against wha…

Read more

Diagnostic

What causes a three-way match failure between the PO, receipt, and invoice?

A three-way match compares the PO, the receipt (what was actually delivered), and the invoice on quantity, price, and charges. A failure means one of those three disagrees beyond tolerance — usually because the invoice bills a quantity that isn't fully receipted yet, the unit price differs from the PO, or the invoice adds a charge, like freight, the PO never included.

Read more

Diagnostic

Why did we pay the same vendor invoice twice?

Almost always one of two things: the vendor exists as two separate records in your vendor master, so a duplicate-invoice-number check that only compares within one vendor ID never sees the second copy — or the invoice was entered twice by different people, because it arrived through two channels and each assumed they had the only copy.

Read more

How-to

How do I securely onboard a new vendor (W-9, banking details, verification)?

Collect a Form W-9 before the first payment — the IRS requires 24% backup withholding if a payee's TIN is missing or incorrect. Then verify banking details through a channel the vendor didn't provide: call a number from your existing vendor file, never one in a change-request email, which is the FBI's core defense against business email compromise.

Read more