Create your own
Lesson illustration

Segregation of Duties Across the Revenue Cycle

Hello. In the previous lesson, you learned to distinguish a visible O2C symptom from its initiating cause and control escape point. That same discipline matters here: a control failure is rarely just “someone made a mistake.” Often, the process gave one person enough authority and system access to create an error, approve it, record it, and prevent anyone else from noticing.

This lesson explains how segregation of duties (SoD) should operate across Sales, Deal Desk, Billing, AR, Cash Application, and Accounting in a B2B SaaS environment. By the end, you should be able to explain not only which teams should be separated, but also the specific risks that separation is designed to prevent.


Segregation of duties: separating the power to act from the power to conceal

Segregation of duties is an internal-control principle that divides incompatible responsibilities among different people or independently controlled roles. Its purpose is to reduce the chance that one person can both cause a financial error or fraud and hide it.

The core framework is often summarized as four categories:

  1. Authorization — approving a transaction, exception, or commitment.
  2. Custody — controlling cash, bank details, payment instruments, or other assets.
  3. Record keeping — creating or changing the records that represent a transaction.
  4. Reconciliation — independently comparing records, evidence, and balances to identify differences.
The four SoD categories—authorization, custody, record keeping, and reconciliation—show why no individual should control a transaction from approval through recording and independent verification.

For example, consider a customer credit memo. If one person can approve the credit, create it in the billing system, adjust the customer’s AR balance, and reconcile the resulting balance to the general ledger, that person could conceal an unauthorized reduction of receivables. Splitting those duties makes that much harder.

SoD is therefore primarily a preventive control: it aims to stop inappropriate activity before it affects invoices, cash, AR, revenue, or the financial statements. Independent reconciliations and exception reviews are detective controls because they identify issues that have already occurred. Correcting an invoice or reversing an entry is a corrective control.

Types of Controls | Internal Controls | Segregation of Duties Rules | CMA (US)-PART 1 Lec 43

Watch “Types of Controls | Internal Controls | Segregation of Duties Rules” from Qasim Riaz for a concise explanation of the ARC/R framework: Authority, Record Keeping, Custody, and Reconciliation.

Watch the ARC/R rule for the foundational model. Continue with each responsibility to connect alternative job titles to the four categories, then watch the violation test for the rule used to identify incompatible combinations.

A practical caution: SoD does not mean that every task must belong to a completely separate department. It means that an individual should not hold a combination of access and authority that allows them to initiate, approve, record, and conceal a material transaction without independent review.


Applying the model to the SaaS O2C lifecycle

In SaaS O2C, a customer transaction begins with commercial terms and ends with financial reporting. The critical question is:

Can the same person create a commercial or financial change, approve it, process it, and make the records appear correct?

If the answer is yes, there is likely an SoD conflict.

The Quote-to-Cash sales-process flow helps place these duties in context: configuration, quote, contract, order, billing, revenue recognition, and renewal all affect the financial trail.

The Quote-to-Cash lifecycle shows that commercial actions such as pricing and contracting ultimately become billing, revenue, and renewal records, making control separation necessary across functions.

A workable operating model across the functions in this course looks like this:

FunctionTypical O2C responsibilityKey SoD boundary
SalesCreates opportunities, quotes, and commercial requests; gathers customer documentationMust not approve its own non-standard pricing, discounts, payment terms, or post-signature amendments
Deal DeskValidates commercial terms, approves permitted exceptions, ensures required deal evidence existsMust not invoice customers, apply cash, approve write-offs, or independently post financial corrections
BillingGenerates invoices from released orders and prepares approved billing correctionsMust not approve the commercial exception or unsupported credit that it processes; should not apply customer cash or reconcile bank activity
AR / CollectionsMaintains customer balances, manages collections activity, and may administer credit or dispute statusMust not create invoices, approve its own write-offs or credit-limit exceptions, or independently reconcile balances it changes
Cash ApplicationIdentifies customer receipts and applies them to invoices, credits, or approved on-account balancesMust not create invoices or customer credits, approve refunds, alter bank details, or reconcile its own cash postings to the bank
AccountingReviews financial reporting, posts controlled journals, oversees AR and revenue integrity, performs or reviews reconciliationsMust not originate commercial terms, create unsupported operational adjustments, or reconcile a balance after preparing the underlying adjustment without independent review

The exact reporting lines vary by company. The control principle does not: the role that proposes a transaction should not be the only role that approves it, records it, and validates its final financial effect.


The most important O2C separations

1. Sales versus Deal Desk: commercial initiation versus approval

Sales needs enough access to create quotes, select approved products, and propose terms. That is not an SoD issue by itself. The risk begins when a seller can also approve their own exception.

Common examples include:

  • A discount below the standard pricing threshold
  • A non-standard payment term, such as net 90 rather than net 30
  • A customer-specific cancellation right
  • An unusual renewal uplift or concession
  • A manual product or billing configuration not supported by the standard catalog
  • A post-signature contract amendment

Sales may request or justify these terms. An appropriately authorized Deal Desk, Finance, Legal, or executive approver should approve them according to policy.

After approval, the commercial record should be locked or changed only through a controlled amendment process. Otherwise, a sales representative could obtain approval for one arrangement but alter the order after approval.

The principle is not “Sales cannot touch order data.” It is:

Sales cannot be the sole authority for non-standard deal economics that it has an incentive to close.


2. Deal Desk versus Billing: approving the deal versus turning it into an invoice

Deal Desk validates whether the order reflects the approved commercial agreement. Billing turns the released order into a customer-facing invoice. These roles should not be treated as interchangeable.

Suppose a Deal Desk analyst approves a one-time concession and then also has unrestricted authority to create the billing credit, change the service period, and release the revised invoice. A legitimate exception could be processed incorrectly or expanded beyond what was approved.

A better design separates the evidence:

  • Deal Desk approves the relevant exception and documents the approved scope.
  • Billing prepares the invoice, credit memo, or revised bill based on that approved evidence.
  • The billing system records the link between the adjustment and its approval.
  • Higher-risk items, such as large credits, unusual refunds, or manual invoices, receive an additional review based on a documented threshold.

In some smaller organizations, Deal Desk may also enter order data. That can be acceptable only if the process includes compensating safeguards, such as a separate approver, a locked approved order, automated validation rules, and a review of high-risk manual changes.


3. Billing versus AR: invoice creation versus balance adjustment and collection action

Billing’s core responsibility is accurate invoicing. AR manages the customer’s outstanding balance after the invoice exists. Separating the two functions reduces the risk that billing errors, unauthorized adjustments, or collection decisions can be hidden.

Consider the following risky combination:

  • A Billing employee creates an invoice.
  • The same employee issues a credit memo when the customer complains.
  • The same employee changes the customer’s AR status or marks the invoice as resolved.

Without independent approval and review, that employee could reduce a valid receivable without sufficient evidence.

A controlled arrangement is more deliberate:

ActivityAppropriate control expectation
Issue a standard invoiceBilling processes from a released, validated order
Correct an invoiceBilling prepares the correction from an approved request and retains the original invoice trail
Approve a material credit or write-offAuthorized manager or designated approver independent of the preparer
Update dispute statusAR records the status and supporting customer evidence
Suspend collection activityAR or Collections follows documented dispute and hold criteria
Review credit memo trendsAccounting, Finance, or an independent manager reviews exceptions and aging

The important distinction is between preparing an adjustment and authorizing it. Operational teams may prepare transactions efficiently, but financial concessions require independent approval.

How Segregation of Duties Protects Accounts Receivable Processes

Read this SecurEnds overview to reinforce the classic separation of credit approval, invoicing, cash handling, and reconciliation in accounts receivable.

In the section “Key Accounts Receivable Roles and Responsibilities to Segregate,” read the role separation. Focus on why credit decisions, invoicing, cash activity, and reconciliation create different risks. Then, in “Example of an Accounts Receivable SoD Matrix,” review the matrix example and compare its simple model with the broader SaaS O2C model used in this lesson.


4. Cash Application versus cash control and reconciliation

Cash Application is often misunderstood because it works with payments but may not physically receive or deposit cash. In many SaaS businesses, payments arrive directly through bank accounts, lockboxes, card processors, or payment gateways.

Still, Cash Application holds a sensitive form of control: it can determine which customer balance is reduced by a receipt.

For example, if a customer pays , a cash application specialist might apply it to:

  • A specific invoice, based on remittance advice
  • Several invoices
  • An approved on-account balance
  • A deposit or advance-payment balance
  • An unapplied-cash account while the payer is being identified

The specialist should not be able to conceal an error by also creating an offsetting credit memo, modifying the underlying invoice, changing customer bank details, authorizing a refund, or independently reconciling the bank account.

A key fraud risk is sometimes called lapping: a person misappropriates one customer’s payment and uses a later payment from another customer to cover the missing balance. Independent cash-to-bank reconciliations, prompt posting, restricted access, and review of unusual unapplied cash help expose this type of issue.

A sound separation is:

  • Cash Application applies the receipt from bank and remittance evidence.
  • AR investigates unresolved balances or customer disputes.
  • Billing creates approved invoice corrections.
  • Accounting or an independent reconciler compares bank deposits, cash-application batches, AR activity, and general-ledger balances.

5. Accounting versus operational processing and self-review

Accounting has a critical independent role because O2C transactions eventually affect the general ledger, revenue reporting, deferred revenue, and the close.

But “Accounting reviewed it” is not automatically an effective control. Independence matters at the individual level.

For example, if an accountant prepares a manual journal entry to correct a billing or revenue error, that same accountant should not be the only person approving the journal and reconciling the account afterward. The review should be performed by someone with appropriate authority who did not prepare the entry.

Typical Accounting controls include:

  • Reviewing and approving material manual journal entries
  • Reconciling the AR subledger to the AR general-ledger control account
  • Reviewing billing-to-revenue differences and unusual revenue movements
  • Reviewing credit memo, write-off, and manual-invoice exception reports
  • Investigating aged unapplied cash or unusual customer-balance changes
  • Assessing whether transactions were recorded in the correct accounting period

Accounting should remain independent from the commercial incentive to close a deal and from the operational pressure to clear a billing queue quickly.

Sarbanes-Oxley (SOX) Controls

Read DealHub’s overview to connect SoD with preventive, detective, and corrective controls, then place commercial approvals and financial reporting reviews within the broader Quote-to-Cash control environment.

Begin in “Preventive vs. detective vs. corrective SOX controls” with the control-type distinction. Next, in “SOX and revenue recognition,” read the contract-entry controls. Finally, in “Key controls in the quote-to-cash process,” review the QTC control set, focusing on how SoD complements approvals, validations, and reconciliations rather than replacing them.

SOX requirements apply specifically to relevant public-company reporting environments, but the control design is useful in any SaaS company that wants reliable invoices, clean AR, defensible revenue reporting, and an auditable close.


A worked scenario: the unauthorized retention credit

Assume an account executive is trying to save a renewal. The customer says it will renew only if it receives a credit for a prior service complaint.

A weak process would allow the account executive to:

  1. Edit the renewal opportunity.
  2. Add a retention credit to the order.
  3. Mark the credit as approved.
  4. Ask Billing to issue the credit memo without evidence.
  5. Tell AR to stop collections on unrelated overdue invoices.

This arrangement contains several risks:

  • The credit may not be commercially or contractually justified.
  • The renewal value may be overstated before the credit is recognized.
  • Billing may issue a financial adjustment without an approved source.
  • AR may suppress collection activity on valid, undisputed invoices.
  • Accounting may discover only at month-end that AR, billings, and revenue do not reconcile.

A controlled process would operate differently:

  1. Sales submits the customer request, evidence of the service issue, and commercial rationale.
  2. Deal Desk or the authorized approver evaluates whether the credit is permitted, whether it changes the contract terms, and whether further approval is needed.
  3. Billing creates the credit memo only after receiving approved documentation that identifies the amount, affected invoice or service period, and reason code.
  4. AR places only the supported disputed amount into the appropriate dispute or collection status.
  5. Cash Application continues to apply valid incoming receipts based on remittance evidence; it does not decide whether the credit is justified.
  6. Accounting reviews the resulting credit, AR movement, and financial-reporting impact through independent reconciliation and exception reporting.

The point is not bureaucracy for its own sake. Each step creates evidence that the adjustment was legitimate and that no single commercial or operational role controlled the entire outcome.


SoD is a process design and system-access issue

Job titles alone do not provide SoD. A company can have separate Sales, Billing, and Accounting departments while still having an ineffective control environment if users have excessive system access.

A manager should therefore examine both process authority and system permissions.

Control areaPractical expectation
Role-based accessUsers receive only the permissions needed for their assigned work
Approval workflowNon-standard discounts, payment terms, credits, refunds, and write-offs require documented approval
Restricted master-data changesCustomer bank details, legal entities, tax settings, and credit limits have controlled access and evidence
Locked approved recordsMaterial order changes after approval require a new amendment or reapproval workflow
Audit trailsSystems retain who changed what, when, and under which approval
Exception reportingManagement reviews manual invoices, credits, write-offs, overrides, unapplied cash, and unusual adjustments
Access reviewManagers periodically review permissions, especially after role changes, temporary coverage, or employee departures

A useful manager-level test is to select a transaction with a high risk of manipulation, such as a large credit memo, customer refund, write-off, or manual journal entry. Then identify:

  • Who can request it?
  • Who can approve it?
  • Who can create or post it?
  • Who can change the related customer or payment record?
  • Who independently reviews or reconciles the result?

If one person can answer “me” to most of these questions, the process needs redesign.


What to do when full separation is not possible

Smaller teams may not have enough people to assign every O2C task to a different employee. That does not eliminate the risk; it means the company needs compensating controls.

Examples include:

  • A Finance Manager reviews all manual invoices, credits, write-offs, and refunds above a threshold.
  • A controller independently reviews bank reconciliations and AR adjustments prepared by an operational employee.
  • A system workflow requires an approver outside the preparer’s reporting line for non-standard commercial terms.
  • Monthly exception reports identify users who created and approved the same transaction.
  • Temporary access is time-limited, documented, and reviewed after the coverage period ends.
  • Customer master-data changes, especially bank details, receive independent verification.

Compensating controls should be specific, evidenced, and frequent enough to detect the risk before it becomes material. A vague statement that “the manager keeps an eye on it” is not a dependable control.


Key takeaways

  • Segregation of duties prevents one person from controlling authorization, custody, record keeping, and reconciliation for the same material transaction.
  • In SaaS O2C, Sales should propose commercial terms but not approve its own non-standard exceptions; Deal Desk should approve and validate exceptions but not process downstream financial activity.
  • Billing may prepare invoices and approved credits, but it should not independently authorize unsupported credits, apply cash, or reconcile related balances.
  • Cash Application should apply receipts using bank and remittance evidence, but it should not create invoices or credits, approve refunds, alter sensitive payment data, or reconcile its own cash postings.
  • Accounting provides financial oversight and reconciliation, but preparers should not independently approve and reconcile their own manual corrections.
  • Strong SoD requires both clear operating responsibilities and properly restricted system access.
  • When staffing prevents complete separation, use documented, independent compensating controls such as approval thresholds, exception reviews, audit trails, and periodic access reviews.

Next, you will use the full O2C perspective developed in this module to deliver a concise, manager-level explanation of the complete lifecycle—from customer setup and order approval through billing, collections, cash application, revenue, and close.

Can't find a good explanation? Sign up and we'll make it for you

Sign up