Zentriq Agent is live on Microsoft AppSourceInstall it free →Microsoft AppSourceInstall it free →

What is Segregation of Duties (SoD) in Business Central?

Segregation of duties splits a business process so that no single person can create, approve and pay a transaction without a second pair of hands.

Segregation of duties, often shortened to SoD and sometimes called the four eyes principle, is the internal control idea that the steps of a transaction should sit with different people. In accounts payable the classic split is five steps: set up the vendor and its bank details, raise the order, receive the goods, post the invoice, release the payment. Controls come in two flavours. Preventive controls stop the combination from happening at all, usually through system rights. Detective controls accept that it happened and make sure somebody reviews it afterwards.

The reason the split exists is that a single person holding several steps can complete a fraud without anyone else touching it: create a vendor, point its bank account at their own, post an invoice, approve it, pay it. The same concentration also produces honest errors that nobody catches, such as a duplicate invoice or a wrong bank account, because there is no second read before money leaves. External auditors test these combinations directly, and a finding here tends to widen the audit rather than close it, which has its own cost.

Business Central gives you the building blocks but not the verdict. Permission sets grant read, insert, modify, delete and execute rights per object, so posting rights and master data rights can be separated. Approval workflows route documents to an approver, with the approval user setup holding approver assignments, substitutes and amount limits, and workflow templates exist for purchase documents, journal batches and master data such as vendors. Payment journals can be kept in separate batches, and the change log records master data changes such as a vendor bank account once you enable it for the relevant tables. What is missing is the control layer on top: there is no conflict matrix, no report that tells you which users hold an incompatible combination, and nothing prevents an administrator from assigning conflicting sets to the same person. SUPER bypasses all of it, and in a small tenant a surprising number of users still have it. Approval setups can also be configured so that a requester is their own approver, which quietly cancels the control.

A workable arrangement in a mid sized company looks like this. Anna in accounts payable posts a CHF 24 700.00 invoice from vendor V10480 and sends it for approval. The controller's purchase amount approval limit is CHF 50 000.00, so it stops with him; above that it goes to the CFO. Anna has no rights on the payment journal batch, which only the treasurer can post, and the bank requires two signatures on transfers above CHF 10 000.00. Vendor bank account changes are captured in the change log and reviewed once a month by someone outside accounts payable. Anna can create, but she cannot approve, pay or quietly redirect a payment.

In practice the design decays rather than fails outright. Everyone gets SUPER during go live and nobody removes it. An approval limit is set to unlimited for a holiday and stays that way. A substitute approver is configured as the person who raised the request. A leaver keeps an active user account for months. Reviews therefore look at who holds which permission sets, how many approvals were granted by the person who created the document, how many payment lines were posted by someone with vendor master data rights, and whether every vendor bank account change in the log traces back to a written request. The same questions apply to any tool or integration that writes into Business Central: it inherits whatever rights it runs under, so it belongs in the review like any other user.

Go deeper

Frequently asked questions

We are a finance team of three. How can we segregate anything?

Full separation is not realistic at that size, so the usual answer is compensating controls: two signatures at the bank, a person outside accounts payable reviewing new vendors and bank account changes, and the owner or managing director reviewing the payment list before release.

Does Business Central report segregation of duties conflicts?

No. It provides permission sets, approval workflows and a change log, but there is no built in conflict matrix or violation report, so the review of who holds what is either done manually or with a third party tool.

Related terms

  • Approval Workflow, Business Central's built-in system for routing purchase orders and invoices through configurable approval chains before posting.
  • Permission Set, A permission set is a named group of read, insert, modify, delete and execute rights on Business Central objects, assigned to users to control what they can do.
  • Payment Journal, The Business Central journal for paying vendors, with automatic payment suggestions, application to open invoices, and payment file export.
  • Purchase Requisition, A purchase requisition is the internal request to buy something, raised by the person who needs it and approved before a buyer turns it into a purchase order.
  • Purchase Invoice, A document recording a vendor's bill for goods or services received, used for accounts payable processing in Business Central.

How Zentriq helps

Zentriq's AI tools automate many of the manual processes around segregation of duties (sod) in Business Central. Learn about the Zentriq Agent or try Zentriq PunchOut to see how AI simplifies procurement in BC.

Related resources

GlossaryApproval WorkflowGlossaryPermission Set