If you could implement a single internal control that would block the majority of employee fraud schemes in your organization one that requires no software, no specialist, and no significant budget would you do it?
Most businesses haven’t. That control is a dual control policy: the requirement that two separate, independent people must be involved in completing any financial transaction or sensitive task. No single person approves their own work. No single person initiates and completes a payment. No single person counts cash and records it.
The math behind why this works is straightforward. The ACFE’s Occupational Fraud 2024: A Report to the Nations found that more than 50% of all occupational fraud cases occurred because of a lack of internal controls or an override of those controls. The median loss per case has now reached $145,000 a 24% increase from 2022. And the average fraud scheme runs for 12 months before anyone notices. A dual control policy addresses the root cause of the majority of these cases: one person controlling an entire transaction with no independent check on what they’re doing.
This isn’t a compliance technicality. It’s the most effective, lowest cost fraud prevention tool available to businesses of any size.
What a Dual Control Policy Actually Means
A dual control policy is a structured requirement that two authorized, independent individuals must participate in completing a designated task or transaction. Neither person alone can complete the full process each holds a different piece of the authorization or execution chain.
The concept appears under several related names: dual control, maker checker, four eyes principle, two person integrity. The underlying logic is identical regardless of terminology: any task where fraud could occur undetected if left to a single person should require a second independent party.
In financial operations, a dual control policy most commonly separates three functions that fraud perpetrators rely on controlling simultaneously:
- Initiation creating or entering a transaction
- Approval authorizing that transaction to proceed
- Reconciliation verifying that the transaction was recorded correctly
When one person controls all three, they can initiate a fraudulent payment, approve it themselves, and reconcile the record to hide it. This is the single most common internal fraud structure in documented cases. When these functions are split across independent parties, a fraudster must coordinate with at least one other person to complete the scheme which dramatically reduces both the likelihood of the fraud occurring and the duration it can run undetected.
The accounting department is at elevated risk precisely because these three functions naturally cluster there. A three person back office structure one person approving invoices, a second writing checks, and a third reconciling the account is the standard implementation for small teams. For even smaller teams, splitting just two of these functions between different people creates meaningful protection.
Where to Apply Dual Control: The High Risk Transaction Points
Not every task requires a dual control policy applying it universally to low risk, routine operations creates unnecessary friction. The goal is to identify the specific transaction points where a single person’s unchecked action could enable fraud, and apply dual control precisely there.
The highest priority areas for any business:
Payment processing and authorization. No employee should be able to both create and approve their own payment requests. This applies to check issuance, ACH transfers, wire payments, and expense reimbursements. Any payment above a defined threshold typically $2,500 to $10,000 depending on business size and transaction volume should require a second approver who is independent of the person initiating the payment. Our guide on how much access employees should have to business bank accounts explains how to structure this in banking platforms specifically.
Vendor setup and payment. One of the most exploited fraud vectors in small businesses is an employee who can both add a new vendor and process payments to that vendor. A dual control policy for vendor management requires a second person to authorize any new vendor addition and to verify vendor bank account details before payment. Vendor fraud through fake invoices becomes significantly harder to execute when these steps are separated.
Payroll processing. The person who inputs payroll data hours worked, pay rates, new employees should not be the same person who approves and submits payroll for processing. Separating these functions closes the door on payroll fraud through ghost workers and falsified timesheets, which accounts for a significant share of small business fraud losses.
Cash handling. Any task involving physical cash counting receipts, preparing deposits, processing refunds should use dual control: one person counts, a second records and verifies. Cash based fraud is among the hardest to detect after the fact because physical cash leaves fewer electronic traces than payment fraud.
Bank reconciliation. The person who processes transactions should never be the same person who reconciles them against bank statements. This is not an optional separation it’s the foundational control that surfaces discrepancies between what was supposed to happen and what the bank shows actually happened.
The Collusion Problem: What Dual Control Can’t Do Alone
A dual control policy is highly effective against single actor fraud the bookkeeper skimming, the AP clerk creating fictitious vendors, the payroll manager adding ghost employees. It is not a complete solution against collusion, where two employees work together to commit fraud by each providing the authorization the other needs.
Collusion based fraud is less common than single actor fraud the ACFE consistently finds it in a minority of cases but it is significantly more difficult to detect and causes higher median losses when it does occur. A dual control policy remains valuable even in this context, because the second required party is still an independent reviewer who may notice anomalies, and because collusion requires the perpetrator to trust another person with evidence of their crime.
The practical protection against collusion is rotation periodically rotating the people who hold dual control roles for specific transaction types and supervision. If a manager or business owner periodically reviews the transactions their approval staff are authorizing together, collusion becomes significantly riskier to sustain.
This is also why a dual control policy works best as part of a layered fraud prevention system rather than as a standalone control. Catching embezzlement early with accounting software and maintaining an active audit trail add detection layers that dual control alone cannot provide.
How to Implement a Dual Control Policy in Your Business
Implementation of a dual control policy is less complex than most business owners expect. The foundational steps:
Step 1: Map your transaction types. List every category of financial transaction in your business payments, payroll, expense reimbursements, vendor setup, cash handling, bank reconciliation. For each one, document who currently performs each step.
Step 2: Identify single points of control. Flag every transaction category where one person currently controls initiation, approval, and/or reconciliation simultaneously. These are your highest priority dual control targets.
Step 3: Assign independent approvers. For each flagged transaction type, designate a second person who will perform the approval or verification step independently. This person should have no involvement in the initiation step and no personal stake in the transaction being approved.
Step 4: Set dollar thresholds. Define the payment amounts that trigger mandatory second approval. Below the threshold, standard processing applies. Above it, dual control is required without exception.
Step 5: Document the policy in writing. A dual control policy that exists only as an informal understanding is not a control it’s a suggestion. Write it into your financial procedures manual, include it in your employee handbook, and ensure every person with financial access understands both the requirement and the reason for it.
Step 6: Enforce without exceptions. Exceptions are where fraud happens. When a supervisor or business owner bypasses dual control because it’s inconvenient approving their own transactions, waiving the second approver requirement for trusted employees they signal to everyone else that the policy is optional. Consistent enforcement is what makes the control effective.
If your team is small and full separation is difficult, consider involving an external bookkeeper or accountant for reconciliation or approval functions. Even one independent external reviewer creates accountability that eliminates the most common single actor fraud structures.
Dual Control and the Fraud Triangle
Criminologist Donald Cressey’s “fraud triangle” identifies three conditions that must be present for occupational fraud to occur: pressure (a financial need or incentive), opportunity (the ability to commit fraud without detection), and rationalization (the ability to justify the behavior to oneself).
A dual control policy directly addresses the opportunity vertex the single factor that most internal controls are designed to eliminate. You cannot control whether employees experience financial pressure in their personal lives. You cannot fully predict how individuals will rationalize their choices. But you can close the opportunity by ensuring that no transaction can be completed, concealed, and reconciled by a single person acting alone.
When opportunity is eliminated, pressure and rationalization become insufficient on their own. This is why segregation of duties and dual control are consistently identified by the ACFE, AICPA, and COSO as among the most effective foundational anti fraud controls available to any organization. And it’s why the most trusted managers still commit fraud when opportunity exists trust doesn’t change the structural math.
Conclusion: The Simplest Control Is Often the Most Powerful
The most sophisticated fraud prevention programs in the world are built on a foundation of simple, consistently enforced structural controls. A dual control policy is the most accessible of these requiring no technology investment, no specialized expertise, and no major operational restructuring.
What it does require is intention. The decision to separate financial functions, to require independent approval, and to enforce those requirements without exception is a policy choice one that dramatically reduces both the likelihood and the scale of internal fraud.
If you haven’t mapped your transaction types and identified your single points of control, that exercise is worth an afternoon of your time. The most common frauds aren’t sophisticated. They work because they’re simple and because no one was watching. A dual control policy is how you change that.
For organizations that suspect fraud is already occurring, securing records and consulting a forensic accountant before taking any action is the right first step. Our guide on what to do when you suspect employee theft walks through the full response sequence.
Frequently Asked Questions
1. What’s the difference between dual control and segregation of duties? Segregation of duties is the broader principle: ensuring that no single person controls an entire process from initiation to completion. Dual control is a specific implementation of that principle requiring two independent people to participate in the same task simultaneously or sequentially before it can be completed. Dual control is most commonly applied to high risk, high value transactions; segregation of duties is the framework that governs how roles and responsibilities are structured across the entire financial operation.
2. Can a small business with only two or three employees implement a dual control policy? Yes, though it requires creativity with limited staff. For very small teams, the business owner can serve as the second approver for critical transactions. An external bookkeeper can perform bank reconciliation independently. A CPA or accountant can provide periodic review of transaction records. The goal is to ensure at least one independent step exists for each high risk transaction type not that every function is staffed by separate full time employees.
3. What dollar threshold should trigger mandatory dual approval? There’s no universal standard thresholds depend on the size and transaction volume of your business. Common small business benchmarks range from $2,500 to $10,000 for requiring a second approver. Higher volume businesses often set lower per transaction thresholds while adding aggregate controls (e.g., any single vendor receiving more than $X per month requires additional review). Consult with your accountant or fraud examiner to set thresholds appropriate for your specific risk profile.
4. Does a dual control policy need to be in writing? Yes, always. An informal practice is not a control it’s a habit that can be bypassed without accountability. A documented dual control policy defines specifically which transaction types require dual authorization, the dollar thresholds that trigger it, who is authorized to serve as the second approver, and what documentation is required for each approval. Written policies also provide legal protection and support insurance claims if fraud does occur.
5. Can someone override a dual control policy and still have the fraud go undetected? Override of controls is documented in 19% of ACFE fraud cases making it the second leading cause of fraud after absence of controls. This is why enforcement consistency matters and why periodic review of whether the policy is being followed is a necessary second step. When a senior manager or business owner is the one overriding controls, detection becomes more difficult which is why independent review (external auditor, board oversight, surprise audits) provides the check on the control enforcer themselves.
6. How does dual control affect efficiency and is the tradeoff worth it? For routine, low value transactions, the efficiency cost of dual control is real and should be weighed against risk. This is why dollar thresholds matter: below the threshold, standard single approval processing is appropriate. Above the threshold, the few minutes required for a second approval are a modest price relative to the fraud losses they prevent. Most businesses that implement dual control policies thoughtfully applying them precisely to high risk transaction points find the operational impact minimal and the protective value significant.
References
- Association of Certified Fraud Examiners (ACFE). (2024). Occupational Fraud 2024: A Report to the Nations. https://www.acfe.com/ /media/files/acfe/pdfs/rttn/2024/2024 report to the nations.pdf
- Alvarez & Marsal. (2025). Segregation of Duties: A Simple Idea to Prevent Fraud. https://www.alvarezandmarsal.com/insights/segregation duties simple idea prevent fraud
- Moss Adams LLP. (2023). Prevent and Detect Fraud With These Key Internal Controls. https://www.mossadams.com/articles/2023/04/internal controls for fraud prevention
- GrowthForce. (2024). Top 10 Internal Controls to Prevent and Detect Fraud. https://www.growthforce.com/blog/top 10 internal controls
- Yooz. (2026). AP Internal Controls for Mind Blowing Fraud Prevention. https://www.getyooz.com/blog/ap internal controls
- Schneider Downs. (2024). Spotting and Stopping Long Lasting Fraud: Highlights from the ACFE’s 2024 Report to the Nations. https://schneiderdowns.com/our thoughts on/spot and stop long lasting fraud/
- Withum. (2024). 2024 ACFE Report to the Nations: Unmasking the Impact of COVID 19 on Occupational Fraud. https://www.withum.com/resources/2024 acfe report to the nations unmasking the impact of covid 19 on occupational fraud/
- TASBO. (2025). ACFE 2024: A Report to the Nations. https://www.tasbo.org/resources/acfe 2024 a report to the nations
- AICPA. (2024). Internal Controls: A Framework for Small and Medium Sized Entities. https://www.aicpa cima.com/resources/article/internal controls framework small entities
- Federal Bureau of Investigation (FBI). (2024). White Collar Crime Financial Fraud Overview. https://www.fbi.gov/investigate/white collar crime
Disclaimer: This article is provided for informational and educational purposes only. It does not constitute legal, financial, or professional advice of any kind, and no professional or client relationship is created by reading it. Internal control requirements and fraud risks vary by jurisdiction, industry, and organization type. Consult a qualified certified fraud examiner, accountant, or attorney for guidance specific to your situation. For questions about FraudOrder services, visit https://fraudorder.co/