The short answer: when a small team makes full segregation of duties impossible, the practical substitute is compensating controls — the owner keeping direct sight of the bank, dual authorisation of payments, independent review of reconciliations and payroll, verified changes to supplier details, and mandatory leave for anyone in a financial role.
Why small businesses are especially vulnerable
Fraud examiners often describe occupational fraud using the fraud triangle: it tends to occur when three elements are present at the same time — pressure (a personal financial problem), rationalisation ("I'll pay it back", "I deserve this"), and opportunity (the ability to act without being caught).
A business can do little about the first two — they live inside the employee. But opportunity is created by the business itself, and small businesses create more of it than most:
- Concentration of duties — one person often raises invoices, records payments, reconciles the bank and handles petty cash.
- Trust as a substitute for checks — long-serving staff are assumed to be beyond question, so no one reviews their work.
- Owner attention elsewhere — founders focus on sales and operations, and stop looking at the bank statements themselves.
- Informal processes — approvals happen verbally or over chat, leaving no trail to review later.
The result is that fraud in smaller organisations typically runs longer before detection and causes proportionally larger losses relative to the size of the business — losses that a thin-margin SME is far less able to absorb than a large corporate.
What internal controls actually are
"Internal controls" sounds like corporate jargon, but the idea is simple: they are the checks, approvals and reviews built into how money moves and how records are kept, designed to do three things:
- Prevent errors and fraud from happening — e.g. requiring two people to approve a payment.
- Detect problems quickly when they do happen — e.g. a monthly reconciliation reviewed by someone independent.
- Safeguard assets — cash, stock, equipment and data — from misuse or loss.
Controls do not need to be bureaucratic. The best SME control environments are lean: a handful of well-chosen checks at the points where money actually leaves the business, rather than a thick policy manual nobody reads.
The segregation-of-duties problem
The classic control principle is that no single person should be able to initiate, approve, record and reconcile the same transaction. In a large finance team, those four steps sit with four different people. In an SME, they often sit with one.
The answer is not to hire three more finance staff. It is to accept that full segregation is out of reach and put compensating controls in place instead — checks that involve the owner or a second person at the few moments that matter most. In practice, the owner's own attention is the single most powerful control an SME has.
Right-sized controls that work for small teams
These are the controls we most often recommend to owner-managed businesses. None of them requires a large finance team; most cost nothing but discipline.
1. Keep payment authorisation with the owner
The owner (or a director) should remain an approver on the bank account, with dual authorisation required above a sensible threshold. Internet banking makes this easy: the bookkeeper prepares payments, and the owner releases them. Review the payee name and bank account — not just the amount — before approving.
2. Have bank statements go to someone independent
The person who records transactions should not be the only person who sees the bank statement. The owner should receive statements (or have direct read access to internet banking) and scan the actual bank activity monthly. Many long-running frauds survive because the fraudster is the sole gatekeeper of the bank statement.
3. Review the bank reconciliation — and its reconciling items
A reconciliation prepared and reviewed by the same person is not a control. Someone independent — usually the owner or an outsourced accountant — should review it monthly, paying particular attention to old or unusual reconciling items, which is where problems hide.
4. Lock down changes to supplier bank details
A large share of SME losses today comes not from insiders but from impersonation scams — fake "updated bank details" emails from suppliers or even from the boss. Make it a rule that any change to a supplier's bank account is verified by phoning a known contact on a number you already have, never one provided in the email requesting the change.
5. Independent review of payroll
Whoever processes payroll should not be the only person who sees the output. A monthly review of the payroll listing — checking headcount, new joiners, leavers and unusual movements — takes ten minutes and defeats ghost employees and unauthorised pay changes.
6. Mandatory leave and job rotation
Require everyone in a financial role to take an uninterrupted block of leave each year, with someone else performing their duties while they are away. Frauds that depend on daily concealment tend to surface the moment someone else sits in the chair.
7. Basic controls over cash, stock and access
- Keep petty cash small, receipted and counted by a second person periodically.
- Perform stock counts at least annually, with someone independent of the storekeeper involved.
- Restrict accounting system access by role, remove leavers promptly, and don't share logins — an audit trail is worthless if everyone uses the same account.
Common fraud red flags
No control catches everything, so it pays to know the warning signs. Individually, each has innocent explanations; in combination, they warrant a closer look:
- A finance employee who never takes leave and resists anyone else touching their work.
- Lifestyle changes that are hard to square with a known salary.
- A dominant finance person who controls all records, statements and relationships with the bank.
- Missing documentation — invoices that can't be produced, approvals that were "verbal".
- Round-number, duplicate or just-below-threshold payments, or payments to vendors nobody recognises.
- Suppliers or customers complaining about statements that don't match your records.
- Margins or expense lines that drift unexplained from budget and history.
Where an audit fits in
A common misconception is that a statutory audit is a fraud investigation. It is not: an audit provides reasonable assurance that the financial statements are free from material misstatement, whether due to error or fraud — but it is not designed to detect every fraud, particularly small or well-concealed ones.
That said, the audit process regularly surfaces control weaknesses: auditors evaluate the control environment, test transactions, and report deficiencies to management in a management letter. For many SMEs this is the only independent health-check their finance function ever receives. It is also worth noting that many Singapore SMEs are audit-exempt under the small-company regime — which means they lose this check entirely unless they choose a voluntary audit or a targeted review of controls.
Getting started: a practical sequence
If your business currently runs on trust, don't try to build a corporate control framework overnight. A sensible sequence:
- Week 1: get the owner direct read access to all bank accounts, and set dual authorisation above a threshold.
- Month 1: institute the monthly owner review — bank activity, bank reconciliation, payroll listing.
- Month 2: write down the payment approval rules and the supplier bank-detail call-back rule, and brief the team.
- Month 3: schedule mandatory leave, tidy up system access, and set a date for a stock count if you carry inventory.
- Ongoing: revisit the controls annually as the team grows — every new hire in finance is a chance to separate one more duty.
Introducing controls can feel awkward — long-serving staff may read it as distrust. Frame it the other way: good controls protect honest employees by making it impossible for suspicion to fall on them, and they are a normal part of a business growing up.
The bottom line
Small businesses cannot segregate every duty — and they don't need to. Most SME fraud exploits a handful of predictable gaps: unwatched bank accounts, unreviewed reconciliations, unverified supplier changes, and one trusted person with end-to-end control. A lean set of compensating controls, anchored by the owner's regular attention to the bank, closes most of those gaps at almost no cost — and the discipline usually improves the quality of your financial information along the way.
At Chua and Lee Associates, we help Singapore SMEs assess their control environment, design right-sized controls, and provide the independent checks — from statutory and voluntary audits to targeted reviews — that keep them working. To learn more, see our Audit services and Advisory services.