15 Jun, 2026 | 6 min read

Delegating finance ops as you grow: roles, approvals and segregation of duties

Zara Chechi
Zara Chechi

In the early days the founder is the finance team: every invoice, every payment, every login. That works until it doesn't. As headcount and payment volume grow, the bottleneck becomes a risk, and you need a way to let people prepare and pay while keeping control of who can approve what.

This guide covers when to hand off payments, how to set roles so no one approves their own work, and the controls that reduce the most common payment fraud.

A business account built for founders

Open your account
A business account built for founders

When a founder should stop handling every payment

There is no exact headcount that triggers it, but a few signs are reliable. You are paying invoices late because you were travelling. You are the only person who can release a supplier payment. Or you find yourself approving things at speed without really checking them, simply to clear the queue.

Any of these means the single-person setup has become the weak point. The goal is not to give everything away at once, but to separate the work of preparing a payment from the act of authorising it, so the founder reviews and approves rather than keying in every transaction.

Setting roles so people can prepare and pay, not approve their own work

The core idea is segregation of duties: the person who sets up a payment should not be the person who signs it off. A practical starting structure looks like this:

  • Preparer — a team member who can create payments and add the details, but cannot release funds on their own.
  • Approver — usually the founder or a senior finance lead, who reviews what was prepared and authorises it.
  • Accountant (read-only) — an external bookkeeper or accountant who can view transactions and download statements, but cannot move money at all.

Read-only access matters more than it sounds. It lets your accountant reconcile and report from live data without ever holding payment rights, which keeps your books current and your exposure low.

Dual authorisation on large payments

For higher-value payments, one approval is often not enough. Dual authorisation requires two people to sign off before funds leave the account, so a single mistake or a single compromised login cannot send a large sum on its own.

A common approach is to set a threshold: payments below it can go out on one approval, while anything above it needs a second authoriser. Pick a threshold that reflects what a genuinely painful error would be for your business, and revisit it as the company grows. The point is to add a deliberate pause and a second pair of eyes exactly where the stakes are highest.

Maker-checker on beneficiary details to reduce invoice-redirection fraud

One of the most common attacks on a growing company is invoice redirection: a fraudster poses as a real supplier and asks you to update their payment details, so your next legitimate-looking payment goes to them instead.

The defence is to treat adding or changing a beneficiary's details as its own controlled step, separate from making the payment:

  • One person enters or edits the beneficiary's details (the maker).
  • A different person reviews and confirms the change before it can be used (the checker).
  • Where details change unexpectedly, verify them through a known contact and channel, not the contact details on the new request.

This maker-checker pattern means a redirected-payment request has to get past two people instead of one, which stops the most common version of the fraud.

Onboarding and offboarding team access cleanly

Access controls only work if they reflect who is actually on the team today. Two habits keep things clean:

  • Onboard with the least access needed. Give a new joiner the narrowest role that lets them do their job, and widen it later if the role grows. It is easier to add rights than to claw them back.
  • Offboard the same day someone leaves. Remove or disable access as part of the leaver process, not weeks later. Lingering logins for former staff or contractors are a quiet but real risk.

Reviewing who has access every few months is a useful backstop, especially after a busy hiring period when roles may have drifted from what was originally set.

Frequently asked questions

It means the person who prepares a payment is not the same person who approves it. Splitting those tasks makes it much harder for a single mistake or a single bad actor to move money unchecked.

Yes. A read-only role lets an accountant view transactions and download statements to reconcile your books, while holding no rights to create or release payments.

Because invoice-redirection fraud usually starts with a request to update a supplier's payment details. Reviewing those changes with a second person, and verifying through a known contact, stops the most common version of that attack.

Remove or disable their access as part of the leaver process, ideally the same day. Reviewing everyone's access every few months helps catch anything that was missed.

This guide is general information to help founders and is not financial, tax or legal advice. Altery is not a bank. Check your own circumstances before acting.

Run your startup's finances from one account

Open your account
Run your startup's finances from one account

Keep reading

15 Jun, 2026 | 6 min read

Spending controls and reporting for investor funds

Multi-user roles, approvals on large outflows, read-only access for accountants, and clean statements for board and investor updates.

Zara Chechi Zara Chechi
15 Jun, 2026 | 5 min read

Managing multiple entities from one platform

Run a holding company and its subsidiaries from one login, with separate balances per entity and a single consolidated view of cash.

Zara Chechi Zara Chechi
15 Jun, 2026 | 5 min read

Control team spend: limits, merchant locks and approvals

Per-person limits, merchant and category locks, a card per vendor, approvals for larger buys, and seeing who spent what in real time.

Zara Chechi Zara Chechi
Open account