Segregation of Duties at a Law Firm That Only Has Three People in Accounting: The 2026 Internal Controls Playbook
Most law firm embezzlement is not committed by strangers. It is committed by the bookkeeper, office manager, or accounting lead the firm trusts most - and it is enabled by one structural fact: at a 15 to 60 attorney firm, the same person usually enters the bill, cuts the check, and reconciles the account. Here is a practical nine-step internal controls framework that works at real firm size, without hiring a controls department.
Published: 2026-08-29T12:49:21.499Z · Category: Compliance · 10 min read
⚠️ Why Trusted Staff Is the Threat Model
Law firm fraud has a consistent profile. The perpetrator is rarely an outsider. It is almost always the person with unrestricted access to the accounting system, sole custody of the bank relationship, and the least oversight - typically a long-tenured bookkeeper or office administrator who is genuinely well-liked and genuinely indispensable. The most damaging cases in the profession have run for years precisely because nobody wanted to insult a loyal employee by checking their work.
The five recurring schemes are well documented: check and disbursement fraud, payroll manipulation, firm credit card abuse, trust account theft, and billing fraud. Every one of them requires the same enabling condition - one person controlling more than one stage of a transaction.
🧩 The Four Stages That Must Never Collapse Into One Person
Every financial transaction at a law firm passes through four stages. The whole discipline of segregation of duties reduces to keeping any single individual away from all four.
1. Authorization
Someone decides the transaction should happen - approving a vendor bill, a trust disbursement, a write-off, a payroll change.
2. Recording
Someone enters it into the ledger - the journal entry, the payable, the billing adjustment.
3. Custody
Someone has access to the asset - bank signature authority, check stock, card credentials, payment portal rights.
4. Reconciliation
Someone independently confirms the ledger matches reality - the bank rec, the three-way trust reconciliation, the AR review.
The textbook rule is that all four should sit with four different people. At a 20-attorney firm with a controller, a billing clerk, and a part-time bookkeeper, that is not happening. The practical rule is narrower and achievable: never let the same person hold custody and reconciliation, and never let the same person hold authorization and recording for the same transaction class.
🛠️ The Nine-Step Playbook
1️⃣ Split custody from reconciliation - permanently
Whoever can move money must not be the person who confirms the money moved correctly. If the bookkeeper has payment rights, the reconciliation must be reviewed and signed off by someone else - a partner, the firm administrator, or an outside CPA. This is the highest-value control in the entire list and costs nothing but calendar time.
2️⃣ Make the bank statement bypass the accounting team
Duplicate statements - paper or a separate read-only online login - should go directly to a partner who does not process transactions. Most long-running frauds survive because the perpetrator controls both the ledger and the document used to verify the ledger. Break that loop and the scheme has a very short half-life.
3️⃣ Approve vendors separately from paying them
Vendor creation is the most under-controlled step at law firms. Fictitious-vendor schemes require only the ability to add a payee. Vendor master changes - new vendors, changed bank details, changed remittance addresses - should require a second approver, and the change should be logged with a timestamp and user.
4️⃣ Set approval thresholds that scale with risk
Not every transaction needs a partner. Define tiers - for example, operating disbursements under $1,000 approved by the administrator, $1,000-$10,000 by a designated partner, above $10,000 by two partners - and enforce them in the system, not in a policy document. A threshold that lives in a Word file is a suggestion.
5️⃣ Treat every trust disbursement as a two-person event
Trust is where a control failure becomes a bar complaint rather than a business loss. No trust withdrawal should be executable by one person, regardless of amount. The disbursement should be tied to a matter, checked against that matter's available client ledger balance at the moment of payment, and approved by someone other than the person entering it.
6️⃣ Reconcile trust three ways, monthly, on a fixed date
Bank balance, total of outstanding items, and the sum of individual client ledgers must agree. A monthly cadence with a named owner and a named reviewer is what regulators increasingly expect - several jurisdictions now require a designated licensee to perform or supervise this - and it is also the fastest way to detect a misappropriation before it compounds.
7️⃣ Lock closed periods
Once a month is reconciled and reported, the accounting period should be closed so no entry can be back-dated into it. Back-dating is how concealment works: the fraudulent entry is posted into a period leadership has already reviewed and stopped looking at. A hard period lock with an exception log turns concealment into a visible, approved event.
8️⃣ Require mandatory vacation and cross-training
An accounting employee who never takes a full uninterrupted week off, insists on handling their own duties during absence, and resists cross-training is exhibiting the most reliable behavioral indicator in the fraud literature. Two consecutive weeks of coverage by another person is a control, not a benefit.
9️⃣ Review exception reports, not transaction lists
Nobody reviews 900 transactions a month. Everybody can review twelve exceptions. Configure standing reports for: manual journal entries over a threshold, entries posted outside business hours, voided or reversed payments, write-offs above a limit, trust balances below zero at any point, and vendor master changes. Route them to a partner monthly.
🔐 Why Software Is the Only Way to Do This at Firm Scale
Every control above can be defeated by a helpful colleague sharing a login, or a busy partner rubber-stamping an approval queue. Controls that depend on human vigilance decay within two quarters. Controls enforced by the system do not.
This is where the architecture of the accounting platform matters more than its feature list. CaseQube and LawAccounting run on Salesforce, which means role-based permissions, field-level security, approval processes, and immutable audit trails are platform capabilities rather than bolt-ons. In practice:
Role-based permissions
Entry, approval, payment, and reconciliation rights are separate permissions - so separation of duties is configured once, not policed monthly.
Threshold approvals
Approval routing by amount, account, and transaction type, enforced before a payment can be generated.
Immutable audit trail
Every create, edit, approval, and deletion carries a user and timestamp that cannot be edited by the person who made the change.
Period lock
Closed accounting periods reject new and back-dated entries; reopening is itself an approved, logged event.
Trust guardrails
Matter-level trust balance checks at the point of disbursement block overdrafts and cross-matter borrowing before they happen.
Standing exception reports
Manual entries, voids, write-offs, and vendor changes surface automatically instead of on request.
🧭 A Realistic 30-Day Start
Firms that try to implement all nine controls at once implement none of them. A sequence that works: in week one, redirect bank statements to a non-processing partner and confirm who currently holds payment rights. In week two, turn on second approval for vendor creation and bank-detail changes. In week three, formalize trust disbursement dual authorization and set the monthly three-way reconciliation date with a named reviewer. In week four, enable period locking and configure the six exception reports. Everything else - thresholds, mandatory vacation policy, the control matrix - follows naturally once those four are live.
- Law firm fraud is overwhelmingly committed by trusted internal staff, and it requires one person controlling multiple stages of a transaction.
- The four stages that must be separated are authorization, recording, custody, and reconciliation - custody plus reconciliation is the most dangerous combination.
- Mid-market firms cannot separate duties by headcount alone; they separate them with system-enforced permissions and approvals.
- Vendor master changes and trust disbursements are the two highest-risk events and both need mandatory second approval.
- Period locks defeat concealment by making back-dated entries impossible without an approved, logged exception.
- Exception reports beat transaction reviews - twelve items a month get read, nine hundred do not.
- A one-page control matrix naming who performs and who reviews each control is what carriers, bar auditors, and acquirers now ask for.
Make Separation of Duties Structural, Not Aspirational
LawAccounting and CaseQube enforce role-based permissions, threshold approvals, trust disbursement guardrails, period locks, and immutable audit trails on one Salesforce-powered platform - so your controls hold even on your busiest month.
Schedule Your Demo →