Segregation of Duties at a Law Firm That Only Has Three People in Accounting: The 2026 Internal Controls Playbook

Most law firm embezzlement is not committed by strangers. It is committed by the bookkeeper, office manager, or accounting lead the firm trusts most - and it is enabled by one structural fact: at a 15 to 60 attorney firm, the same person usually enters the bill, cuts the check, and reconciles the account. Here is a practical nine-step internal controls framework that works at real firm size, without hiring a controls department.

Published: 2026-08-29T12:49:21.499Z · Category: Compliance · 10 min read

Segregation of Duties at a Law Firm That Only Has Three People in Accounting: The 2026 Internal Controls Playbook
💡 IN SHORT
Segregation of duties is the single most effective control against law firm financial fraud, and the single hardest one for a mid-market firm to implement - because the classic model assumes headcount most firms do not have. The workable answer in 2026 is not more people. It is system-enforced separation: role-based permissions, approval thresholds, immutable audit trails, and period locks that make it structurally impossible for one person to originate, approve, and conceal a transaction. This guide walks through nine controls a firm with a three-person accounting team can actually run.
👥 Who should read this: Managing Partners Firm Administrators Controllers & Bookkeepers Compliance Leads

⚠️ Why Trusted Staff Is the Threat Model

Law firm fraud has a consistent profile. The perpetrator is rarely an outsider. It is almost always the person with unrestricted access to the accounting system, sole custody of the bank relationship, and the least oversight - typically a long-tenured bookkeeper or office administrator who is genuinely well-liked and genuinely indispensable. The most damaging cases in the profession have run for years precisely because nobody wanted to insult a loyal employee by checking their work.

The five recurring schemes are well documented: check and disbursement fraud, payroll manipulation, firm credit card abuse, trust account theft, and billing fraud. Every one of them requires the same enabling condition - one person controlling more than one stage of a transaction.

🚫 Red Flag
If a single employee can create a vendor, enter a bill against that vendor, generate the payment, and later reconcile the bank account where that payment cleared, your firm has no meaningful control environment - regardless of how honest that employee is. Controls are not an accusation. They are what makes trust safe to extend.

🧩 The Four Stages That Must Never Collapse Into One Person

Every financial transaction at a law firm passes through four stages. The whole discipline of segregation of duties reduces to keeping any single individual away from all four.

✍️

1. Authorization

Someone decides the transaction should happen - approving a vendor bill, a trust disbursement, a write-off, a payroll change.

⌨️

2. Recording

Someone enters it into the ledger - the journal entry, the payable, the billing adjustment.

🏦

3. Custody

Someone has access to the asset - bank signature authority, check stock, card credentials, payment portal rights.

🔍

4. Reconciliation

Someone independently confirms the ledger matches reality - the bank rec, the three-way trust reconciliation, the AR review.

The textbook rule is that all four should sit with four different people. At a 20-attorney firm with a controller, a billing clerk, and a part-time bookkeeper, that is not happening. The practical rule is narrower and achievable: never let the same person hold custody and reconciliation, and never let the same person hold authorization and recording for the same transaction class.

🛠️ The Nine-Step Playbook

1️⃣ Split custody from reconciliation - permanently

Whoever can move money must not be the person who confirms the money moved correctly. If the bookkeeper has payment rights, the reconciliation must be reviewed and signed off by someone else - a partner, the firm administrator, or an outside CPA. This is the highest-value control in the entire list and costs nothing but calendar time.

2️⃣ Make the bank statement bypass the accounting team

Duplicate statements - paper or a separate read-only online login - should go directly to a partner who does not process transactions. Most long-running frauds survive because the perpetrator controls both the ledger and the document used to verify the ledger. Break that loop and the scheme has a very short half-life.

3️⃣ Approve vendors separately from paying them

Vendor creation is the most under-controlled step at law firms. Fictitious-vendor schemes require only the ability to add a payee. Vendor master changes - new vendors, changed bank details, changed remittance addresses - should require a second approver, and the change should be logged with a timestamp and user.

⚠️ Watch Out
Changed banking details on an existing vendor is the highest-risk event in accounts payable and the mechanism behind most business email compromise losses. Treat a bank-detail change as a new vendor: independent verification by a phone call to a previously known number, never to the number in the request email.

4️⃣ Set approval thresholds that scale with risk

Not every transaction needs a partner. Define tiers - for example, operating disbursements under $1,000 approved by the administrator, $1,000-$10,000 by a designated partner, above $10,000 by two partners - and enforce them in the system, not in a policy document. A threshold that lives in a Word file is a suggestion.

5️⃣ Treat every trust disbursement as a two-person event

Trust is where a control failure becomes a bar complaint rather than a business loss. No trust withdrawal should be executable by one person, regardless of amount. The disbursement should be tied to a matter, checked against that matter's available client ledger balance at the moment of payment, and approved by someone other than the person entering it.

6️⃣ Reconcile trust three ways, monthly, on a fixed date

Bank balance, total of outstanding items, and the sum of individual client ledgers must agree. A monthly cadence with a named owner and a named reviewer is what regulators increasingly expect - several jurisdictions now require a designated licensee to perform or supervise this - and it is also the fastest way to detect a misappropriation before it compounds.

7️⃣ Lock closed periods

Once a month is reconciled and reported, the accounting period should be closed so no entry can be back-dated into it. Back-dating is how concealment works: the fraudulent entry is posted into a period leadership has already reviewed and stopped looking at. A hard period lock with an exception log turns concealment into a visible, approved event.

8️⃣ Require mandatory vacation and cross-training

An accounting employee who never takes a full uninterrupted week off, insists on handling their own duties during absence, and resists cross-training is exhibiting the most reliable behavioral indicator in the fraud literature. Two consecutive weeks of coverage by another person is a control, not a benefit.

9️⃣ Review exception reports, not transaction lists

Nobody reviews 900 transactions a month. Everybody can review twelve exceptions. Configure standing reports for: manual journal entries over a threshold, entries posted outside business hours, voided or reversed payments, write-offs above a limit, trust balances below zero at any point, and vendor master changes. Route them to a partner monthly.

💡 Pro Tip
Write the control owners down. For each of the nine steps, name the person who performs it and the person who reviews it, with a date. When a malpractice carrier, a bar auditor, or an acquiring firm asks about your control environment in 2026, that one-page matrix is the answer - and firms that have it get through the questionnaire in an hour instead of a week.

🔐 Why Software Is the Only Way to Do This at Firm Scale

Every control above can be defeated by a helpful colleague sharing a login, or a busy partner rubber-stamping an approval queue. Controls that depend on human vigilance decay within two quarters. Controls enforced by the system do not.

This is where the architecture of the accounting platform matters more than its feature list. CaseQube and LawAccounting run on Salesforce, which means role-based permissions, field-level security, approval processes, and immutable audit trails are platform capabilities rather than bolt-ons. In practice:

🛡️

Role-based permissions

Entry, approval, payment, and reconciliation rights are separate permissions - so separation of duties is configured once, not policed monthly.

Threshold approvals

Approval routing by amount, account, and transaction type, enforced before a payment can be generated.

🧾

Immutable audit trail

Every create, edit, approval, and deletion carries a user and timestamp that cannot be edited by the person who made the change.

🔒

Period lock

Closed accounting periods reject new and back-dated entries; reopening is itself an approved, logged event.

⚖️

Trust guardrails

Matter-level trust balance checks at the point of disbursement block overdrafts and cross-matter borrowing before they happen.

📊

Standing exception reports

Manual entries, voids, write-offs, and vendor changes surface automatically instead of on request.

📊 Did You Know?
When practice management and accounting sit in separate systems, the trust balance check at disbursement is usually a human step - someone looks at a report, then makes a payment somewhere else. On a unified ledger, the check happens inside the transaction. That difference is the entire distance between a policy and a control.

🧭 A Realistic 30-Day Start

Firms that try to implement all nine controls at once implement none of them. A sequence that works: in week one, redirect bank statements to a non-processing partner and confirm who currently holds payment rights. In week two, turn on second approval for vendor creation and bank-detail changes. In week three, formalize trust disbursement dual authorization and set the monthly three-way reconciliation date with a named reviewer. In week four, enable period locking and configure the six exception reports. Everything else - thresholds, mandatory vacation policy, the control matrix - follows naturally once those four are live.

✅ Key Takeaways
  1. Law firm fraud is overwhelmingly committed by trusted internal staff, and it requires one person controlling multiple stages of a transaction.
  2. The four stages that must be separated are authorization, recording, custody, and reconciliation - custody plus reconciliation is the most dangerous combination.
  3. Mid-market firms cannot separate duties by headcount alone; they separate them with system-enforced permissions and approvals.
  4. Vendor master changes and trust disbursements are the two highest-risk events and both need mandatory second approval.
  5. Period locks defeat concealment by making back-dated entries impossible without an approved, logged exception.
  6. Exception reports beat transaction reviews - twelve items a month get read, nine hundred do not.
  7. A one-page control matrix naming who performs and who reviews each control is what carriers, bar auditors, and acquirers now ask for.

Make Separation of Duties Structural, Not Aspirational

LawAccounting and CaseQube enforce role-based permissions, threshold approvals, trust disbursement guardrails, period locks, and immutable audit trails on one Salesforce-powered platform - so your controls hold even on your busiest month.

Schedule Your Demo →

Related Articles

← Back to Blog