Sulayo.

Controls and audit

Separation of duties in expense approval

Separation of duties in expense approval means the person who approves a spend is never the person who pays it. Trexo enforces this with a three-level approval chain of line manager, department head and finance, and a separate Accounts Payable role that releases payment but cannot approve. Trexo is built by Sulayo, a Dubai product studio.

01

What is separation of duties, and why do auditors ask about it?

Separation of duties splits a transaction so that no single person can carry it from start to finish alone. In expenses that means approving a claim and releasing the money are different people holding different permissions. Auditors ask about it first because it is the control that makes most expense fraud require collusion rather than merely opportunity, and because it is the one most commonly missing in organisations that outgrew their spreadsheet without noticing.

02

How does Trexo separate approval from payment?

Trexo carries six roles, and Accounts Payable is one of them. A claim is approved up the chain by line manager, department head and finance, and only then becomes payable. The Accounts Payable role can see and pay what has been approved, and cannot approve anything itself. Because the two capabilities are separate roles rather than separate checkboxes on one role, the separation survives somebody being promoted, covering a colleague, or joining mid-year.

03

What does the audit trail actually show?

Every request in Trexo carries a visible approval timeline: who raised it, who approved it at each level, when, and who released the payment. A delegation is recorded as a delegation rather than appearing as the absent manager acting in person, which matters because a shared login is the usual way separation of duties quietly stops being true. The trail is what an auditor is shown, so it is designed to be read by somebody who was not there.

At a glance

Approval roles
Line manager, department head, finance
Payment role
Accounts Payable, separate, cannot approve
Total roles
Six
Delegation
Recorded as delegation, not as the absent approver acting
Evidence
A visible approval timeline per request, exportable to PDF
Policy controls
Per-category spend policies on Business and above

Questions people ask

Can one person hold both an approval role and Accounts Payable?

That would defeat the control, and it is the configuration to avoid. The roles exist separately in Trexo precisely so that an organisation can assign them to different people and demonstrate that it has. In a small finance team where the same person genuinely does both jobs, the honest answer is that the organisation does not have separation of duties, and no software can create it by relabelling.

How small does a company need to be before this stops mattering?

It matters as soon as somebody other than an owner is spending the company's money, which is usually well before anyone gets round to it. What changes with size is not whether the control is needed but whether there are enough people to staff it, and a five-person finance function can still separate approval from payment across two individuals.

Does Trexo prevent someone approving their own claim?

A claim travels up an approval chain from the person who raised it, so the ordinary path never routes a request back to its own author. Combined with the separate payment role, that means a single individual raising, approving and paying a claim is not a path the system offers.

What evidence can be handed to an auditor?

The approval timeline on each request, showing the sequence of approvers, the timestamps, any delegation in force and the payment step, exportable to PDF. Trexo also carries budget-against-actual reporting, so the sample an auditor picks can be traced from the authorisation through to the payment without leaving the system.

Does Trexo support single sign-on for role control?

Yes, on Enterprise: SAML 2.0, Microsoft Entra and Google. That matters for separation of duties because it lets joiners, movers and leavers be handled in the identity provider rather than remembered separately in the expense system, which is where stale permissions usually accumulate.