Research story · Governance, forensic accounting & control design
Separated duties.
Shared exposure.
Every payment can have a separate preparer and reviewer while the same small group controls a large amount across the file. Research on coalition exposure shows how to compare compliant assignments and make feasible repairs.
An accounts-payable file passes a familiar control check: nobody reviews a payment they prepared. Each record has two different people, staffing is unchanged and review duties are balanced. The organisation still needs to ask how those assignments fit together. Which group could jointly reach the largest amount across several payments?
My manuscript, Separated Duties, Shared Exposure: Coalition Containment and Feasible Redesign, develops that assessment. It holds transaction-level separation of duties in place, then examines how the pattern of responsibilities contains or concentrates access. The result is a way to distinguish compliant designs that an individual-record check treats alike.
The same duties can create different exposure
Consider six employees and six separately capped payment tranches. Each employee prepares one tranche and reviews another. One assignment places the employees in two three-person review groups. Another links all six in a single cycle of review responsibilities. These links connect duties across different payments; they are not circular steps that must be completed within one payment.
Three cooperating employees can control all three tranches in one of the smaller groups. In the six-person cycle, a proper three-person subset can control at most two. Changing two reviewer assignments produces that improvement while keeping one preparation and one review per employee and leaving two-person exposure unchanged.
The example identifies an organisational property that local compliance misses. Access depends on the combination of duties held by the same people across the monetary population. Counting signatures establishes a rule for each release; mapping the whole assignment establishes what a group can reach.
Measure the amount, then show the witnesses
The paper calls the resulting curve the coalition-exposure spectrum. For each possible group size, it reports the largest accessible amount under the recorded permissions. Its inverse asks how many employees are needed to reach a specified amount. A maximizing group supplies a witness: the employee identities and payment records that support the calculation.
This assessment requires no estimate of who will cooperate. It measures conditional access, rather than expected theft or fraud incidence. Incentives, recruitment, concealment, detection and recovery affect what happens in practice. The permission file provides evidence about the opportunity, not a finding about anyone’s conduct.
The monetary unit also matters. A record must have an enforceable cap over a defined horizon. Separate tranches can be added only when their caps are jointly attainable. Repeated appearances of one nonreplenishing balance cannot each be treated as new money. These accounting conditions determine whether a precise exposure number describes a real possibility.
An exact benchmark, within a defined class
For balanced assignments with equal tranche caps, the paper derives the complete exposure spectrum from the review-cycle structure. A group controls a full tranche for each of its members when it contains complete cycles. Otherwise the attainable maximum is one tranche lower. A single workforce-wide cycle minimizes exposure at every smaller group size within that class.
A second result gives the minimum number of reviewer changes needed to eliminate short cycles when all new pairings are permitted. This is a useful benchmark for the disruption a repair requires. It does not make an employee qualified to perform a new review or extend an approval limit.
Unequal amounts, eligibility restrictions, additional duties and alternative access paths require their own calculation. The research separates the exact balanced-class result from the constrained operational problem so that a mathematically attractive assignment is never mistaken for an implementable recommendation.
The feasible repair has a price
The weighted six-record example makes that distinction concrete. Its identities, amounts and permissions are constructed. Ignoring reviewer eligibility, two changes reduce maximum three-person access from 300,000 dollars to 200,000 dollars. Both new pairings, however, are forbidden by the specified permissions.
The unique eligible repair requires four changes and reduces three-person exposure to 220,000 dollars. It meets the selected two- and three-person caps, but raises maximum four-person exposure from 300,000 dollars to 310,000 dollars. The improvement and the deterioration belong in the same recommendation.
If management also requires four-person exposure to remain at or below 300,000 dollars, that repair is rejected and no eligible reassignment meets all the stated targets. The result then identifies a policy decision: existing assignment flexibility is insufficient. Changing an exposure tolerance or a permission is a separate choice, not something the optimisation silently assumes.
Carry the method into an operational file
A twelve-record reconstruction adds delegated approval limits, payment-domain permissions, supplier-owner exclusions and review-effort budgets. Public banking and enterprise-system documentation supplies the process concepts; every employee, cap and assignment in the example is author-constructed.
Equal numbers of reviews do not necessarily mean equal hours. The reconstruction therefore preserves each person’s minute budget as well as assignment counts. Its outputs include changed records, the groups reaching each reported maximum and the coalition sizes at which exposure deteriorates. This makes the recommendation traceable to both its arithmetic and its operational constraints.
Another constructed test adds a vendor-master route to an existing payment. That pathway can give a pair access to money beyond the original two-person cap, even after the ordinary reviewer assignments have been repaired. The payment is counted once whichever route succeeds. The total monetary population stays the same while its accessibility changes.
Accept a design with its residuals visible
The managerial lesson is to assess the full curve rather than one favourable number. A design can improve three-person containment and worsen two-person containment. An average or a selected probability-weighted threshold can conceal the same trade-off. The paper keeps explicit protected sizes and exposure tolerances at the centre of acceptance.
The research combines forensic accounting, graph structure, authorisation modelling and constrained optimisation. Its examples demonstrate a conditional design instrument, with documented computational limits, rather than measured fraud reduction or enterprise-wide scalability. A sound implementation depends on complete authority mapping, valid monetary caps and evidence for every relevant pathway.
That gives control redesign a stronger brief: preserve separation on each record, measure concentration across records, make only eligible changes and expose what remains. The practical value lies in turning a general concern about collusion into a checkable account of access and a recommendation whose benefits and costs can both be examined.