
Many small business owners in Singapore run their accounts the way they run everything else in the early years: one person raises the invoice, approves it, pays it and reconciles the bank statement at the end of the month. It works, until it does not. Good internal controls for small businesses do not require a finance team or expensive software. They require a handful of deliberate checks, built around segregation of duties, that a lean team can still run on a tight budget.
This article, “Good Internal Controls for Small Businesses: Segregation of Duties on a Budget”, sets out what internal controls mean for a Singapore SME, the steps to introduce them with just two or three people on the accounts function, and how a corporate secretary Singapore firm can support the process.
Who this applies to
This guidance is most relevant to:
- Private companies limited by shares with a small owner-operator team handling both operations and finance
- Businesses approaching audit thresholds under the Companies Act, where auditors ask about controls before numbers
- Companies that have recently hired their first finance or admin employee and want to avoid concentrating too much authority in one person
- Founders preparing for external financing, where lenders and investors review how cash and approvals are controlled
Key rules and requirements in Singapore
Singapore law does not prescribe a specific internal control framework for private companies, but several obligations make controls a practical necessity rather than a nice-to-have.
- Proper accounting records: Under the Companies Act, directors must ensure the company keeps accounting records that sufficiently explain its transactions and financial position. Weak controls make this duty harder to discharge and harder to evidence if ACRA or an auditor asks questions.
- Directors’ general duties: Directors are expected to act with reasonable diligence, which includes basic safeguards around company funds. A single-signatory bank account with no independent review sits uneasily with that duty once a company has any scale.
- Audit thresholds: Once a company exceeds two of the three small company thresholds for revenue, total assets and employee count, it needs a statutory audit. Auditors test controls during risk assessment, and weak segregation of duties usually means more testing, higher fees and a longer audit.
- Tax recordkeeping: IRAS requires supporting documents for income and expenses to be kept for five years. If one person can create, approve and file a transaction unchecked, the risk of errors slipping into your GST returns or corporate tax computation rises.
- CPF, payroll and data access: Controls over who can add employees or change salaries reduce error and misuse in payroll and CPF contributions, and support Personal Data Protection Act compliance by limiting who has unrestricted access to payroll records.

Step-by-step process
You do not need a full finance department to build reasonable controls. A phased approach works well for a small team.
- 1. Map who does what today. Write down who raises purchase requests, approves them, makes payments and reconciles the bank account. Most small businesses find the same one or two people in every box.
- 2. Split the highest-risk steps first. You cannot separate every task with three staff, so prioritise cash. Aim to have the person who approves a payment be different from the person who executes it, even if that just means a director approves and an admin staff member releases it through online banking.
- 3. Use bank-level controls as a free safeguard. Most Singapore banks let you set a payment approval limit or second-signatory requirement at no extra cost. This is the cheapest control available and should be switched on from day one.
- 4. Introduce a simple approval trail. A shared spreadsheet or an email approval before payment is issued is enough, as long as it records that someone other than the preparer reviewed the transaction.
- 5. Rotate or spot-check reconciliations. If one person always reconciles the bank account, have a director or another staff member review it monthly. This single habit catches a large share of both errors and irregularities.
- 6. Review access when roles change. Remove banking and accounting system access as soon as someone leaves, not at the next audit. Outdated access is a common gap found in a first statutory audit.
- 7. Write it down. A one-page controls memo listing who can approve what, and at what value, is enough for most small companies and gives your auditor something concrete to work from.
Common mistakes to avoid
- Treating internal controls as something only larger companies need, then scrambling to build them once an auditor or investor asks.
- Giving one person sole access to online banking, the accounting system and the company chop or e-signature all at once.
- Assuming trust in a long-serving employee removes the need for basic checks. Controls protect good employees from suspicion as much as they protect the company from error or fraud.
- Building an approval process too complicated for the team size, which staff then quietly bypass under time pressure, or failing to update controls as the company grows from one bookkeeper to a finance team.
- Overlooking supplier master data. Anyone who can both add a new supplier and approve payment to that supplier can create a channel for misdirected funds.
Practical examples
- Two-person approval on payments: A five-person design studio set its bank account so any payment above SGD 2,000 needs a second approver. The founder still authorises daily expenses, while larger transfers need the co-founder’s sign-off, at no cost beyond a settings change.
- Separating supplier setup from payment: A logistics SME allows only the office manager to add a new supplier, while only the finance executive can release payment to that supplier. Neither can complete the full cycle alone.
- Monthly reconciliation review: A retail company has its part-time bookkeeper prepare the monthly bank reconciliation, which a director then reviews and initials before filing. This takes around fifteen minutes a month and has twice caught duplicate supplier payments before they were repeated.

How a corporate secretary can help
A corporate secretary Singapore firm sits close to your statutory records, your Financial Year End timetable and, often, your bookkeeping, which puts it in a good position to design controls that fit your actual size rather than a generic template. Raffles Corporate Services can assist with reviewing your approval processes, drafting a simple controls memo for your board, and coordinating with your accounting and payroll functions so segregation of duties is built into everyday filing, tax and CPF processes rather than bolted on before an audit. Having these basics in place ahead of a statutory audit generally means a smoother, faster engagement with your auditor.
Frequently Asked Questions
Is segregation of duties a legal requirement in Singapore?
There is no standalone law requiring a segregation of duties framework for private companies. It supports legal obligations such as proper accounting records under the Companies Act and IRAS recordkeeping rules, so most auditors and lenders expect to see it once a company has staff beyond the founders.
How many staff do we need before this becomes realistic?
Meaningful segregation is possible with two or three people if you focus on the highest-risk step, usually payment approval and release. Full separation of every accounting task becomes practical once a company has a dedicated finance hire.
What is the cheapest control a very small company can put in place today?
Setting a second-signatory or approval limit on the company’s online banking is usually free and takes minutes to configure, making it the most cost-effective starting point before any system or process changes.
Will weak internal controls delay our first statutory audit?
Often, yes. Auditors assess controls during planning, and where controls are weak they increase the amount of testing performed, which extends timelines and can raise audit fees compared with a company that can evidence basic approval and review steps.
Do internal controls apply to sole proprietorships as well?
The Companies Act duties described here apply to companies rather than sole proprietorships, but separating who approves and who executes payments is good financial discipline for any business structure, including sole proprietorships and partnerships.
Key takeaways
- Internal controls for small businesses do not require a finance department, only a small number of deliberate checks around the highest-risk transactions.
- Segregation of duties supports, rather than replaces, existing obligations such as proper accounting records under the Companies Act and IRAS recordkeeping requirements.
- Free or low-cost measures, such as bank-level payment approval limits and a monthly reconciliation review, deliver most of the benefit for a resource-constrained team.
- Controls should be revisited as the company grows, particularly around banking access, supplier setup and payroll changes.
- Basic controls in place ahead of a first statutory audit generally mean a smoother, faster audit process.
Requirements may change, so always check the latest guidance from ACRA, IRAS or MOM, or consult a professional adviser.
If you would like to find out more about how Raffles Corporate Services can assist with your company’s compliance and corporate secretarial requirements, please get in touch with the team at [email protected].
Yours sincerely,
The editorial team at Raffles Corporate Services
Disclaimer: This does not constitute legal advice. If you require legal advice, please contact a lawyer.
Let’s talk