A segregation-of-duties matrix that forbids the same person from creating and approving a payment is correct in principle and impossible in a four-person team that also covers leave. Pretending otherwise produces shared logins, after-hours releases on someone else’s ID, and a control environment that looks better in the policy than in the logs.
We start from the cash-moving tasks, not from the vendor’s role names. Create, amend beneficiary, approve, release to bank, and repair a rejected file are the five that matter. If one person must hold two of those, the compensating control has to be detective and timely — a next-day review of a system extract by someone who did not do the payment, with evidence that the review actually happened.
Privileged and vendor accounts are where small teams get hurt. A support ID left enabled ‘for the project’ will outlive the project. Recertification that consists of forwarding a screenshot of the user list is not recertification. We sample the last year of joiners and leavers; the pattern is usually obvious in an afternoon.
The recommended role model we leave behind is sized to the team you have, with a note on what would change if you hired one more operations person. That is more use than a red finding you cannot staff.