An ABA practice segregation of duties matrix maps who can request, approve, execute, hold assets or data, record, reconcile, review, and override important work. It identifies conflicts such as one person creating a vendor, approving an invoice, and releasing payment. Small practices can use documented compensating review when full separation is impractical. The matrix does not transfer clinical decisions to unqualified reviewers.
Define the segregation of duties matrix
Zain maps duties at the action and permission level, then checks the related job titles. He reviews system capability, actual assignment, backup coverage, emergency overrides, and evidence of compensating review. Every row has a stable identifier, owner, custodian, source, effective period, state, evidence, exception, change trigger, next review, and relationship to the decisions it supports.
Choose fields that support the decision
Record workflow and transaction, risk, request role, approval role, execution role, custody role, recording role, reconciliation role, reviewer, override and emergency authority, system permission, incompatible combination, assigned people, backup, conflict, compensating control, review frequency, population, evidence, exception, temporary access, expiry, finding, corrective owner, validation, and residual risk decision.
Separate source facts from practice decisions
For each duty combination, record the policy, role authorization, system configuration, approval rule, contract condition, or risk decision that establishes whether the combination is allowed. The practice's supported, held, conditional, retired, or exception state appears in a separate field with an owner and date. A portal result, marketing statement, verbal comment, identifier, or old approval never silently becomes controlling evidence.
Set entry, review, and retirement rules
Define when a duty combination enters the matrix, when it may be assigned, who reviews it, which role or system changes reopen review, and when it is retired. Source expiry, staff changes, new sites, payer updates, system releases, incidents, audit findings, contract changes, and capacity shifts can trigger review. Historical versions remain available for older transactions and explanations.
Connect fields to real workflow gates
Trace which purchasing, payroll, billing, access, approval, refund, reporting, and audit steps rely on each duty assignment. Software may surface a current state and block a defined release. Authorized roles decide exceptions and qualified clinicians retain clinical judgment. The operational record keeps each decision and author visible.
Make a bounded operating decision
The practice chooses a control response that fits the actual conflict. Prevention blocks one person from holding incompatible permissions. Detection uses timely independent review of a complete population. Dual approval requires two qualified decisions before execution. Temporary access expires automatically and receives after-the-fact review when the workflow allows it. In a small practice, an owner may perform several duties, so the matrix states the compensating reviewer, evidence, frequency, and escalation threshold. Clinical approval remains with a qualified clinician even when finance or compliance reviews the related transaction.
Reconcile independent source populations
Reconcile the segregation-of-duties matrix against role definitions, access logs, approval histories, purchases, payroll, refunds, claims, bank activity, and incident reports. Differences receive an owner, consequence, next action, due date, and validation instead of disappearing through manual overwrites.
A fictional example
Zain reviews 25 material workflows. Seventeen have acceptable separation or tested compensating control. Two let one person create and pay vendors, one combines claim posting and refund approval, two have broad access overrides, one lacks backup review, and two temporary conflicts never expired. Six repair. Two require redesigned controls. The scenario is synthetic. It tests scope, evidence, state, exception, and denominator logic without establishing legal compliance, clinical quality, coverage, payment, licensure, competence, security, financial accuracy, client satisfaction, or outcome.
Calculate compatible measures
Initial conflict-control readiness is 17 of 25, or 68.0%. Twenty-three workflows validate, or 92.0%. Workflows, duties, people, permissions, conflicts, transactions, reviews, and exceptions remain separate.
Control the main risk
An organization chart can hide that several named roles belong to one person. Zain tests the actual people and permissions behind each duty, including service accounts and emergency access.
Test hard cases
Test vendor setup, invoice payment, payroll change, claim correction, refund, write-off, user creation, access approval, record correction, clinical order, emergency override, and owner-performed review. Each case shows the source, owner, current state, affected workflow, immediate safeguard, exception route, correction, validation, and retirement or next-review rule.
Close the review with open work visible
Before closing the review, confirm population completeness, source currency, decision authority, qualified ownership, evidence, cross-register links, exceptions, change triggers, workflow use, validation, unresolved work, and next review. The segregation of duties matrix remains draft until every named reviewer completes the required review.
Use CASP as organizational context
Use the CASP Organizational Guidelines public overview for high-level business, clinical-operations, and risk-management context. CASP sells the detailed guidance. The public page does not prescribe this segregation of duties matrix, prove a row is complete, or grant authority for where incompatible control over a transaction or record needs prevention, review, or monitoring.
Apply voluntary compliance guidance carefully
When reviewing the segregation-of-duties matrix, treat the OIG General Compliance Program Guidance as voluntary and nonbinding. Its discussions of risk assessment, policies, training, reporting, audits, corrective action, incentives, and oversight help test register design. Current law, contract, payer, professional, workforce, privacy, finance, and operational sources control each real decision.
Keep business orientation separate from authority
For broad business context around the segregation-of-duties matrix, use the SBA Manage Your Business guide as orientation across finances, employees, compliance, marketing, emergencies, and closure. It gives no ABA clinical, payer, privacy, licensure, facility, credentialing, tax, or legal authority. The register cites current primary sources for every material state.
Preserve clinical decision rights
For professional duties reflected in the segregation-of-duties matrix, apply the current BACB Ethics Code only to covered people and professional activities. The Code addresses competence, responsibility, client involvement, documentation, supervision, risk, evaluation, billing, and reporting. BACB has no separate corporate jurisdiction. Organizational ownership and register custody never replace qualified case-specific clinical judgment.
Scope privacy and security fields
For electronic PHI represented in the segregation-of-duties matrix, use HHS risk-analysis guidance when a covered entity or business associate must assess risks and vulnerabilities to all electronic protected health information it creates, receives, maintains, or transmits. HHS minimum-necessary guidance informs role-based PHI access when that standard applies. Neither source mandates a particular database, register, score, spreadsheet, or vendor product.
Use cybersecurity and provider identifiers within limits
For cybersecurity and identifier dependencies in the segregation-of-duties matrix, the practice can adapt the NIST Cybersecurity Framework as voluntary risk-management guidance while current legal and contractual requirements remain controlling. The CMS NPI fact sheet distinguishes individual and organizational identifiers and states that an NPI does not establish licensure, credentialing, enrollment, or payment. Identifiers connect records; they do not validate the underlying configuration.
Design a visible compensating review
A small practice may need one person to initiate and record a transaction, but that does not make the conflict disappear. Define which independent person reviews it, what evidence and population they examine, how quickly, what exceptions stop processing, and where the result is retained. Reassess after staffing, system, volume, or authority changes. A manager's general awareness is not the same as a performed and documented compensating control.
Related resources
- ABA Practice Access Review: Role Changes, Least Privilege, and Removal
- ABA Practice Operational Dependency Map: People, Systems, Vendors, and Facilities
- Audit ABA Practice Foundational Registers and Control Evidence
- ABA Practice Control Evidence Register: Proving Policies Operate
Sources
- Council of Autism Service Providers, Organizational Guidelines public overview
- HHS Office of Inspector General, General Compliance Program Guidance
- U.S. Small Business Administration, Manage Your Business
- Behavior Analyst Certification Board, Ethics Code for Behavior Analysts
- U.S. Department of Health and Human Services, Guidance on Risk Analysis
- U.S. Department of Health and Human Services, Minimum Necessary Requirement
- National Institute of Standards and Technology, Cybersecurity Framework
- Centers for Medicare and Medicaid Services, National Provider Identifier Fact Sheet