Role based access control gives people the accounts payable permissions needed for their responsibilities and no more. It reduces accidental changes, limits the effect of a compromised account and supports separation between invoice preparation, approval and payment.

RBAC is not a set and forget list of job titles. Effective access reflects legal entity, department, authority limit, employment status and temporary responsibilities, with regular evidence that the design still matches real work.

What is role based access control in AP?

Role based access control (RBAC) assigns system permissions to defined roles, then assigns users to those roles according to approved job responsibilities rather than granting access individually without a consistent model.

A role might allow invoice preparation without approval, approval within a defined authority limit, supplier administration, reporting or organisation wide administration. Entity scope can further restrict which company records a person can see or change.

Roles make access understandable, but they must be granular enough to avoid an “administrator for convenience” culture. High risk actions deserve explicit permissions and stronger review.

Typical accounts payable responsibilities

Preparer

Capture and code

Reviews invoice data, resolves routine fields and prepares the record without approving its own purchase.

Approver

Commercial decision

Confirms receipt, budget and authority for assigned invoices within the relevant entity.

Administrator

Configuration

Manages users, roles, integrations or workflow settings under controlled change procedures.

Reviewer

Oversight

Reads reports, audit history and exceptions without routine mutation rights.

Supplier maintenance and payment release often sit in connected systems. Include them in the end to end access model even if the AP platform cannot enforce those external permissions.

Separate duties that become risky together

  1. Supplier creation and payment. The person establishing bank details should not independently release money to them.
  2. Invoice preparation and approval. Prevent inappropriate self approval and route purchases to an accountable budget owner.
  3. Approval and bank release. Treat commercial approval and payment authorisation as related but distinct decisions.
  4. Administration and monitoring. Powerful users should not be the only people reviewing their own role or configuration changes.

A small team may not be able to assign every task to a different employee. Separate the highest risk combinations first, use dual authorisation and add an independent documented review as a compensating control.

Emergency access needs an expiry. Record why elevated access was granted, who approved it, what the user did and when the access was removed.

Control the complete access lifecycle

JoinApprove a role, entity scope and authority appropriate to the job.
ChangeRemove old access before or when responsibilities move.
LeaveDisable access promptly and transfer owned tasks visibly.

Use a reliable identity source, multi factor authentication and individual accounts. Shared logins make it difficult to revoke one person, investigate activity or prove who approved a transaction.

Review high risk access more frequently than basic read access. Ask managers to confirm actual need, not merely whether a familiar name remains employed. Remove unused permissions and stale temporary delegation.

Evidence that RBAC is operating

Retain role definitions, approval records, user assignments, authority limits, entity scope, access review decisions and change history. Monitor failed access, unusual administrator actions, self approval attempts, decisions outside normal scope and activity after a role change.

RBAC supports governance but does not certify compliance with UK law, an audit standard or a particular framework. The organisation must determine the requirements that apply and test whether its configured controls operate in practice.

For the wider control environment, read How to build stronger accounts payable controls.

Give each AP user a clear operating role

Keep invoice preparation, approval and entity access visible while retaining a timestamped decision history.

Frequently asked questions

What is RBAC in accounts payable?

Role based access control grants AP permissions according to defined job responsibilities, such as invoice preparation, approval, administration, reporting or payment release.

Which AP duties should be separated?

Separate supplier maintenance, invoice preparation, commercial approval, payment release and reconciliation where practical, with compensating review when a small team cannot fully divide them.

How often should AP permissions be reviewed?

Review permissions regularly and whenever someone joins, changes role or leaves. High risk administrative, supplier and approval access should receive more frequent scrutiny.

Does RBAC prove compliance?

No. RBAC supports control design, but organisations must configure it correctly, monitor its operation, retain evidence and assess the legal or regulatory requirements that apply to them.

Authored by Tayyib Ali

Tayyib writes practical guides for finance teams building role clarity, approval control and reliable audit evidence.