A maker-checker control separates preparation of a transaction or change from its independent review and approval. The maker enters or proposes the action, and an authorized checker validates it before release.
Where is it used?
- Payments and refunds
- Supplier bank-detail changes
- Journal entries and master data
- Customer credit and pricing overrides
- User access and permission changes
- Contracts and high-risk exceptions
How should the control operate?
The checker should see the complete final record, supporting evidence and policy rule. The system should prevent the maker from acting as checker and require reapproval after a material change.
Maker-checker vs. dual approval
Maker-checker requires one preparer and one independent approver. Dual approval often means two approvers are required, which can be in addition to the preparer. Policy should define the exact role count and independence.
What weakens the control?
Shared accounts, role conflicts, after-the-fact approval, rubber-stamping, unlogged offline consent and broad emergency overrides undermine the separation.
What should the audit trail show?
Record the maker, submitted version, checker, evidence reviewed, decision, timestamps, overrides and changes after approval. A final status alone does not prove independent review.

