The control breaks when certification becomes a record-keeping exercise instead of a decision that changes access. Repeated conflicts mean the programme is not closing risk through removal, mitigation, or prevention. In practice, the same toxic entitlement combinations keep surviving across cycles because nothing forces remediation before the next review.
When SoD conflicts keep reappearing, the issue is control failure, not noisy reporting
Recurring segregation of duties findings usually mean the review process is surfacing the same toxic combination without changing the underlying access model. That can happen when roles are too broad, entitlement owners are not accountable, or remediation is deferred into a future cycle. Segregation of Duties (SoD) Guide and the IAM and IGA Basics guide explain why review outcomes must change access, not just document it.
In a healthy programme, the review is the last checkpoint before access is removed, split, constrained, or formally mitigated. If the same conflict survives repeated certifications, the organisation is effectively accepting persistent design debt in the entitlement model. Access Reviews and Certification Guide and Role Mining and Role Design Guide both reflect the structural fix, reduce the volume of review noise and redesign the access model so conflicting access is not continually recreated.
Repeated SoD findings are also a sign that the programme is missing a closed loop between review, ticketing, remediation and preventive controls. When that loop is weak, the same entitlement combination reappears because no one has changed the upstream role, workflow, exception path, or provisioning rule that created it. Segregation of Duties (SoD) Guide and IGA Buyer’s Guide are useful here because both point toward controls that prevent recurrence, not just detect it.
Risk and Threat Considerations
Repeated SoD conflicts create a durable exposure because the conflict itself becomes normalised. That increases the chance of fraud, self-approval, unauthorised change, or unobserved privilege combinations being used in real workflows rather than remaining theoretical policy violations. CIS Controls v8 and NIST SP 800-53 Rev 5 Security and Privacy Controls both support the idea that access governance must be enforced continuously, not only recorded at review time.
Failure mechanism: The same toxic entitlement set survives because review findings are treated as attestations, while remediation, role redesign, or compensating control enforcement is not mandatory before the next cycle. That leaves an exploitable gap between policy and actual access state.
Impact: Risk accumulates across cycles, exceptions multiply, and reviewers lose trust in the control. Over time, the organisation can end up with a permanent class of known conflicts that are only documented, not eliminated.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | SoD conflicts are directly governed by separation of duties controls. |
| AC-6 — Least Privilege | Repeated SoD findings often show roles are broader than necessary. | |
| CA-7 — Continuous Monitoring | Recurring findings show the control must be monitored and acted on continuously. | |
| Recommendation — Enforce AC-5 so recurring conflicting access is removed or formally mitigated. Apply AC-6 to narrow entitlements that keep recreating SoD conflicts. Use CA-7 to track whether review outcomes actually reduce access risk over time. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account and entitlement governance is central when SoD conflicts recur. |
| Recommendation — Use CIS-5 to remove conflicting access and prevent it from reappearing. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | SoD conflicts are an access control governance failure under Annex A. |
| Recommendation — Apply A.5.15 to ensure access decisions change the entitlement state. | ||
Practitioner Guidance
What to verify: Confirm that every repeated SoD finding has a named owner, a due date, and a tracked disposition, removal, mitigation, or redesign. If the same conflict appears again with the same explanation, the programme is not operating as a control and should be treated as a workflow failure.
Decision rule: If a conflict is recurring, stop asking only whether the reviewer approved it and ask why the entitlement path still exists. Either the role model is wrong, the provisioning rule is wrong, or the exception is being allowed to persist without compensating control.
What practitioners underestimate: Recurring SoD conflicts are often a role engineering problem disguised as a review problem. The durable fix is usually to change the access architecture, not to ask reviewers to keep re-approving the same exception.
Practitioner takeaway: A repeated SoD conflict is evidence that the access governance loop is incomplete, because a real review must reduce future exposure as well as record the current one.