Look for evidence that employee setup, payroll calculation, payment authorisation, and reconciliation are owned by different roles and that access reviews flag conflicts before each pay cycle. If the same account can complete more than one of those steps, the control is not effective.
How do organisations tell whether payroll SoD is really working?
Payroll segregation of duties works only when the process has real separation, not just a policy on paper. The practical test is whether one person or one account can complete incompatible steps end to end, especially where setup, calculation, approval, and reconciliation can be combined in the same hands.
What evidence shows the control is operating every pay cycle?
Look for role ownership that is genuinely split across the payroll lifecycle: employee setup, payroll calculation, payment authorisation, and post-run reconciliation. A working control produces audit evidence that each step has a different owner, that exceptions are reviewed before release, and that access reviews identify toxic combinations before payroll is executed. Organisations should also confirm that compensating controls are documented where true separation is not possible, because a manual workaround without oversight is usually just a control gap with a different label. For a deeper control model, see the Segregation of Duties (SoD) Guide.
In practice, the strongest evidence is not a one-time matrix, but recurring proof: who submitted changes, who approved them, who ran payroll, who released payment, and who reconciled the results. If access recertification never surfaces conflicts, that can be a warning sign rather than reassurance, because an absent finding may mean the review is too shallow to detect combined authority.
What failure patterns usually mean payroll SoD is ineffective?
The common failure is hidden concentration of authority. One user may not hold every formal role, but they can still control the workflow through shared admin access, delegated permissions, emergency access, or a service account used to bypass approvals. Another failure pattern is weak review quality: the review exists, but it checks names instead of effective permissions, so conflicting access remains visible only after a payroll issue.
If payroll, HR, finance, and systems teams all believe “someone else” owns the control, the process often drifts into informal approval chains that are hard to test and easier to override. The control also weakens when exceptions are permanent, when reviews happen after payment release, or when reconciliations are performed by the same people who prepared the run.
Risk and Threat Considerations
Payroll SoD failures matter because they create both fraud opportunity and error concealment. When setup, calculation, approval, and reconciliation are not independently controlled, a single mistake or malicious action can propagate into payment without timely challenge, and weak access design can let one account approve, alter, and conceal the same transaction path.
Failure mechanism: Combined roles, shared credentials, or broad delegated access collapse the check-and-balance model, so conflicting actions are no longer forced through independent review before money moves.
Impact: The organisation can overpay, pay the wrong recipient, miss duplicate or ghost employees, or fail to detect manipulation until after funds are released and recovery is harder.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | Payroll SoD is a direct separation-of-duties control problem. |
| AC-6 — Least Privilege | Payroll access should be limited to the minimum rights needed for each step. | |
| AU-6 — Audit Review, Analysis, and Reporting | Proving payroll SoD needs reviewable evidence of who did what and when. | |
| Recommendation — Enforce AC-5 so incompatible payroll duties cannot sit with one role or account. Apply AC-6 to remove unnecessary payroll permissions and reduce toxic combinations. Use AU-6 to review payroll activity and confirm incompatible actions did not occur. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Payroll SoD depends on governed access paths and role boundaries. |
| A.5.18 — Access rights | Periodic access reviews are central to detecting payroll SoD conflicts. | |
| Recommendation — Implement A.5.15 to govern payroll access and prevent conflicting authority. Review A.5.18 access rights regularly to catch combined payroll permissions. | ||
Practitioner Guidance
What to verify: Test the actual payroll workflow, not the policy wording. You want evidence that each critical step is enforced by different people or systems, and that the review looks at effective permissions, not only job titles or directory groups.
Decision rule: If one account can create or change an employee record and also approve or release the payroll run, treat the control as failed until the access path is removed or tightly compensating controls are in place.
What good looks like: Conflicts are detected before each pay cycle, exceptions are temporary and approved, and reconciliations are independent enough to catch both accidental and intentional changes. The best signal is repeatable prevention, not just post-pay investigation.
Practitioner takeaway: Payroll SoD is only real when the control prevents a single identity from carrying the process across incompatible steps, and the review process reliably proves that separation every cycle.