Join our Newsletter — 33% off our NHI Course

Incompatible Duties

Incompatible duties are tasks that should not be assigned to the same person or identity because combining them removes effective oversight. In IAM and PAM programmes, they often include account creation and approval, or monitoring and remediation of the same activity.

What Incompatible Duties Means in IAM and PAM

Incompatible duties are a core access-governance concept: two tasks are intentionally split so one identity cannot both initiate and independently approve, monitor, or remediate the same high-risk activity.

The idea is less about job titles than about control design. If a single person or service can create access and also approve it, or can both perform and conceal an action, oversight becomes circular and the control loses its value.

Why Segregation of Duties Matters

segregation of duties reduces the chance that one identity can carry a transaction end to end without review. In practice, the control is used to prevent a single user, admin, or privileged workflow from concentrating authority across request, approval, execution, and verification.

This matters most where access changes or privileged actions have material security or compliance impact. A well-designed process keeps the deciding authority separate from the operating authority, so there is always a meaningful second set of eyes.

Common Examples and Failure Patterns

The most common examples are account provisioning and approval, access grant and recertification, monitoring and remediation of the same event, and request handling plus exception approval. These combinations are risky because they let one identity control both the action and the control over that action.

Failure often appears as temporary exceptions that become permanent, or as shared administrative roles that quietly accumulate too much authority. Over time, the organisation may believe it has oversight when in reality the same workflow owner can bypass it.

How to Apply the Control in Practice

The control should be expressed as a policy decision, not just an informal convention. Organisations typically map incompatible functions, then enforce them through role design, workflow approvals, PAM, and periodic review of exceptions.

It is also important to distinguish between operational convenience and control equivalence. If a backup operator, responder, or approver can effectively override the same boundary, the separation has become procedural rather than real.

Risk and Threat Considerations

When incompatible duties are not enforced, the main risk is undetected abuse of privilege, whether accidental or malicious. A single identity that can both act and approve can create self-authorising changes, concealment opportunities, and weaker auditability.

Failure mechanism: The same person or identity can create, approve, execute, and validate an action, so oversight no longer breaks the chain of control.

Impact: Access abuse, fraud, unauthorised privilege expansion, and harder-to-detect administrative compromise become more likely, especially in high-value IAM and PAM workflows.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-5 — Separation of Duties Defines separation of duties for access control and oversight.
AC-6 — Least Privilege Limits the authority that one identity can accumulate across tasks.
Recommendation — Apply AC-5 to separate request, approval, execution, and review for sensitive access changes. Use AC-6 to keep each role narrowly scoped so no identity can both perform and verify the same sensitive action.
CIS Controls v8 6 — Access Control Management Covers account and access governance controls that support duty separation.
Recommendation — Use CIS-6 to formalise access approvals, role boundaries, and periodic review of exceptions.
ISO/IEC 27001:2022 A.5.3 — Segregation of Duties Annex A control specifically addresses incompatible duties in governance.
Recommendation — Implement A.5.3 to separate conflicting responsibilities across approval, administration, and review.
NIST CSF 2.0 PR.AA-05 — Least Privilege CSF 2.0 requires least privilege to reduce over-concentration of access authority.
Recommendation — Apply PR.AA-05 to prevent one identity from holding the full authority chain for a sensitive process.

Practitioner Guidance

Governance implication: Treat incompatible duties as a role and workflow design problem, not just a policy statement. The practical test is whether any identity can independently complete a sensitive transaction without a separate reviewer, approver, or verifier.

What to watch for: Watch for exception paths, shared admin groups, emergency access, and remediation workflows that collapse back into the same team or identity. Those are the places where segregation usually erodes first.