Join our Newsletter — 33% off our NHI Course

SoD Policy Drift

The gap that appears when a segregation of duties policy no longer matches how the business actually operates. It usually emerges after application changes, role changes, or process redesign, and it weakens both compliance evidence and real-world control effectiveness.

What SoD Policy Drift Means in Practice

SoD policy drift is not just a documentation issue. It means the policy still says one thing while the operating model, application landscape, or role design now creates different paths for approval, execution, and reconciliation.

That mismatch matters because segregation of duties is only effective when policy, access design, and day-to-day workflows stay aligned. Once drift appears, the policy can remain formally correct on paper while the control fails in practice.

Drift often shows up after application releases, workflow automation, reorganisations, outsourced process changes, or new exceptions introduced to keep operations moving. The result is usually a growing distance between the original control intent and the actual permission structure.

How SoD Policy Drift Develops

SoD policy drift typically begins with a real business change. A new system module, a merged team, a reworked approval chain, or a temporary mitigation becomes permanent, but the conflict matrix and role model are not updated with the same speed.

That is why drift is often invisible inside routine operations. Teams may continue to see clean policy language, while the underlying transactions, entitlements, and delegated approvals have changed enough to create new toxic combinations or obsolete restrictions.

Segregation of Duties (SoD) Guide explains how SoD rulesets, toxic combinations, and compensating controls should be managed as the business changes.

Why Policy Drift Weakens the Control

The security problem is that SoD is both a policy and an operating control. If the policy no longer reflects the actual process, the organisation can no longer rely on it as evidence that conflicting actions are prevented or detected.

That weakens compliance assurance, but it also weakens practical control effectiveness. A drifted policy can miss new separation failures, overstate the strength of mitigations, or fail to capture newly introduced shared access paths across systems and teams.

In mature environments, SoD drift is often tied to broader identity and access change patterns, including role redesign and entitlement sprawl. Salesloft OAuth token breach is a useful reminder that access relationships can change materially when tokens, integrations, or delegated access are not governed as the environment evolves.

Signals That SoD Policy Drift Is Emerging

Common signals include recurring manual exceptions, role names that no longer match job functions, approvals that bypass the documented path, and controls that only work because a team member knows how to operate around them. A policy can also drift when compensating controls become the real control but are never formally revalidated.

Another warning sign is when audit findings, control attestations, and operational reports start describing different realities. When that happens, the gap is no longer theoretical, because the control design and the control execution have diverged.

SoD drift deserves attention whenever process redesign, automation, or organisational change occurs faster than control maintenance. At that point, the question is not whether the policy exists, but whether it still describes the environment that people actually use.

Risk and Threat Considerations

SoD policy drift creates control blind spots because attackers, insiders, and even ordinary users can benefit from separation gaps that the policy no longer captures. It also increases the chance that auditors and control owners overestimate the strength of the control environment.

Failure mechanism: A business process changes, but the SoD ruleset, role design, or compensating control model is not updated, leaving new conflicts, exceptions, or shared access paths unaddressed.

Impact: Conflicting actions can be approved, executed, and concealed more easily, which raises fraud risk, weakens compliance evidence, and reduces confidence in the control framework.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-5 — Separation of Duties Directly addresses separation of duties as a control objective for this drift problem.
AC-6 — Least Privilege SoD drift often appears alongside role expansion and excessive access.
CM-3 — Configuration Change Control Policy drift commonly follows application and workflow changes that are not revalidated.
Recommendation — Review and enforce AC-5 rules whenever process or role changes could create new conflicts. Limit access to only the privileges each role needs and remove unnecessary overlap. Require change review to include SoD impact analysis before production changes go live.
ISO/IEC 27001:2022 A.5.18 — Access rights Access-rights governance is central when role and entitlement changes drive SoD drift.
Recommendation — Revalidate access rights after role changes so entitlement structure stays aligned with the SoD model.

Practitioner Guidance

Governance implication: Treat SoD policy as a living control artifact, not a one-time compliance document. The control owner should be responsible for keeping policy, role design, exceptions, and compensating controls synchronized with business and application change.

What to watch for: Repeated exceptions, control overrides, and redesigns that are not followed by a formal SoD review are the clearest signs that drift is accumulating. When those appear, the issue is usually not the policy text itself, but the control model underneath it.

Practitioner takeaway: The most reliable SoD program is the one that is updated at the same speed as the processes it governs.