By NHI Mgmt Group Editorial TeamBased on SecurEnds: “Segregation of Duties in Internal Controls: Framework and Best Practices” (September 12, 2025)

TL;DR: Segregation of duties reduces fraud and audit risk by splitting authorization, custody, and recordkeeping, and an ACFE survey cited by SecurEnds found organisations with strong SoD controls detected fraud 50% faster than those without. The governance lesson is that control design only works when access, approvals, and evidence are separated and reviewed continuously.


At a glance

What this is: This is a governance piece on segregation of duties, showing how splitting authorization, custody, and recordkeeping reduces fraud and audit risk in internal controls.

Why it matters: It matters because IAM and IGA teams must prevent any one human identity from accumulating enough access and approval power to bypass control checkpoints.


Context

Segregation of duties is a control design principle, not a finance-only procedure. The core idea is that no single person should be able to initiate, approve, execute, and record the same high-risk action, because that concentration of authority removes the checkpoints that make internal controls credible.

For IAM practitioners, the governance question is how identity and access decisions map to business responsibilities. When role design, approval workflows, and audit evidence are not separated, access reviews can confirm permissions on paper while the underlying process still lets one identity complete the whole transaction.

This article frames SoD as an operational control issue that also shows up in payroll, IT, and HR. That wider scope is typical, because the failure mode is always the same: process power becomes identity power when duties are not split.


Key questions

Q: What breaks when segregation of duties is not continuously monitored?

A: Toxic combinations can persist unnoticed in privileged, financial, and regulated-data workflows. Without continuous monitoring, organisations often detect violations only after a transaction, audit finding, or incident. The result is delayed remediation, weaker accountability, and a higher chance that one identity can control both sides of a sensitive process.

Q: Why do weak duties controls increase compliance risk?

A: Because auditors and regulators expect evidence that no one person can control a critical process from start to finish. When access and approval rights overlap, the organisation cannot prove that its governance structure actually separates authority. The result is often a material weakness, not just a policy gap.

Q: How do organisations know whether segregation of duties is actually working?

A: Segregation of duties is working only if no identity can combine enough permissions to complete the full banking workflow without an independent check. The test is not whether a policy exists, but whether cross-system role combinations are blocked before they create an end-to-end abuse path. If combinations are still possible, the control is only documented, not enforced.

Q: What should smaller organisations do when they cannot fully separate duties?

A: Use documented compensating controls such as independent review, supervisor sign-off, and rotating responsibilities, but treat them as temporary exceptions with clear ownership. The goal is to preserve independent oversight, even if the team is too small for perfect role separation in every process.


Technical breakdown

Why overlapping duties break control design

Segregation of duties works by forcing a process to cross identity boundaries before completion. If the same person can create a vendor, approve the invoice, and release payment, the control has no independent checkpoint. In IAM terms, the problem is not just excessive privilege but privilege concentration across workflow stages. That concentration makes fraud easier, errors harder to catch, and audit evidence less trustworthy. SoD is therefore a control architecture problem, not merely a policy statement. Practical implication: model critical processes as multi-actor workflows and deny any role combination that lets one identity control initiation, approval, and recordkeeping.

Practical implication: model critical processes as multi-actor workflows and deny any role combination that lets one identity control initiation, approval, and recordkeeping.

How role-based access control supports segregation of duties

Role-based access control can either enforce SoD or quietly defeat it, depending on how roles are designed. A well-built role set separates duties such as vendor maintenance, payment approval, and ledger posting. A poorly built role set accumulates exceptions until users inherit combinations that recreate end-to-end control in one account. This is why SoD issues often surface inside ERP systems and other business platforms with broad entitlement models. The access model must reflect the business process, not just the job title. Practical implication: review role bundles for toxic combinations and align entitlement design to process checkpoints, not convenience.

Practical implication: review role bundles for toxic combinations and align entitlement design to process checkpoints, not convenience.

Why continuous monitoring matters more than audit-time checks

SoD degrades over time because access changes, job moves, and temporary exceptions accumulate. If teams only review duties at audit time, they see a snapshot rather than the living entitlement pattern that created the risk. Continuous monitoring helps detect when the same user can both approve and record the same transaction, or when compensating controls have quietly become permanent workarounds. In practice, that means SoD is not a once-a-year compliance artifact. It is a runtime governance signal that should be visible in access review, workflow telemetry, and audit logs. Practical implication: monitor toxic duty combinations continuously and treat them as active governance exceptions.

Practical implication: monitor toxic duty combinations continuously and treat them as active governance exceptions.


Threat narrative

Attacker objective: The objective is to complete an unauthorised transaction or conceal an error while preserving the appearance of normal process execution.

  1. Entry occurs when one identity is granted broad workflow access, such as vendor creation, payment approval, or ledger posting rights, within the same business process.
  2. Escalation follows when the same identity can move from initiating a transaction to authorising it, removing the independent check that should stop abuse or errors.
  3. Impact occurs when fraudulent or erroneous transactions are completed and the resulting evidence trail looks legitimate because no separate reviewer was involved.

NHI Mgmt Group analysis

Segregation of duties is an identity governance problem before it is an accounting control. The article is right to frame SoD as a baseline defense, because the real issue is whether one identity can traverse a critical process without a second actor interrupting it. That is an IAM design failure, not just a finance policy gap. Practitioners should treat toxic duty combinations as access architecture defects.

SoD only works when entitlement design reflects process structure. Role-based access control can either separate work or reproduce the same concentration of authority in a cleaner interface. When ERP roles, approval chains, and recordkeeping rights are bundled for convenience, the control is already compromised. Practitioners should align roles to checkpoints, not job labels.

Continuous access review is the control surface that keeps SoD alive. Privilege creep, temporary exceptions, and informal backup duties erode separation long before auditors arrive. That makes SoD a living IGA discipline rather than a static policy statement. Practitioners should govern SoD as an always-on exception management problem.

Compensating controls are acceptable only when they are explicit and temporary. Small teams cannot always split every duty, but supervisor sign-off, independent review, and rotation only work when they are documented as exceptions, not permanent substitutes. The governance lesson is that the control objective matters more than the organisational constraint. Practitioners should prevent temporary workarounds from hardening into normal access.

Segregation of duties creates identity blast-radius control. By splitting custody, approval, and recording, organisations reduce the number of paths an internal actor can use to complete a harmful action. That concept is increasingly important as business systems, IAM, and audit evidence converge in shared platforms. Practitioners should measure SoD as blast-radius reduction, not just compliance coverage.

What this signals

Segregation of duties should be treated as an entitlement design constraint, not an audit-season checkbox. If one identity can hold approval and execution power at the same time, the control is already weakened before any transaction occurs. IAM and IGA teams need to surface those combinations in role engineering and lifecycle governance, then keep them visible as exceptions.

Role clean-up is the practical lever that most programmes underestimate. Over time, temporary access, backup coverage, and job changes quietly rebuild the very concentration SoD is supposed to prevent. The real governance work is to remove those overlaps before they become accepted operating practice.


For practitioners

  • Map toxic duty combinations Inventory which roles can create, approve, execute, and record the same transaction inside finance, payroll, IT, and HR workflows. Remove combinations that let one identity complete an end-to-end process.
  • Rebuild roles around control checkpoints Design entitlements so that approval, custody, and recordkeeping sit in different roles, even when one person performs multiple business tasks in practice.
  • Enforce continuous SoD review Use periodic and event-driven access reviews to catch role drift, temporary exceptions, and inherited rights before they become standing access.
  • Use compensating controls sparingly Where staffing limits prevent perfect segregation, require documented supervisor review, independent sign-off, or rotating duties with a defined expiry.
  • Preserve audit evidence for every exception Keep approvals, sign-offs, and change logs together so auditors can see when a control was intentionally compensated rather than silently bypassed.

Key takeaways

  • The article shows that segregation of duties is fundamentally about preventing one identity from controlling a high-risk process end to end.
  • Its strongest evidence is that strong SoD controls were associated with fraud detection that was 50% faster in the ACFE survey cited by SecurEnds.
  • The control that matters most is separation of approval, custody, and recordkeeping, backed by continuous access review and clear exception handling.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSoD depends on limiting any one identity from holding end-to-end process power.
Recommendation — Apply AC-6 to prevent one account from combining approval, custody, and recordkeeping rights.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is about entitlement design and control separation inside business processes.
Recommendation — Review permissions and authorisations for toxic combinations across critical workflows.
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle and role assignment determine whether SoD stays intact over time.
Recommendation — Use CIS-5 to remove standing access that recreates conflicting duties in business systems.
ISO/IEC 27001:2022A.8.2 — Privileged Access RightsPrivileged rights are the mechanism that lets one identity bypass SoD boundaries.
Recommendation — Restrict privileged access rights so no user can execute and approve the same control path.

Key terms

  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Compensating Control: A compensating control is a measure that reduces risk when the ideal fix, such as immediate patching or redesign, is not possible. In OT, compensating controls often include session recording, access restriction, and tighter monitoring. They do not eliminate the underlying issue, but they narrow exposure until safer remediation can happen.
  • Toxic Role Combination: A set of permissions that should not exist together in one identity because they create conflict, excessive access, or separation-of-duties risk. Graph analysis is useful here because it can trace how multiple roles intersect across systems and reveal hidden combinations that standard reports miss.
  • Continuous Access Review: Continuous access review is the practice of evaluating identity permissions using live usage and behavior signals instead of relying only on periodic certifications. It helps teams find stale access, unusual patterns, and over-permissioned identities before those conditions become incident paths.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org