Join our Newsletter — 33% off our NHI Course

Notifications
Clear all

Segregation of duties in finance systems: are your controls provable?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20605
Topic starter  

TL;DR: Manual segregation of duties checks break down when ERP roles bundle incompatible permissions, creating hidden overlaps in vendor setup, payments, journals, and reconciliations, according to SafePaaS. The governance problem is no longer whether a policy exists, but whether finance teams can prove continuous enforcement across complex systems.

NHIMG editorial — based on content published by SafePaaS: segregation of duties in modern finance and ERP environments

Questions worth separating out

Q: What breaks when segregation of duties relies on annual spreadsheet reviews?

A: Annual spreadsheet reviews fail because they see access too late and too abstractly.

Q: How should teams implement segregation of duties in finance and ERP systems?

A: Start by mapping the full transaction path, then split creation, approval, posting, and reconciliation across different roles.

Q: How do organisations know whether segregation of duties is actually working?

A: Segregation of duties is working only if no identity can combine enough permissions to complete the full banking workflow without an independent check.

Practitioner guidance

  • Map finance duties to incompatible activity pairs Build a business-language SoD matrix for supplier maintenance, payment approval, journal posting, and reconciliation.
  • Test live ERP access continuously Run automated checks against current users, roles, and privilege combinations across SAP, Oracle, and connected finance applications.
  • Separate reconciliation from transaction ownership Ensure the person reconciling bank, payroll, or clearing accounts does not also initiate, approve, or correct the underlying transactions.

What's in the full article

SafePaaS's full article covers the operational detail this post intentionally leaves for the source:

  • Finance-language examples of incompatible duty pairs across vendor setup, invoice processing, payment approval, and reconciliation
  • Role-level examples from SAP and Oracle that show how hidden privilege combinations emerge in real ERP deployments
  • Workflow and audit trail detail for routing SoD conflicts, approvals, and compensating controls
  • Practical guidance on translating a segregation of duties matrix into preventive and detective controls

👉 Read SafePaaS's analysis of segregation of duties failures in modern finance →

Segregation of duties in finance systems: are your controls provable?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 4 months ago
Posts: 20196
 

Segregation of duties has become an access governance problem, not a policy problem. The article shows that the real failure sits in the gap between written control design and live ERP entitlement combinations. Once a role can carry supplier changes, payment approval, and reconciliation access in one package, the policy statement loses meaning. For IAM and IGA teams, the discipline is to prove incompatible access cannot coexist in the active role model.

A question worth separating out:

Q: What should organisations do when finance access exceptions keep reappearing?

A: Treat recurring exceptions as role design failure, not as one-off approvals. Re-examine the underlying business process, remove unnecessary inherited privileges, and make exception approvals time-bound with explicit ownership. If the same conflict keeps returning, the access model is compensating for a broken operating design rather than enforcing one.

👉 Read our full editorial: Segregation of duties in ERP finance: why paper controls fail



   
ReplyQuote
Share: