Join our Newsletter — 33% off our NHI Course

Segregation of duties in internal controls - what are teams missing?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Segregation of duties reduces fraud and audit risk by splitting authorization, custody, and recordkeeping, and an ACFE survey cited by SecurEnds found organisations with strong SoD controls detected fraud 50% faster than those without. The governance lesson is that control design only works when access, approvals, and evidence are separated and reviewed continuously.

Editorial analysis by NHI Mgmt Group, based on content published by SecurEnds: “Segregation of Duties in Internal Controls: Framework and Best Practices”.

Key questions

Q: What breaks when segregation of duties is not continuously monitored?

A: Toxic combinations can persist unnoticed in privileged, financial, and regulated-data workflows.

Q: Why do weak duties controls increase compliance risk?

A: Because auditors and regulators expect evidence that no one person can control a critical process from start to finish.

Q: How do organisations know whether segregation of duties is actually working?

A: Segregation of duties is working only if no identity can combine enough permissions to complete the full banking workflow without an independent check.

Practitioner guidance

  • Map toxic duty combinations Inventory which roles can create, approve, execute, and record the same transaction inside finance, payroll, IT, and HR workflows.
  • Rebuild roles around control checkpoints Design entitlements so that approval, custody, and recordkeeping sit in different roles, even when one person performs multiple business tasks in practice.
  • Enforce continuous SoD review Use periodic and event-driven access reviews to catch role drift, temporary exceptions, and inherited rights before they become standing access.

Bottom line: The article shows that segregation of duties is fundamentally about preventing one identity from controlling a high-risk process end to end.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

Segregation of duties is an identity governance problem before it is an accounting control. The article is right to frame SoD as a baseline defense, because the real issue is whether one identity can traverse a critical process without a second actor interrupting it. That is an IAM design failure, not just a finance policy gap. Practitioners should treat toxic duty combinations as access architecture defects.

A question worth separating out:

Q: What should smaller organisations do when they cannot fully separate duties?

A: Use documented compensating controls such as independent review, supervisor sign-off, and rotating responsibilities, but treat them as temporary exceptions with clear ownership. The goal is to preserve independent oversight, even if the team is too small for perfect role separation in every process.

👉 Read our full editorial: Segregation of duties in internal controls is still a live IAM issue


This post was modified 5 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.