Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How do auditors use a segregation of duties…
Governance, Ownership & Risk

How do auditors use a segregation of duties matrix during reviews?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Auditors compare real user access against the matrix to confirm that risky combinations are either separated or formally mitigated. The matrix gives them a fast way to test whether governance matches actual permissions, not just written policy.

How auditors use a segregation of duties matrix in a review

Auditors use the matrix as a test harness for access governance. They do not treat it as a policy artifact alone, they compare live user access, role assignments, and exceptions against the matrix to see whether risky combinations are actually prevented or formally approved and mitigated.

What the matrix lets auditors test

The main value of a segregation of duties matrix is that it turns an abstract control into a testable rule set. It shows which combinations of duties should not sit with the same person, role, or account, and which compensating controls are expected when a conflict cannot be fully removed. In practice, this is how reviewers connect governance intent to actual access review evidence.

Auditors usually look for three things: whether the matrix is complete enough to cover the critical business processes, whether it reflects current job functions and system access paths, and whether it is used consistently when access is granted or recertified. A good matrix also makes it easier to spot role creep, orphaned conflicts, and inconsistent exception handling.

How auditors translate conflicts into findings

Once a conflict is identified, auditors ask whether the issue is truly separated, whether a compensating control exists, and whether that control is strong enough to justify the exception. That is why a matrix is often paired with ticket history, approval records, and evidence of periodic review. The control question is not just “does the conflict exist?” but “has the organisation decided, documented, and monitored the risk?”

This is also where the distinction between designed access and actual access matters. A matrix may say two duties are segregated, but if one role inheritance chain, shared account, or emergency entitlement reintroduces the conflict, the effective control has failed. Reviewers often focus on that mismatch because it reveals where governance is weaker than the formal role model.

Where the review becomes operationally difficult

Segregation of duties reviews become harder when organisations rely on broad roles, temporary exceptions, shared administrative access, or manual compensating controls. In those cases, the matrix must be precise enough to explain why an exception is acceptable and what detects misuse. A weak matrix often fails by being too generic, too static, or disconnected from the systems that actually enforce access.

A practical reviewer will also ask whether the matrix covers high-risk workflows end to end, not just named systems. For example, a conflict can span request, approval, payment, and reconciliation steps even if no single application appears risky on its own. That is why many teams pair the matrix with segregation of duties rulesets that define toxic combinations, mitigations, and exception handling in operational terms.

Risk and Threat Considerations

Segregation of duties gaps create fraud, error, and override risk because one identity can approve, execute, and conceal the same activity. The matrix reduces that exposure only when it reflects actual permissions and is enforced across roles, accounts, and exceptions.

Failure mechanism: risky duty combinations survive through role inheritance, shared access, emergency privileges, weak recertification, or untracked compensating controls, so the conflict exists even when the policy says it should not.

Impact: auditors can miss real concentration of power, management can overstate control effectiveness, and an attacker or insider can exploit the same concentration to alter records, payments, or approvals without meaningful challenge.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-5 — Separation of DutiesDirectly addresses segregation of duties conflicts and compensating controls.
AC-6 — Least PrivilegeSoD reviews often reveal excessive access that should be reduced.
Recommendation — Use AC-5 to define and test conflicting duties, then document mitigations for approved exceptions. Use AC-6 to remove unnecessary access that creates SoD conflicts.
ISO/IEC 27001:2022A.5.3 — Segregation of dutiesDirect ISO Annex A control for separating conflicting responsibilities in governance reviews.
Recommendation — Map critical processes to A.5.3 and verify conflicts are separated or formally mitigated.
CIS Controls v8CIS-6 — Access Control ManagementCovers access governance, review, and reduction of risky permission combinations.
Recommendation — Use CIS-6 to review entitlements and enforce separation of conflicting access.

Practitioner Guidance

What to verify: Check that the matrix is tied to real entitlements, not only job titles. The most useful evidence is a current conflict list, exception approvals, and proof that mitigations are revisited on a defined cadence.

Common mistake: Treating the matrix as a one-time design document. In practice, access models change faster than review cycles, so a matrix that is not refreshed against role engineering and system change will quickly lose audit value.

What good looks like: The review can trace every high-risk conflict to either removal, a documented exception, or a compensating control that is actually operating. That is the point at which the matrix becomes a governance control rather than a spreadsheet.

Practitioner takeaway: Auditors get the most value from a segregation of duties matrix when it is used to test live access against expected control boundaries, not when it is treated as static policy prose.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org