Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations augment IGA when segregation of…
Governance, Ownership & Risk

How should organisations augment IGA when segregation of duties controls need continuous oversight?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 18, 2026 Domain: Governance, Ownership & Risk

Organisations should treat IGA as the access layer, not the full control plane. Pair it with a governance capability that monitors business processes, maintains a living Risk and Controls Matrix, tracks testing frequency, and preserves independent audit evidence. That combination is what supports SoD enforcement, exception handling, and regulator-ready assurance across both access and process controls.

How to Extend IGA Without Turning It Into a False Single Control Plane

When segregation of duties has to work continuously, the key design move is to separate access entitlement administration from control oversight. IGA can confirm who has access and route approvals, but SoD also depends on how transactions, roles, process exceptions, and compensating controls behave in practice. Organisations should therefore combine IGA with process-level monitoring, rule maintenance, and evidence capture.

The practical reason for this split is that SoD failures often emerge after provisioning, not during it. A user can remain formally approved while a downstream business process, shared privilege pattern, or manual override undermines the intended control. That is why governance over the business process itself, not just the identity record, has to stay live.

  • Track the SoD rule set as a living control object, not a one-time policy artifact.
  • Reconcile access decisions against the actual process path, including exceptions and temporary overrides.
  • Keep the control owner, reviewer, and approver model explicit so audit evidence is attributable.

For the access layer itself, the most useful extension point is a control layer that can observe entitlement changes, business-rule breaches, and exception ageing in near real time. Where the organisation has material NHI exposure, the same logic should cover service and application access paths, because process exceptions and stale privileges can accumulate outside human review cycles.

Why Continuous Oversight Needs a Living Risk and Controls Matrix

A living Risk and Controls Matrix is what makes SoD oversight operational instead of ceremonial. It links each critical business process to the relevant control objective, the testing cadence, the evidence source, and the person accountable for remediation. Without that structure, organisations tend to detect violations inconsistently and cannot explain whether a control failure is isolated, repeated, or systemic.

The matrix also helps distinguish between a true access problem and a process-design problem. If a control fails because the workflow permits conflicting steps, re-approving access will not fix it. If the failure is caused by stale entitlement data, then recertification or privilege reduction may be enough. That distinction matters because the response, ownership, and retest timing are different.

NHI Mgmt Group’s Ultimate Guide to NHIs is useful here because it frames governance as lifecycle, visibility, and auditability, not just initial access approval. For practitioners, that is the right mental model when SoD must remain effective across changing roles, integrations, and automation paths.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementSoD oversight depends on managing conflicting access and exception paths.
8 — Audit Log ManagementContinuous SoD oversight needs durable evidence of approvals, overrides, and violations.
Recommendation — Enforce access control rules and review exceptions on a recurring basis. Retain and review logs that show SoD breaches, overrides, and remediation timing.
NIST CSF 2.0GV.RM — Risk Management StrategyA living control matrix links SoD enforcement to enterprise risk treatment and ownership.
PR.AA — Identity Management, Authentication and Access ControlIGA is the access layer that must support SoD entitlements and approvals.
DE.CM — Continuous MonitoringSoD controls need ongoing monitoring of business process behaviour and exceptions.
Recommendation — Define SoD risk ownership, review cadence, and escalation thresholds in governance. Align access approvals and entitlement reviews with SoD policy requirements. Continuously monitor for conflicting transactions, control drift, and unresolved exceptions.

Practitioner Guidance

What to prioritise: Start with the business processes where a single conflicting action would create the largest financial, operational, or compliance consequence. Those are the places where continuous SoD oversight should be measured first, because broad access reviews alone will miss the highest-risk process paths.

What to verify: Make sure every material SoD rule has three things: a named owner, a repeatable test method, and preserved evidence of both exceptions and resolution. If any of those are missing, the organisation may have access administration, but it does not yet have defendable continuous control.

What good looks like: The control environment should be able to show when a rule changed, why an exception was approved, how long it stayed open, and what evidence proves the issue was re-tested. That is the point at which IGA becomes part of assurance rather than the whole story.

Practitioner takeaway: Treat SoD as an ongoing control assurance problem, not an access review problem, and design the oversight layer so it can prove both rule enforcement and exception handling over time.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org