Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when organisations only review segregation of…
Governance, Ownership & Risk

What breaks when organisations only review segregation of duties at audit time?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 7, 2026 Domain: Governance, Ownership & Risk

If segregation of duties is checked only at audit time, teams usually discover conflicts after they have already affected operations, reporting, or approvals. That leads to remediation work, delayed attestations, and weak evidence for compliance. Continuous assessment is better because it finds risky role combinations, compensating controls, and exceptions before they become recurring control failures.

Audit-Time Review Creates a Blind Spot, Not a Control

segregation of duties is only effective when it is used to prevent or interrupt conflicting access before the conflict is exercised. If organisations wait until audit time, the control becomes retrospective evidence collection rather than operational prevention, and that changes what can be trusted in approvals, financial workflows, and privileged administration. NIST Cybersecurity Framework 2.0 is useful here because it frames governance and control assurance as ongoing practice rather than a periodic check. In practice, many teams only discover SoD conflicts after a business process has already normalised around them.

How the Control Fails in Practice

At audit time, organisations usually review role assignments, ticket history, and approval trails after the fact. That can tell them whether a conflict existed, but not whether the conflict was already used to approve, create, and release work without meaningful independence. The operational failure is that SoD is treated as a compliance snapshot instead of a living rule over identity, role design, and workflow routing.

When the review happens only once or twice a year, several things break at the same time:

  • conflicting access persists long enough to affect multiple transactions
  • approvers become accustomed to exceptions that should have been challenged earlier
  • compensating controls are never validated under real operating conditions
  • attestation evidence becomes weak because it proves review activity, not preventive assurance
  • remediation turns into cleanup work that disrupts users, managers, and system owners

This is especially damaging where the same person can initiate, approve, and reconcile work, because the issue is not the existence of a conflict alone but the length of time the organisation allows it to remain active. Continuous monitoring, control testing, or workflow checks reduce that exposure because they surface risky combinations close to the point of assignment or use. NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant where organisations need to align access governance with ongoing review and control operation. Where SoD depends on manual spreadsheets and year-end clean-up, the guidance breaks down because the control no longer intercepts the behaviour it was meant to stop.

When Audit-Only SoD Checks Become an Exception Factory

Tighter segregation often increases operational friction, so organisations have to balance cleaner control boundaries against role design, staffing constraints, and process speed. The common mistake is to let that friction justify deferred review, which turns temporary exceptions into permanent operating conditions.

There is an important distinction between deliberate, time-bound exceptions and uncontrolled drift. A justified exception has an owner, a rationale, a compensating control, and an expiry point. Audit-only review often finds the opposite: stale exceptions, inherited access, and role combinations that were never revalidated after a process change, acquisition, or reorganisation. Industry consensus is clear that SoD should be governed continuously, but there is less agreement on whether the best enforcement point is identity governance, workflow design, or application-layer control. The answer depends on where conflicting authority actually enters the process.

For organisations with complex ERP, finance, procurement, or admin workflows, the edge case is usually not a dramatic policy violation but gradual control erosion. A role that was acceptable in one team can become risky after a merger, automation change, or delegation shift. That is why audit-time review catches symptoms late: it sees the accumulated result of design drift, not the moment the control boundary was crossed. The practical lesson is that SoD must be checked where access is granted or exercised, otherwise the control becomes a report about yesterday’s failure rather than a barrier against today’s one.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV — OversightSoD needs ongoing governance and oversight, not periodic after-the-fact review.
Recommendation — Establish continuous oversight for segregation of duties and track exceptions until closure.
CIS Controls v85 — Account ManagementConflicting access is created and persisted through account and role assignments.
6 — Access Control ManagementSoD failures are access-control failures when one identity can execute incompatible actions.
Recommendation — Review account and role assignments continuously to prevent conflicting access from lingering. Enforce access separation so incompatible actions cannot be combined in the same role path.
NIST SP 800-634.3 — Identity Proofing Records and IntegrityIdentity governance evidence must be timely and reliable when access decisions drive SoD outcomes.
Recommendation — Retain trustworthy identity and access records that support timely segregation-of-duties decisions.

Practitioner Guidance

What to prioritise: Focus first on the role combinations that can create business impact immediately, especially create/approve, request/fulfil, and administer/audit pairings. If those are only reviewed in periodic attestations, treat them as control design gaps rather than review gaps.

What to verify: Confirm that every exception has a named owner, a compensating control that is actually operating, and a review date that forces revalidation. If the organisation cannot produce that evidence quickly, the SoD process is not yet governable at scale.

What good looks like: Conflicts are identified near assignment time, exceptions are time-bound, and remediation is routine rather than disruptive. The control should reduce recurring findings, not merely generate a cleaner audit trail.

Practitioner takeaway: Audit-time SoD review is useful for proving that a problem exists, but it is too late to prevent the business, financial, or privilege consequence that the conflict may already have caused.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 7, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org