If segregation of duties is checked only at audit time, teams usually discover conflicts after they have already affected operations, reporting, or approvals. That leads to remediation work, delayed attestations, and weak evidence for compliance. Continuous assessment is better because it finds risky role combinations, compensating controls, and exceptions before they become recurring control failures.
Audit-Time Review Creates a Blind Spot, Not a Control
segregation of duties is only effective when it is used to prevent or interrupt conflicting access before the conflict is exercised. If organisations wait until audit time, the control becomes retrospective evidence collection rather than operational prevention, and that changes what can be trusted in approvals, financial workflows, and privileged administration. NIST Cybersecurity Framework 2.0 is useful here because it frames governance and control assurance as ongoing practice rather than a periodic check. In practice, many teams only discover SoD conflicts after a business process has already normalised around them.
How the Control Fails in Practice
At audit time, organisations usually review role assignments, ticket history, and approval trails after the fact. That can tell them whether a conflict existed, but not whether the conflict was already used to approve, create, and release work without meaningful independence. The operational failure is that SoD is treated as a compliance snapshot instead of a living rule over identity, role design, and workflow routing.
When the review happens only once or twice a year, several things break at the same time:
- conflicting access persists long enough to affect multiple transactions
- approvers become accustomed to exceptions that should have been challenged earlier
- compensating controls are never validated under real operating conditions
- attestation evidence becomes weak because it proves review activity, not preventive assurance
- remediation turns into cleanup work that disrupts users, managers, and system owners
This is especially damaging where the same person can initiate, approve, and reconcile work, because the issue is not the existence of a conflict alone but the length of time the organisation allows it to remain active. Continuous monitoring, control testing, or workflow checks reduce that exposure because they surface risky combinations close to the point of assignment or use. NIST SP 800-53 Rev 5 Security and Privacy Controls is relevant where organisations need to align access governance with ongoing review and control operation. Where SoD depends on manual spreadsheets and year-end clean-up, the guidance breaks down because the control no longer intercepts the behaviour it was meant to stop.
When Audit-Only SoD Checks Become an Exception Factory
Tighter segregation often increases operational friction, so organisations have to balance cleaner control boundaries against role design, staffing constraints, and process speed. The common mistake is to let that friction justify deferred review, which turns temporary exceptions into permanent operating conditions.
There is an important distinction between deliberate, time-bound exceptions and uncontrolled drift. A justified exception has an owner, a rationale, a compensating control, and an expiry point. Audit-only review often finds the opposite: stale exceptions, inherited access, and role combinations that were never revalidated after a process change, acquisition, or reorganisation. Industry consensus is clear that SoD should be governed continuously, but there is less agreement on whether the best enforcement point is identity governance, workflow design, or application-layer control. The answer depends on where conflicting authority actually enters the process.
For organisations with complex ERP, finance, procurement, or admin workflows, the edge case is usually not a dramatic policy violation but gradual control erosion. A role that was acceptable in one team can become risky after a merger, automation change, or delegation shift. That is why audit-time review catches symptoms late: it sees the accumulated result of design drift, not the moment the control boundary was crossed. The practical lesson is that SoD must be checked where access is granted or exercised, otherwise the control becomes a report about yesterday’s failure rather than a barrier against today’s one.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.OV — Oversight | SoD needs ongoing governance and oversight, not periodic after-the-fact review. |
| Recommendation — Establish continuous oversight for segregation of duties and track exceptions until closure. | ||
| CIS Controls v8 | 5 — Account Management | Conflicting access is created and persisted through account and role assignments. |
| 6 — Access Control Management | SoD failures are access-control failures when one identity can execute incompatible actions. | |
| Recommendation — Review account and role assignments continuously to prevent conflicting access from lingering. Enforce access separation so incompatible actions cannot be combined in the same role path. | ||
| NIST SP 800-63 | 4.3 — Identity Proofing Records and Integrity | Identity governance evidence must be timely and reliable when access decisions drive SoD outcomes. |
| Recommendation — Retain trustworthy identity and access records that support timely segregation-of-duties decisions. | ||
Practitioner Guidance
What to prioritise: Focus first on the role combinations that can create business impact immediately, especially create/approve, request/fulfil, and administer/audit pairings. If those are only reviewed in periodic attestations, treat them as control design gaps rather than review gaps.
What to verify: Confirm that every exception has a named owner, a compensating control that is actually operating, and a review date that forces revalidation. If the organisation cannot produce that evidence quickly, the SoD process is not yet governable at scale.
What good looks like: Conflicts are identified near assignment time, exceptions are time-bound, and remediation is routine rather than disruptive. The control should reduce recurring findings, not merely generate a cleaner audit trail.
Practitioner takeaway: Audit-time SoD review is useful for proving that a problem exists, but it is too late to prevent the business, financial, or privilege consequence that the conflict may already have caused.
Related resources from NHI Mgmt Group
- How do organisations reduce the dwell time of exposed credentials at scale?
- What breaks when organisations only review mobile AI at design time?
- What breaks when organisations treat compliance as a one-time audit instead of an ongoing program?
- What breaks when organisations rely only on segregation of duties checks in ERP cloud security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org