When SoD is weak across portfolio companies, one identity can initiate, approve, and reconcile the same business process. That makes financial misstatement, fraud, and control override easier to hide because the review path is separated from the action path only on paper. The practical failure is not just excess access, but control inheritance across acquired entities.
How SoD breaks inside portfolio-company operating models
segregation of duties fails when the same person or role can create, approve, and close out the same transaction path. In private equity portfolios, that failure is often amplified by inherited controls, shared templates, and post-acquisition urgency, where access is copied faster than governance is rebuilt. The result is a control design that looks distributed on paper but behaves like single-person authority in practice.
That matters because SoD is not just a policy statement, it is a control boundary. When portfolio companies keep local exceptions, shared admin rights, or informal workarounds, the boundary between initiation and independent review disappears. IAM and IGA Basics is useful here because the underlying problem is access governance, not just process documentation.
In acquired entities, the weak point is usually not one dramatic override, but many small exceptions that accumulate across finance, procurement, payroll, and treasury. Once those exceptions are inherited, the business can still produce approvals and reconciliations, yet the approvals no longer provide meaningful assurance. That is why SoD has to be designed around actual entitlement paths, not only organizational charts.
Why the control failure is especially dangerous in portfolio companies
Portfolio-company environments create a common failure pattern: central owners expect standard controls, but local systems, staffing gaps, and integration delays keep legacy permissions alive. That makes the control environment uneven across subsidiaries, so one company may have robust review while another retains concentrated power in a single finance user or shared service role. Segregation of Duties (SoD) Guide is the clearest internal reference for the toxic-combination problem and for extending SoD beyond traditional human roles.
When SoD is weak, the main exposure is concealment. A person who can both execute and attest to a transaction can suppress evidence, delay reconciliation, or normalize an exception before anyone notices the pattern. That increases the chance that misstatement, fraud, or unauthorized spending survives routine review because the reviewer is not independent in a meaningful way.
The practical risk is broader than fraud alone. Weak SoD also undermines management reporting, auditability, and acquisition integration because control ownership becomes ambiguous across the parent and the portfolio company. In that environment, control inheritance can spread the same weak model to multiple entities, multiplying the blast radius of one design failure.
What practitioners should look for before trusting SoD
The decisive question is not whether SoD exists in policy, but whether conflicting actions are technically and operationally blocked. If a role can initiate a vendor setup, approve payment, and reconcile the ledger, the control is already compromised even if separate people nominally own each step. That is the signal to test permissions, not just process narratives.
What to verify: confirm that critical business flows have independent approvers, that emergency access is time-bound, and that legacy access from pre-acquisition systems has been re-certified after integration. Where control ownership is split across parent and subsidiary teams, verify that the review path is actually outside the action path, not merely downstream of it.
Decision rule: if a portfolio company cannot demonstrate independent initiation, approval, and reconciliation for its highest-risk financial processes, treat the gap as a control design issue rather than a training issue. Training can reduce mistakes, but it does not create segregation when the entitlement model still allows one person to do everything.
What practitioners underestimate: inherited exceptions are sticky. A temporary acquisition workaround often becomes permanent because local teams depend on it, and that is how a short-term integration decision turns into durable control override.
Risk and Threat Considerations
Weak SoD across portfolio companies creates a direct exposure to misstatement, fraud, and hidden override because the same identity can act, approve, and validate the same business event. In practice, that makes control failure easier to blend into normal operations, especially when acquired entities retain inconsistent access models or informal compensating controls.
Failure mechanism: excessive or inherited entitlements let one user or role span initiation, approval, and reconciliation, so the review step no longer provides independent challenge. The weakness often persists because the access model is copied during acquisition and never fully re-baselined across finance and control functions.
Impact: management reporting becomes less trustworthy, audit evidence becomes weaker, and the same defect can propagate across multiple subsidiaries, increasing the scope of any concealment or abuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | SoD itself is the central control issue in the question. |
| AC-6 — Least Privilege | Inherited excess access is a key reason SoD fails across portfolio companies. | |
| Recommendation — Enforce AC-5 so no single role can initiate, approve, and reconcile the same process. Restrict privileges to the minimum needed for each finance and control role. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access-right governance underpins SoD in acquired entities and shared service models. |
| A.8.2 — Privileged access rights | Privileged users can bypass normal process segregation if their access is not controlled. | |
| Recommendation — Review and remove conflicting access rights after acquisition and during periodic recertification. Tighten privileged access so no administrator can override finance controls unchecked. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The question is about whether access boundaries prevent one identity from doing everything. |
| Recommendation — Use access control management to remove conflicting entitlements and enforce independent approvals. | ||
Practitioner Guidance
What to prioritise: focus first on the highest-risk transaction paths, usually procure-to-pay, journal entry, vendor master changes, treasury movements, and manual adjustments. These are the places where a single conflicted role can create the largest financial and audit impact.
What to measure: track the number of toxic combinations, temporary access exceptions, and post-acquisition roles that still cross approve-and-execute boundaries. If those metrics are not trending down after integration, the control program is not yet enforcing segregation, only documenting it.
Common mistake: treating SoD as a finance-policy exercise instead of an access-governance exercise. If entitlements are not removed, recertified, and independently monitored, the control will fail even when the process narrative sounds sound.
Practitioner takeaway: in private equity portfolios, SoD breaks most dangerously when control inheritance outlives the acquisition phase, because the business keeps the same authority pattern while assuming the new ownership model has already fixed it.
Related resources from NHI Mgmt Group
- How should private equity firms govern privileged access across portfolio companies?
- How should private equity firms implement internal controls to reduce financial misstatement and fraud risk across portfolio companies?
- What breaks when segregation of duties is not enforced in identity governance?
- What breaks when segregation of duties is enforced only in core ERP?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org