Common signs include users who can both create and approve transactions, admins who review their own privileged activity, recurring access creep, and unresolved toxic entitlement combinations. If those patterns appear across ERP, cloud, or IAM systems, the control is probably being managed as a periodic review exercise rather than an enforced governance rule.
How to spot SoD failure in day-to-day operations
SoD fails when a control that should prevent self-service abuse stops shaping real access decisions. The clearest signal is not a policy document gap, but repeated combinations that let one person or role complete an incompatible workflow end to end, especially when exceptions are allowed without expiry, owner review, or compensating controls.
That shows up as workflow paths that collapse approval boundaries, standing access that never gets reviewed out, and toxic combinations that are tolerated because they are convenient. In practice, the question is whether the control still blocks risky combinations before they can be used, or whether it only records them after the fact.
Where SoD governance breaks down most often
Failure usually appears first in the edge cases: emergency access that becomes routine, privileged users who can certify their own access, or ERP and cloud roles that accumulate through repeated exceptions. When SoD is managed as a quarterly checklist, governance may look active while the underlying access model keeps drifting.
The control is also weak when ownership is unclear. If no one is accountable for reconciling role design, approvals, and actual entitlements, toxic combinations survive because each team sees only part of the path. A mature SoD program makes the conflict visible at design time, during provisioning, and again during recertification.
What the pattern means for control design
A recurring SoD issue usually means the organisation is relying on manual review to compensate for an access model that is too permissive or too fragmented. The fix is not just more attestations, but clearer policy logic, better role engineering, and enforcement points that stop incompatible access before it is granted. For broader role and access governance, the Segregation of Duties (SoD) Guide is a useful reference point.
Where SoD is applied across business systems, the control should align with actual transaction paths, not abstract job titles. That matters in ERP, IAM, and cloud environments because toxic combinations often emerge when a role is reused across functions that should never be combined, or when a privileged override bypasses the standard approval chain.
Risk and Threat Considerations
Weak SoD governance increases the chance of fraud, misuse, and undetected privilege abuse because the same actor can initiate, approve, and sometimes conceal a sensitive action. The risk becomes more serious when exceptions are normalised, because the organisation loses the ability to distinguish a true emergency from routine privilege expansion.
Failure mechanism: Conflicting entitlements, self-approval paths, and stale exceptions let a user or administrator complete incompatible steps without an independent check, which defeats the control's purpose.
Impact: Unauthorized transactions, audit findings, policy exceptions that never expire, and a materially higher likelihood of fraud or concealed misuse across ERP, cloud, and IAM workflows.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.3 — Segregation of duties | SoD failures map directly to duty separation control design. |
| Recommendation — Define and enforce incompatible duties before granting access or approving exceptions. | ||
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | This is the core federal control for preventing conflicting access and approval paths. |
| AC-6 — Least Privilege | Access creep and toxic combinations are often symptoms of excessive privilege. | |
| AU-6 — Audit Review, Analysis, and Reporting | Self-review and unresolved conflicts require independent audit visibility. | |
| Recommendation — Identify conflicting duties and enforce separation in workflows and access grants. Remove unnecessary privileges that allow a single actor to complete incompatible tasks. Review privileged activity independently and escalate unresolved conflicts. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | SoD governance depends on lifecycle control of access grants and exceptions. |
| Recommendation — Review, remove, and document access that creates conflicting duties. | ||
Practitioner Guidance
What to verify: Confirm that SoD rules are enforced at provisioning and transaction time, not only in periodic reviews. If conflicts are found only during recertification, the control is already too late to stop abuse.
Decision rule: If a person can both create and approve a sensitive transaction, treat that as a control failure unless a documented compensating control is independently operating and time-bound. If the exception has no owner, expiry, or audit trail, it should be treated as unresolved.
What good looks like: Conflicts are detected before access is activated, exceptions are rare and deliberate, and ownership exists for both the role model and the remediation path. The organisation should be able to show which combinations are prohibited, which are temporarily allowed, and who signs off on each one.
Practitioner takeaway: SoD is failing when governance can describe the conflict but cannot prevent the conflict from being used. A working program blocks toxic combinations by design and only permits exceptions that are explicit, bounded, and continuously visible.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org