Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› When should organisations rely on compensating controls instead…
Governance, Ownership & Risk

When should organisations rely on compensating controls instead of perfect SoD splits?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Use compensating controls only when team size or operating model makes a full split impossible, and document the reviewer, frequency, and evidence trail. They are not a substitute for separation, but they can reduce risk where one person must hold more than one function temporarily.

When compensating controls are the right answer, and when they are not

Compensating controls belong in the gap between ideal segregation and operational reality. They are appropriate when a clean SoD split is temporarily or structurally impossible, but only if the compensating design reduces the same conflict risk rather than simply documenting it. The control must be deliberate, reviewable, and strong enough to make the exception traceable.

In practice, that means the organisation is accepting residual risk in exchange for continuity. The compensating control should narrow the opportunity for abuse through review, approval, logging, thresholds, or independent oversight, and it should have a defined end date or review cycle.

What makes a compensating control credible

A compensating control is credible only when it addresses the specific conflict created by the combined duties. For example, if one person can initiate and approve the same transaction, the control must insert an independent check that is hard to bypass, not merely a post hoc report that no one reads.

Documentation matters because auditors and internal reviewers need to see why the split could not be achieved, what exact risk remains, who owns the exception, and how often it is revalidated. A weak exception process quickly becomes a permanent workaround, which defeats the purpose of SoD.

For teams building the control set, Segregation of Duties (SoD) Guide is the most direct reference for building rulesets, identifying toxic combinations, and deciding when mitigations are acceptable.

How to judge whether the exception is still too risky

Use compensating controls only when the business can tolerate the remaining exposure and the control actually changes the abuse path. If the same person can still initiate, alter, and conceal a transaction, the exception is not really controlled, it is only recorded. That is usually a sign the organisation should redesign the process rather than accept the split.

The threshold for acceptance should rise when the action is high impact, hard to detect, or easy to repeat at scale. Temporary exceptions are easier to justify than standing exceptions, and narrow task-based access is safer than broad standing authority that depends on informal trust.

For practitioners aligning this to a wider control set, access review, logging, and least-privilege requirements in NIST SP 800-53 Rev 5 Security and Privacy Controls support the kind of independent oversight compensating controls usually require. The same logic appears in CIS Controls v8, which emphasises controlled account use, auditability, and secure configuration.

Risk and Threat Considerations

Compensating controls reduce exposure, but they also create a dependency on review quality, evidence retention, and exception discipline. The main failure mode is exception drift, where a temporary workaround becomes normal operating practice and the original SoD conflict is never retired.

Failure mechanism: A single individual retains enough combined authority to initiate, approve, and obscure the same action, while oversight becomes predictable, delayed, or incomplete.

Impact: Fraud, unauthorised changes, concealment of mistakes, and audit findings become more likely, especially where transactions are high value or the control is repetitive.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-5 — Separation of DutiesDirectly governs SoD conflicts and exception handling.
AU-6 — Audit Record Review, Analysis, and ReportingCompensating controls rely on reviewable evidence and oversight.
Recommendation — Apply AC-5 to separate conflicting duties and document approved compensating controls. Use AU-6 to review exception activity and preserve evidence trails.
CIS Controls v8CIS-6 — Access Control ManagementSoD compensating controls depend on limiting and reviewing access paths.
Recommendation — Use CIS-6 to restrict conflicting access and validate compensating controls.
ISO/IEC 27001:2022A.5.15 — Access controlSoD exceptions are an access-control governance issue in the ISMS.
Recommendation — Apply A.5.15 to govern exceptions and enforce controlled access boundaries.

Practitioner Guidance

What to prioritise: Decide first whether the exception is truly temporary or whether the operating model has made the split structurally impossible. If it is structural, the compensating control must be designed as a durable control, not a short-term waiver.

What to verify: Confirm that the compensating control includes an independent reviewer, a defined cadence, retained evidence, and a clear trigger for removal or redesign. If any of those elements are missing, the control is too weak to justify the exception.

Common mistake: Treating a report, after-the-fact review, or manager awareness as equivalent to separation. A good compensating control changes the path of abuse, not just the paperwork around it.

Practitioner takeaway: Use compensating controls to contain a real SoD gap, not to normalise it, and review them as exceptions that should be reduced over time, not permanent substitutes for proper separation.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org