Reduce fraud opportunity
Separate initiation, approval, custody and review activities so one person cannot complete and conceal a high-risk transaction.
DataConsultant helps organisations identify incompatible access, strengthen approval boundaries and establish sustainable segregation of duties controls across finance, procurement, HR, enterprise applications, data platforms and privileged administration. Our assessment-led approach connects process risk, role design, access evidence and remediation priorities so decision-makers can reduce preventable fraud, error and unauthorised-change exposure.
Segregation of duties, often shortened to SoD, is the practice of dividing incompatible responsibilities among different people, roles or accounts. The objective is to prevent a single actor from initiating, approving, executing and concealing a sensitive transaction or change without independent oversight.
Practical principle: access should reflect the minimum combination of activities needed for a role, while high-risk exceptions require documented approval, compensating controls, monitoring and periodic review.
Effective SoD controls reduce avoidable risk while improving accountability, access transparency and the quality of audit evidence.
Separate initiation, approval, custody and review activities so one person cannot complete and conceal a high-risk transaction.
Keep development, deployment, access administration and independent review responsibilities appropriately separated.
Create traceable rules, ownership, approvals, exceptions, monitoring evidence and remediation records.
Align business roles, application permissions and identity-governance processes as teams, systems and suppliers change.
Risk: A user can create a vendor, raise a purchase, approve an invoice and influence payment processing.
Response: Define incompatible activities, analyse effective access and redesign roles or approvals.
Risk: Administrators can grant access, alter configurations or data and review their own activity.
Response: Separate administration, approval and monitoring; introduce time-bound access and independent logging review.
Risk: Transfers, temporary assignments and inherited permissions create hidden combinations of access.
Response: Establish joiner-mover-leaver controls, role ownership, recertification and conflict checks before provisioning.
Risk: Compensating reviews exist in principle but lack defined frequency, reviewer independence or retained proof.
Response: Document control design, evidence standards, escalation rules, owners and effectiveness testing.
The engagement can focus on assessment, design, remediation, implementation assurance or ongoing monitoring.
Identify sensitive transactions, critical data changes, privileged activities, approval points and opportunities for concealment. Map each risk to accountable owners and required preventive or detective controls.
Define incompatible activity pairs and risk scenarios using business language, application permissions and regulatory or policy requirements. Rationalise overly broad rules to reduce false positives while protecting material risks.
Analyse users, groups, roles, entitlements and effective permissions to detect direct, inherited, cross-application and privileged conflicts. Review role construction, toxic combinations and access accumulation.
Prioritise conflicts by likelihood, impact, usage and control coverage. Recommend access removal, role redesign, workflow changes, approval separation, time-bound access or documented mitigating controls.
Define decision rights, risk acceptance, exception approval, rule maintenance, evidence retention, review frequency, reporting and escalation across business, technology, security, compliance and internal audit stakeholders.
| Deliverable | Purpose | Typical contents |
|---|---|---|
| Current-state SoD assessment | Establish risk and control baseline | Scope, systems, processes, evidence reviewed, findings, limitations and priority risks |
| Conflict rule matrix | Define incompatible activities consistently | Risk scenario, activity pair, severity, affected process, owner and rationale |
| User and role conflict report | Identify effective access combinations | User, role, entitlement, conflict source, usage evidence, risk and recommended action |
| Remediation backlog | Sequence practical corrective action | Priority, owner, action, dependency, acceptance criteria, target review and residual risk |
| Mitigating-control register | Govern unavoidable exceptions | Control owner, procedure, frequency, reviewer independence, evidence and testing method |
| SoD governance model | Sustain control effectiveness | Decision rights, role ownership, provisioning checks, recertification, reporting and escalation |
Confirm business processes, applications, risk appetite, regulatory drivers, stakeholders and available evidence.
Primary output: scope, responsibility map and evidence request
Identify sensitive actions, approval boundaries, privileged functions and incompatible responsibility combinations.
Primary output: process-risk and activity inventory
Build a proportionate conflict matrix aligned with business language, permissions and material risk.
Primary output: approved SoD rule set
Review roles, groups, entitlements, inheritance, cross-system combinations and privileged accounts.
Primary output: risk-ranked conflict analysis
Evaluate access removal, role redesign, workflow separation, monitoring and mitigating controls.
Primary output: remediation backlog and exception register
Confirm decisions, test selected controls, document ownership and prepare monitoring and review routines.
Primary output: control framework, reporting and knowledge transfer
The service is designed to work across mixed estates and does not require a single vendor platform.
ERP, finance, procurement, HR, payroll, CRM, supply-chain and custom transactional systems.
Identity governance, SSO, directory services, cloud IAM, role-management and access-certification tools.
Databases, data warehouses, lakehouses, analytics tools, cloud consoles, DevOps platforms and PAM solutions.
Independent review of selected processes, applications, roles or audit findings with prioritised recommendations.
Rule-set development, conflict analysis, role redesign, mitigating controls and implementation support.
SoD requirements and control reviews within ERP, cloud, IAM, data-platform or transformation programmes.
Periodic conflict analysis, exception review, KPI reporting, rule maintenance and control-evidence support.
Number of business processes, applications, legal entities, regions, users, roles and privileged accounts.
Availability and consistency of role definitions, entitlement exports, user mappings, activity logs and control records.
Whether the engagement covers assessment only, role redesign, system changes, testing, rollout or managed monitoring.
Sector obligations, internal policies, external-audit requests, documentation depth and specialist review requirements.
Process-owner access, decision speed, workshop volume, approval cycles and dependency on vendors or integrators.
Existing IAM or GRC capabilities, data extraction effort, custom analytics and required integration or automation.
Removing conflicts must not prevent legitimate work. Role changes require business validation, testing and controlled deployment.
Access extracts may contain employee identifiers and security information. Collection, transfer, retention and access should be restricted and documented.
SoD design can support compliance, but it does not replace legal advice, statutory audit, certification or formal risk acceptance by authorised client personnel.
Segregation of duties is a control principle that prevents one person, role or account from completing incompatible activities without independent oversight. It commonly separates initiation, approval, execution, custody, administration and review responsibilities.
Scope can include process-risk mapping, application and role inventories, SoD rule-set design, entitlement analysis, conflict classification, role review, remediation planning, mitigating-control design, governance, reporting and implementation support.
Participation usually includes process owners, finance, procurement, HR, technology, application owners, identity and access teams, security, risk, compliance, internal audit and data-platform owners. Executive sponsorship should sit with an accountable business or control leader.
The assessment can cover ERP, finance, procurement, HR, CRM, identity systems, cloud consoles, databases, data platforms, analytics tools, privileged-access systems and custom applications where incompatible permissions create material risk.
Conflicts are detected by comparing effective user access against an agreed rule matrix. Analysis may include direct permissions, inherited roles, nested groups, cross-application access, privileged accounts and, where available, transaction or activity evidence.
A toxic combination is a set of permissions that allows a user to perform incompatible activities, such as creating a supplier and approving its payment, developing a production change and deploying it, or granting privileged access and reviewing the resulting activity.
No. Some conflicts may be operationally necessary, particularly in small teams or specialist support roles. These should be explicitly approved, risk assessed, time bounded where possible and covered by independent, evidenced mitigating controls.
Common measures include independent transaction review, workflow approval, restricted or time-bound access, enhanced logging, exception reports, supervisory review, dual control, periodic recertification and retrospective monitoring by a separate accountable person.
Timing depends on process and system scope, user and role volumes, data quality, stakeholder access, rule complexity, review cycles and remediation depth. A dependable schedule is established after initial scoping and evidence review.
Pricing is influenced by the number of systems, processes, roles and users; data extraction effort; assessment depth; workshops; regulatory requirements; deliverables; implementation support; and whether ongoing monitoring is included.
Yes. The service can use available exports and workflows from existing identity, GRC, ERP, PAM and access-certification tools. Recommendations can remain vendor neutral unless configuration or implementation support is specifically commissioned.
Yes. SoD requirements can be embedded into role design, migration, testing, deployment gates, access provisioning, privileged administration and post-go-live monitoring for ERP, cloud, data-platform and identity programmes.
Review frequency should reflect risk, change rate, regulatory expectations and control design. High-risk access may require continuous or frequent monitoring, while rule sets, roles, exceptions and certifications should also be reviewed after major organisational or system changes.
Useful inputs include process maps, policies, risk registers, application and role inventories, entitlement exports, user mappings, privileged-account lists, workflow definitions, prior findings, access-review records, exception logs and access to accountable stakeholders.
No. DataConsultant can support control design, assessment and evidence preparation, but the service does not replace legal advice, statutory audit, formal certification or risk acceptance by authorised client personnel unless separately and appropriately commissioned.
Share the processes, systems, audit findings or access concerns you need to address. DataConsultant can help define an appropriate assessment, remediation or monitoring approach.