
IIf there's one control auditors reach for before anything else, it's Segregation of Duties (SoD). It's simple in concept — no single person should control an entire high-risk process — and surprisingly easy to violate in practice.
Where SoD Breaks Down:
- The same employee can raise a purchase order and approve it.
- Role changes over time create quiet, unintended conflicts nobody notices.
- SoD policies exist on paper but aren't enforced inside the actual systems.
Why This Keeps Coming Up in Audits:
- SoD violations are a direct, tangible fraud risk — not a theoretical one.
- Manual policy documents don't stop a conflict from happening in real time.
Bottom Line:
Segregation of Duties only works when it's enforced automatically, at the moment access is requested — not discovered months later during a review. Building SoD checks into your access governance process turns a paper policy into a real control.