Segregation of duties is an internal control principle that divides critical tasks among multiple people so that no single individual can both execute and conceal an error or fraud. It separates responsibilities such as authorisation, custody, recording, and reconciliation. It is a core requirement of financial, security, and compliance control frameworks.

Content

  • Effective implementation maps roles to incompatible function pairs and enforces them through access control, approval workflows, and dual authorisation. Where staffing is limited, compensating controls such as independent review or monitoring substitute, and access certifications periodically detect toxic role combinations.