Separation of duties is a control principle that divides a sensitive task among multiple people or roles so that no single individual can complete it alone, reducing the risk of fraud, error and abuse of privilege. It requires collusion to subvert controls and is foundational to access governance, financial controls and compliance regimes. It complements least-privilege and is operationalised through role-based access control.
Overview
- Separation of duties prevents concentration of power by splitting high-risk activities - for example requesting, approving and disbursing a payment - across distinct roles. It is a cornerstone of internal control and regulatory regimes, and is enforced technically through role design, approval workflows and access governance.
Mechanisms
- Splitting initiation, approval and execution of sensitive tasks.
- Collusion-resistance: multiple parties required to subvert controls.
- Enforcement via role-based access control and approval workflows.
- Pairing with least-privilege and audit trails.
- Detection of toxic role combinations during access reviews.
Applications
- Financial controls and payment authorisation.
- Privileged-access governance in IT systems.
- Regulatory compliance and audit assurance.
- Change-management and deployment approvals.