What is Segregation of Duties (SoD)?
Segregation of Duties (SoD), also known as Separation of Duties, is the principle that no single person should hold enough privileges to misuse a system or process for personal gain without detection. ISO 27001 Annex A 5.3 states it plainly: conflicting duties and conflicting areas of responsibility shall be segregated, with the explicit purpose of reducing the risk of fraud, error, and the bypassing of security controls.
A straightforward example makes this concrete. The person who approves salary payments must never be the same person who executes them. Without that separation, an individual could adjust their own pay and authorise the payment themselves, with no one else involved. SoD closes that gap.
Examples of Segregation of Duties
In practice, SoD means separating the roles of requesting, authorising, and executing within any process where a conflict of interest could arise. Common examples include:
Procurement versus payment: A procurement manager selects suppliers, manages tenders, and raises purchase orders. They must not also approve the resulting invoices for payment.
Approval versus accounting: The person who approves expenses must never process those same expenses in the accounts.
Inventory management versus stocktaking: A warehouse manager must not carry out or sign off their own stock counts.
Project management versus evaluation: Project managers lead delivery but must not conduct the formal evaluation or provide their own sign-off.
Change control: The person requesting a system change must not be the same person approving and implementing it.
All of these share the same premise. No process with significant financial or operational risk should be controlled end to end by a single person. This principle is also referred to as the four-eyes principle: a second pair of eyes must always be involved.
Why SoD Matters
The most obvious reason to implement SoD is fraud prevention. Consistent internal controls make it substantially harder for any individual to misuse their access, because no single person controls enough of a process to act without someone else noticing.
But SoD does more than guard against deliberate misconduct. It is equally important to avoid placing people in situations where they could cause harm without ever intending to. Consider a well-meaning employee who encounters serious financial difficulty. What begins as creative accounting to manage cash flow can, without the right controls in place, quickly escalate into fraud. Not planned, not malicious at the outset, but harmful and unlawful all the same.
For these reasons, every organisation of any significant size benefits from an independent external auditor who can assess operations and role separation objectively. In information security specifically, customers and partners increasingly expect that independent verification, whether through ISO 27001 certification or sector-specific audit requirements.
SoD in UK Regulation and Compliance
Segregation of Duties is not just good practice in the UK. It is explicitly required or strongly implied across several major frameworks:
Framework | Applies to | SoD requirement |
|---|---|---|
ISO 27001 Annex A 5.3 | Organisations seeking or holding ISO 27001 certification | Mandatory control where risk assessment identifies that a single individual could compromise a critical process without detection |
FCA SYSC 5.1 | FCA-regulated financial services firms | Senior management must define and maintain arrangements for segregation of duties and prevention of conflicts of interest |
UK Corporate Governance Code 2024, Provision 29 | UK premium listed companies | Board must declare the effectiveness of material internal controls; in force from 1 January 2026 |
UK GDPR | All organisations processing personal data | Controllers must implement appropriate technical and organisational measures, including access controls that limit exposure of personal data |
Benefits of Segregation of Duties
Implementing SoD consistently delivers value across three areas:
Reduced risk of fraud and abuse. Effective internal controls make it substantially harder for individuals to misuse their access, because no single person controls enough of any process to act without oversight.
Fewer unintentional errors. SoD means there is always someone reviewing another person's work. This catches mistakes as well as misconduct, improving accuracy across the board.
Stronger compliance posture. Documented, enforceable SoD controls directly support ISO 27001 certification, FCA supervisory requirements, UK Corporate Governance Code obligations, and UK GDPR compliance.
How to Implement Segregation of Duties
Implementing SoD systematically starts with mapping your key processes and your organisational structure. The goal is to identify where a single person or a small team currently controls too much of a process from start to finish. Once those areas are identified, tasks and responsibilities need to be redistributed.
This is not a one-off exercise. Organisations change: people move roles, teams are restructured, and new systems are introduced. SoD needs to be reviewed regularly to remain effective.
Technology is central to managing this at scale. Most business processes today run through ERP, CRM, financial, and other management systems. Every user of those systems needs access rights that match their role and nothing beyond it. This is the Principle of Least Privilege, and it is the practical foundation on which effective SoD is built.
How HelloID Supports Segregation of Duties
A modern IAM platform such as HelloID makes SoD enforceable, auditable, and scalable across your organisation.
Automated provisioning with conflict prevention
HelloID Provisioning grants access rights automatically based on a person's role, department, competencies, and work location. Within the business rules used to assign those rights, toxic combination policies can be configured to prevent conflicting permissions from being granted in the first place.
Controlled approval for additional access
When a user requires access beyond their standard provisioning, the HelloID Service Automation module routes that request through an approval workflow before any access is granted. Time-limited access can be configured to expire automatically. Segregation policies can also be defined so that access to system A cannot be combined with access to system B where those permissions conflict.
Segregation within the IAM environment itself
HelloID also enforces separation between administrative roles within the platform, ensuring that configuration management is handled by different staff than those who issue individual access rights.
Complete audit trail
Every action in HelloID is logged automatically. If an incident occurs, it is always possible to establish exactly who performed which action and when, providing the audit evidence that ISO 27001 auditors and FCA supervisors require.
To find out how HelloID supports SoD implementation in your organisation, contact our team.