Segregation of Duties
Segregation of Duties is a control principle that splits a task or process among more than one person so that no single individual can complete it alone. The idea is that dividing responsibilities makes it harder for any one person to make errors or commit and conceal wrongdoing without being noticed. It is a foundational practice used to strengthen internal controls across finance, security, and operations.
Segregation of Duties (SoD), also termed Separation of Duties, is an internal control principle holding that no single user or role should possess sufficient privileges to complete a sensitive process end-to-end or to misuse a system on their own. It operates by distributing distinct steps of a transaction or workflow—such as authorization, execution, custody, and recording—across separate individuals or roles so that collusion would be required to circumvent the control. SoD supports both preventive controls (blocking incompatible privilege combinations before an action occurs) and detective controls (identifying conflicts or violations after the fact), and it functions to reduce the risk of mistakes and inappropriate actions. As a control principle it is applied at the discretion of an organization or as required by an applicable framework or contract; the specific role separations, thresholds, and enforcement mechanisms depend on the organization's risk profile and system design, and this entry does not address any particular regulatory mandate.
Why it matters
Segregation of Duties addresses a structural weakness in any process where a single person holds concentrated control: the ability to both cause an error and conceal it, or to both commit and hide an inappropriate action. By distributing the distinct steps of a sensitive process—such as authorization, execution, custody, and recording—across separate individuals or roles, an organization reduces the risk that a mistake goes undetected and raises the difficulty of wrongdoing, because circumventing the control would generally require collusion among multiple parties. This is why SoD is widely treated as a foundational element of effective internal control across finance, information security, and operations.
The principle matters because concentration of privilege creates a single point of failure that is difficult to detect from within the process itself. When the same person who authorizes a transaction also executes it and records it, there is no independent check built into the workflow. Segregation reinstates that check by design rather than relying solely on after-the-fact review. In practice, SoD supports both preventive controls that block incompatible privilege combinations before an action can occur and detective controls that surface conflicts or violations afterward.
Segregation of Duties is a control principle rather than a legal requirement in its own right; it is applied at an organization's discretion or where mandated by an applicable framework or contract. The specific role separations, approval thresholds, and enforcement mechanisms depend on the organization's risk profile and system design. Readers should note that where SoD obligations arise, they typically flow from a particular framework, contractual commitment, or sector rule, and those sources—not this general principle—define the precise expectations that apply in a given situation.
Who it's relevant to
Inside SoD
Common questions
Answers to the questions practitioners most commonly ask about SoD.

