Separation of Duties (SoD)
Separation of duties is the principle of preventing a single subject from holding conflicting capabilities that could enable fraud, abuse, or uncontrolled critical actions.
- Acronym
- SoD
- Synonym
- Segregation of DutiesSeparation of Responsibilities
Definition
Separation of duties, often abbreviated SoD, is an authorization and governance principle designed to prevent toxic combinations of privileges by distributing critical tasks across different individuals or controlled approval paths. It can be static, where conflicting access rights must never be assigned together, or dynamic, where conflicts are evaluated at execution time within a process. SoD controls are especially important in finance, ERP, privileged administration, identity administration, procurement, and any process involving creation, approval, execution, and reconciliation steps. Mature SoD models require clear conflict definitions, compensating controls, exception governance, and traceability. Separation of duties is also called segregation of duties: the two names describe the same control principle. Conflicts frequently span several applications, so inter-application SoD, access simulation before granting rights, and documented mitigating controls are part of a mature model.
Why it matters
Separation of duties is essential for reducing insider risk, fraud scenarios, and unmonitored concentration of power.
The Ariovis perspective
Segregation of duties must be tied to meaningful risk scenarios and supported by ownership, detection, decisions and remediation. A static list of conflicts is not enough.
Related services
Common pitfalls
- A frequent problem is defining SoD rules at a very abstract level without mapping them to real permissions, transactions, roles, and operational exceptions.
- Limiting SoD analysis to a single application leaves conflicts that are spread across several systems undetected.
Standards and protocols
- SOX
- ISO/IEC 27001
- NIST SP 800-53
Resources
Explore this category
These concepts matter most inside a real project.
The first conversation helps establish your context, the systems involved and the next useful decision.