Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Document and evidence governance

Dual control principle

Also known as: Four-eyes principle

German: Vier-Augen-Prinzip

In internal control, the dual control principle (four-eyes principle) requires that a critical step — such as approving a payment, releasing a document or granting privileged access — is carried out or confirmed by at least two independent people, typically one who executes and one who approves.

  • Compliance
  • Cybersecurity

In one sentence

The dual control principle requires at least two independent people for a critical step, typically one who approves and one who executes.

Example

A technical writer finalizes the safety chapter of an instruction manual; the release in the content management system only goes through once a second, independent reviewer has approved it.

How it applies

  • Independence: The second person must be independent of the first — not their subordinate acting on instruction, and not the same person under a second account. Shared accounts defeat the principle.
  • Documentation: Release workflows for safety-relevant documents, change control and the release decision for software are typical places for a second approval. Record both people in the audit trail.
  • Systems: Many content, ERP and PLM systems can enforce a second approval technically, so the rule does not depend on discipline alone.

Dual control vs. segregation of duties

The dual control principle applies segregation of duties to one critical step by requiring two independent parties. Segregation of duties is broader: it separates conflicting tasks across a whole process.

By knowledge.aitechdoc.world · Published September 29, 2026 · Last reviewed

Source: AI TechDoc Knowledge editorial definition, based on internal control practice (COSO Internal Control — Integrated Framework) and ISO/IEC 27002:2022, control 5.3

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!