Glossary · Document and evidence governance
Dual control principle
Also known as: Four-eyes principle
German: Vier-Augen-Prinzip
In internal control, the dual control principle (four-eyes principle) requires that a critical step — such as approving a payment, releasing a document or granting privileged access — is carried out or confirmed by at least two independent people, typically one who executes and one who approves.
- Compliance
- Cybersecurity
In one sentence
The dual control principle requires at least two independent people for a critical step, typically one who approves and one who executes.
Example
A technical writer finalizes the safety chapter of an instruction manual; the release in the content management system only goes through once a second, independent reviewer has approved it.
How it applies
- Independence: The second person must be independent of the first — not their subordinate acting on instruction, and not the same person under a second account. Shared accounts defeat the principle.
- Documentation: Release workflows for safety-relevant documents, change control and the release decision for software are typical places for a second approval. Record both people in the audit trail.
- Systems: Many content, ERP and PLM systems can enforce a second approval technically, so the rule does not depend on discipline alone.
Dual control vs. segregation of duties
The dual control principle applies segregation of duties to one critical step by requiring two independent parties. Segregation of duties is broader: it separates conflicting tasks across a whole process.