Glossary · Document and evidence governance
Segregation of duties (SoD)
Also known as: Separation of duties, SoD
German: Funktionstrennung
In internal control and information security, segregation of duties (SoD) is the principle that conflicting tasks — such as requesting, approving, executing and checking a critical action — are assigned to different people or roles, so that no single person can both make an error or commit a fraudulent act and conceal it.
- Compliance
- Cybersecurity
In one sentence
Segregation of duties assigns conflicting tasks to different people, so no single person can make and hide an error or a fraudulent act.
What it implies
Segregation of duties (SoD) is associated with 3 further concepts:
- Fraud and error preventionFraud and error prevention
No single person can commit an error or a fraudulent act — such as issuing a fake invoice — and then cover it up themselves.
- Dual control principleDual control principle
Critical steps always require at least two independent parties, for example one who approves and one who executes.
- Compliance and regulationInternal control system (ICS)
Standards and rules such as SOX, ISO/IEC 27001 and MaRisk require controls that keep duties separate.
Example
An engineer prepares a change to the release parameters of a safety PLC program, a second engineer reviews and approves it, and only then does a third role load it to the machine — no one can push an unreviewed change on their own.
How it applies
German uses two words for the principle: Funktionstrennung and, less often, Aufgabentrennung. Both mean the same thing.
- Three implications: Segregation of duties is associated with three further concepts — it serves fraud and error prevention, it is put into practice through the dual control principle, and it is required by compliance frameworks as part of an internal control system.
- Finance and procurement: The classic conflicts are creating a supplier and paying it, or entering an invoice and releasing the payment.
- IT and OT: Administrators should not approve their own access rights or review their own logs. Role-based access control and privileged access management enforce the separation technically; the audit trail shows whether it held.
- Engineering and documentation: Author and reviewer of a safety-relevant document or a software change are different people; change control records who prepared, approved and released it.
- Small teams: Where there are too few people to separate every duty, compensating controls — later review, logging, management checks — take the place of full separation. Document that decision.
Segregation of duties vs. dual control
Segregation of duties is the organizational principle: conflicting tasks go to different roles. The dual control principle is one way to apply it to a single critical step, where a second, independent person must approve or take part. An organization can separate duties across a process without requiring two people for every step.
Naming the principle in a policy does not by itself show that an organization meets SOX, ISO/IEC 27001 or any other requirement; auditors look for the separation in actual roles, rights and records.