Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · Document and evidence governance

Segregation of duties (SoD)

Also known as: Separation of duties, SoD

German: Funktionstrennung

In internal control and information security, segregation of duties (SoD) is the principle that conflicting tasks — such as requesting, approving, executing and checking a critical action — are assigned to different people or roles, so that no single person can both make an error or commit a fraudulent act and conceal it.

  • Compliance
  • Cybersecurity

In one sentence

Segregation of duties assigns conflicting tasks to different people, so no single person can make and hide an error or a fraudulent act.

What it implies

Segregation of duties (SoD) is associated with 3 further concepts:

Segregation of duties (SoD) implies: Fraud and error prevention, Dual control principle, Compliance and regulation
Segregation of duties (SoD)
  1. Fraud and error preventionFraud and error prevention

    No single person can commit an error or a fraudulent act — such as issuing a fake invoice — and then cover it up themselves.

  2. Dual control principleDual control principle

    Critical steps always require at least two independent parties, for example one who approves and one who executes.

  3. Compliance and regulationInternal control system (ICS)

    Standards and rules such as SOX, ISO/IEC 27001 and MaRisk require controls that keep duties separate.

Example

An engineer prepares a change to the release parameters of a safety PLC program, a second engineer reviews and approves it, and only then does a third role load it to the machine — no one can push an unreviewed change on their own.

How it applies

German uses two words for the principle: Funktionstrennung and, less often, Aufgabentrennung. Both mean the same thing.

  • Three implications: Segregation of duties is associated with three further concepts — it serves fraud and error prevention, it is put into practice through the dual control principle, and it is required by compliance frameworks as part of an internal control system.
  • Finance and procurement: The classic conflicts are creating a supplier and paying it, or entering an invoice and releasing the payment.
  • IT and OT: Administrators should not approve their own access rights or review their own logs. Role-based access control and privileged access management enforce the separation technically; the audit trail shows whether it held.
  • Engineering and documentation: Author and reviewer of a safety-relevant document or a software change are different people; change control records who prepared, approved and released it.
  • Small teams: Where there are too few people to separate every duty, compensating controls — later review, logging, management checks — take the place of full separation. Document that decision.

Segregation of duties vs. dual control

Segregation of duties is the organizational principle: conflicting tasks go to different roles. The dual control principle is one way to apply it to a single critical step, where a second, independent person must approve or take part. An organization can separate duties across a process without requiring two people for every step.

Naming the principle in a policy does not by itself show that an organization meets SOX, ISO/IEC 27001 or any other requirement; auditors look for the separation in actual roles, rights and records.

By knowledge.aitechdoc.world · Published September 29, 2026 · Last reviewed

Source: ISO/IEC 27001:2022, Annex A, control 5.3 Segregation of duties (guidance in ISO/IEC 27002:2022)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Knowledge and are not part of any standard.

Seen a mistake? Send us a note!