Skip to content

Segregation of Duties

What is Segregation of Duties?

A governance control that requires more than one person to complete different parts of a task, preventing fraud and errors through shared responsibilities.

Governance

Each of these is named in at least one of the same controls as segregation of duties. The number is how many controls name both.

What the standards actually require on segregation of duties

Requirements naming segregation of duties across 6 standards, quoted from the control text.

C5 (Germany)2 controls

Separate conflicting duties on the basis of the documented risk assessment, at minimum across rights administration and access approval, change development, testing and release, and system operation, and where separation is not feasible monitor those activitie...

C5-OIS-04 · Segregation of Duties

Developers cannot deploy their own changes to production; deployment is performed by separate personnel or automated pipelines with controls

CO-ChangeMgmt-3 · Segregation of Duties in Change Deployment

Access Management and Segregation of Duties. Procedures must manage the allocation of access rights to information systems, and roles and areas of responsibility should be segregated to minimise the risk of unauthorised or unintentional modification or misuse...

BMA-16 · Access Management and Segregation of Duties

Split conflicting duties so no single person can run a sensitive process end to end unchecked.

iso-27001-2022::5.3 · Segregation of duties

Requires duties and areas of responsibility that would conflict if held by one person to be separated, limiting the scope for undetected error, fraud or abuse of privilege.

iso-27002-2022::5.3 · Segregation of duties

Requirement defined in ISO 27018:2019, clause 6.1.2 (Segregation of duties). See licensed source for normative text. Implementation focus is to demonstrate conformity with the obligations of this clause through the artefacts listed in evidence_requirements.

iso-27018-2019::6.1.2 · Segregation of duties

Questions people ask about segregation of duties

What is Segregation of Duties?
A governance control that requires more than one person to complete different parts of a task, preventing fraud and errors through shared responsibilities.
Why is Segregation of Duties important for compliance?
Segregation of Duties is a key concept in Governance. Understanding segregation of duties helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Segregation of Duties?
Segregation of Duties appears in the requirement text of C5 (Germany), SOC 1 (SSAE 18 / ISAE 3402), Bermuda Monetary Authority (BMA) Cyber Risk Management Code of Conduct, ISO 27001:2022, ISO 27002:2022. Across these standards we have identified 8 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Segregation of Duties?
Explore our compliance framework pages to see how segregation of duties applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Segregation of Duties applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.