IT & Cyber Audit
Segregation-of-Duties Conflicts
When one person can both initiate and approve a sensitive transaction, the single most fundamental fraud control has failed.
Why SoD Conflicts Matter
Segregation of duties ensures that no individual controls a transaction from start to finish, a principle central to COSO, the MFMA control framework and every credible ITGC assessment. Toxic role combinations โ create vendor and approve payment, capture and authorise journals โ let a single user perpetrate and conceal fraud without collusion. AuditPro Core analyses role assignments for these conflicting combinations so the entity can remove or compensate for them before they are exploited.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Active conflicts
128
โผ 22 vs prior
High-risk conflicts
31
Users affected
97
Mitigated
64%
Conflicts by risk rating
Top toxic role pairs
| Role pair | Users | Rating | Mitigated |
|---|---|---|---|
| Create vendor / Approve payment | 14 | Critical | 6 |
| Post journal / Approve journal | 11 | Critical | 5 |
| Maintain payroll / Run payroll | 9 | High | 4 |
| Receive goods / Approve invoice | 17 | High | 9 |
| Edit master / Approve master | 8 | Medium | 6 |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Toxic combinations
A toxic combination is any pairing of duties that should never sit with one person, such as creating a supplier and approving its invoice. These combinations are defined in advance and tested against actual access.
Inherent versus mitigated conflict
Sometimes a conflict cannot be removed in a small unit and must instead be mitigated by a compensating control such as independent review. The dashboard distinguishes unmanaged conflicts from those with a documented mitigation.
Access-driven exposure
SoD conflicts arise from the access a user holds, so they must be tested against live entitlements, not the org chart. A formally separated duty means nothing if one login can perform both steps.
How AuditPro Core Bridges the Gap
- Conflict ruleset: predefined toxic combinations are tested continuously against actual system entitlements.
- Exception workflow: each conflict routes for removal or for a documented compensating control.
- Traceability to source: every conflict links to the specific roles and users that create it.
- Audit-ready export: the SoD matrix and mitigations export as evidence for the ITGC and COSO control assessment.
Key Takeaways
- SoD is the baseline control against single-actor fraud; conflicts undermine it directly.
- Test against live access, not the organogram โ entitlements are where conflicts live.
- Where conflicts cannot be removed, a documented compensating control is mandatory.
- An unmanaged toxic combination is a finding waiting to be written.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ every figure traceable to source.
