Back to Explore
๐ŸŽญ

IT & Cyber Audit

Segregation-of-Duties Conflicts

When one person can both initiate and approve a sensitive transaction, the single most fundamental fraud control has failed.

๐Ÿ“– 6 min read๐ŸŽฏ Intermediateโœ๏ธ Updated 2026

Why SoD Conflicts Matter

Segregation of duties ensures that no individual controls a transaction from start to finish, a principle central to COSO, the MFMA control framework and every credible ITGC assessment. Toxic role combinations โ€” create vendor and approve payment, capture and authorise journals โ€” let a single user perpetrate and conceal fraud without collusion. AuditPro Core analyses role assignments for these conflicting combinations so the entity can remove or compensate for them before they are exploited.

The Numbers

AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.

Active conflicts

128

โ–ผ 22 vs prior

High-risk conflicts

31

Users affected

97

Mitigated

64%

Conflicts by risk rating

Top toxic role pairs

Role pairUsersRatingMitigated
Create vendor / Approve payment14Critical6
Post journal / Approve journal11Critical5
Maintain payroll / Run payroll9High4
Receive goods / Approve invoice17High9
Edit master / Approve master8Medium6

Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.

Toxic combinations

A toxic combination is any pairing of duties that should never sit with one person, such as creating a supplier and approving its invoice. These combinations are defined in advance and tested against actual access.

Inherent versus mitigated conflict

Sometimes a conflict cannot be removed in a small unit and must instead be mitigated by a compensating control such as independent review. The dashboard distinguishes unmanaged conflicts from those with a documented mitigation.

Access-driven exposure

SoD conflicts arise from the access a user holds, so they must be tested against live entitlements, not the org chart. A formally separated duty means nothing if one login can perform both steps.

How AuditPro Core Bridges the Gap

  • Conflict ruleset: predefined toxic combinations are tested continuously against actual system entitlements.
  • Exception workflow: each conflict routes for removal or for a documented compensating control.
  • Traceability to source: every conflict links to the specific roles and users that create it.
  • Audit-ready export: the SoD matrix and mitigations export as evidence for the ITGC and COSO control assessment.

Key Takeaways

  • SoD is the baseline control against single-actor fraud; conflicts undermine it directly.
  • Test against live access, not the organogram โ€” entitlements are where conflicts live.
  • Where conflicts cannot be removed, a documented compensating control is mandatory.
  • An unmanaged toxic combination is a finding waiting to be written.

See This on Your Own Data

AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ€” every figure traceable to source.