Internal Controls
Segregation of Duties Conflicts
Detected SoD conflicts across business processes with mitigation status and access counts.
Why segregation of duties conflicts matter
Segregation of duties is a foundational preventive control against fraud and error, and SoD breakdowns feature prominently in PRECCA-relevant fraud cases and AGSA findings on supply-chain and payment processes. Detecting conflicts across business processes, with their mitigation status and access counts, exposes where one person can both initiate and conceal an irregular transaction. AuditPro Core maps SoD conflicts to the processes and access they touch so management can mitigate concentrations of incompatible duties before they are exploited.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Active conflicts
64
Users affected
211
Mitigated
38
59% of conflicts
Unmitigated high-risk
11
Conflicts by process
Top conflict rules
| Conflict rule | Users | Mitigated | Risk |
|---|---|---|---|
| Create & approve PO | 41 | 22 | High |
| Maintain vendor & pay | 33 | 19 | High |
| Post & approve JE | 28 | 14 | Medium |
| Hire & set pay | 19 | 11 | Medium |
| Receive & record asset | 14 | 8 | Low |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Incompatible duties
SoD requires that no single individual controls a transaction end to end, for example creating a vendor and approving its payment. Combining such duties removes the natural check that one person watches another.
Conflict versus violation
A detected conflict is the potential for abuse; a violation is its actual occurrence. Tracking conflicts lets management mitigate before harm, rather than investigating after the fact.
Mitigating controls
Where duties genuinely cannot be separated, often in small units, compensating controls such as independent review reduce residual risk. The mitigation status records whether such a control is in place and operating.
Access counts
The number of users holding a conflicting access pairing scales the exposure. A conflict held by one supervised user differs materially from one held across dozens of accounts.
How AuditPro Core Bridges the Gap
- Conflict detection: incompatible duty pairings are identified across business processes from access assignments.
- Mitigation tracking: each conflict carries its mitigation status, distinguishing accepted-with-control from unmanaged exposure.
- Access quantification: conflicts show the count of users affected, scaling exposure for prioritisation.
- Audit-ready conflict register: the SoD matrix exports with mitigation evidence for internal audit and AGSA review.
Key Takeaways
- SoD prevents one person from both committing and concealing irregularity.
- Distinguish conflicts (potential) from violations (actual) to act preventively.
- Where separation is impossible, evidence a compensating control.
- Access counts scale exposure and should drive remediation priority.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records — every figure traceable to source.
