Delegation of Authority Matrix Validator
Segregation of duties pair

Payment run release and reconciliation sign-off

The role that approves payments also signs off the reconciliation that would show a wrong one. It is read across two lines of the matrix; one role on both sides of one line is read as self-approval instead.

The question for the matrix owner

Who other than a payment approver signs off the bank reconciliation?

The two halves

Clauses

5 clauses
RegimeClause
COSOCOSO P10 Principle 10: Selects and develops control activities
ISO/IEC 27001ISO/IEC 27001 5.3 Segregation of duties
NIST SP 800-53NIST SP 800-53 AC-5 Separation of duties
COBITCOBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authority ยท COBIT DSS06.02 Control the processing of information
COSO P10 Principle 10: Selects and develops control activities

The organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. Points of focus: Integrates with risk assessment; Considers entity-specific factors; Determines relevant business processes; Evaluates a mix of control activity types; Considers at what level activities are applied; Addresses segregation of duties. Control activities are selected and developed integrated with the risk assessment, considering entity-specific factors (environment, complexity, nature, scope), the relevant business processes, a mix of control activity types (preventive and detective, manual and automated), the level at which activities are applied, and segregation of duties where practical, with alternative controls where not.

What an auditor asks to see: Control matrices linking risks to control activities across processes and levels, with segregation of duties analysis
Where matrices usually fall short: Controls not traceable to assessed risks; Segregation conflicts unmitigated
Source: COSO Internal Control, Integrated Framework
ISO/IEC 27001 5.3 Segregation of duties

Split conflicting duties so no single person can run a sensitive process end to end unchecked.

What an auditor asks to see: Role separation matrix; Approval workflow records; Access rights review reports; Segregation conflict log
Where matrices usually fall short: Combining conflicting roles in small teams; Lack of documented exceptions; Infrequent access rights reviews; Reliance on informal approvals
Source: ISO/IEC 27001:2022
NIST SP 800-53 AC-5 Separation of duties

Requires the organization to identify and document the individual duties that must be kept apart to limit malevolent activity without collusion, and to define system access authorizations so that those duties cannot be exercised by one person.

What an auditor asks to see: Documented conflicting duty pairs for the mission and system in question; Role definitions and entitlement mapping showing conflicting duties are not held together; Toxic combination report from the identity system or a manual conflict analysis; Approved exceptions with the compensating detective controls applied
Where matrices usually fall short: Conflicting duties named for finance processes only and never for system administration; Small teams create unavoidable conflicts that are tolerated rather than documented and compensated; Separation enforced at role definition but broken by direct entitlement grants
Source: NIST SP 800-53 Rev 5
COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authority

Business roles, responsibilities, levels of authority and segregation of duties supporting the process objectives are managed, and access to all information assets related to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; levels of authority for approving transactions, transaction limits and other decisions follow approved job roles; sensitive activities are allocated so that duties are clearly segregated; access rights and privileges are the minimum needed for predefined job roles, removed or revised immediately on role change or termination; regular awareness and training cover roles, responsibilities, the importance of controls and the security, integrity, confidentiality and privacy of information; administrative privileges are secured, tracked and controlled to prevent misuse; and access control definitions, logs and exception reports are periodically reviewed so that privileges remain valid and aligned with current staff and roles.

What an auditor asks to see: Authority and limit matrices; segregation of duties allocations; access aligned to roles with prompt removal; privilege reviews and exception reports
Where matrices usually fall short: Transaction limits not enforced in the system; Access accumulated across role changes
Source: COBIT 2019
COBIT DSS06.02 Control the processing of information

The execution of business process activities and related controls is operated on enterprise risk so that information processing is valid, complete, accurate, timely and secure, reflecting legitimate and authorised business use: the originator of transactions is authenticated and their authority verified; duties are segregated between origination and approval; transactions are verified as accurate, complete and valid through controls such as sequence, limit, range, validity, reasonableness, table look-ups, existence, key verification, check digit, completeness, duplicate and logical relationship checks and time edits, with validation rules and criteria reviewed periodically; erroneously input data are corrected and resubmitted without compromising original authorisation levels, retaining original source documents for reconstruction; data integrity and validity are maintained through the processing cycle with erroneous transactions not disrupting valid ones; output is handled in an authorised manner, delivered to the right recipient, protected in transmission and verified for accuracy and completeness; data integrity is maintained through unexpected interruptions and confirmed after failures; and transaction data passed between applications and functions inside or outside the enterprise are checked for proper addressing, authenticity of origin and integrity of content, with authentication and integrity protection in transit.

What an auditor asks to see: Input validation and authorisation controls; segregation of duties matrices; output distribution controls; interface integrity checks; error correction records
Where matrices usually fall short: One person able to originate and approve a payment; Interface files accepted without checking origin or integrity
Source: COBIT 2019