Raising and approving journals
The role that prepares journals also approves them on other lines, so its own entries can reach the ledger unreviewed. It is read across two lines of the matrix; one role on both sides of one line is read as self-approval instead.
The question for the matrix owner
Who reviews the journals this role prepares, and at what amount does a second reviewer come in?
The two halves
- Raising journal entries
- Approving journal entries, by the same role
Clauses
6 clauses| Regime | Clause |
|---|---|
| COSO | COSO P10 Principle 10: Selects and develops control activities |
| SOX | SOX FRAUD-3 Journal Entry Review and Approval ยท SOX FRAUD-2 Management Override Controls |
| ISO/IEC 27001 | ISO/IEC 27001 5.3 Segregation of duties |
| NIST SP 800-53 | NIST SP 800-53 AC-5 Separation of duties |
| COBIT | COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authority |
COSO P10 Principle 10: Selects and develops control activitiesThe organization selects and develops control activities that contribute to the mitigation of risks to the achievement of objectives to acceptable levels. Points of focus: Integrates with risk assessment; Considers entity-specific factors; Determines relevant business processes; Evaluates a mix of control activity types; Considers at what level activities are applied; Addresses segregation of duties. Control activities are selected and developed integrated with the risk assessment, considering entity-specific factors (environment, complexity, nature, scope), the relevant business processes, a mix of control activity types (preventive and detective, manual and automated), the level at which activities are applied, and segregation of duties where practical, with alternative controls where not.
Where matrices usually fall short: Controls not traceable to assessed risks; Segregation conflicts unmitigated
Source: COSO Internal Control, Integrated Framework
SOX FRAUD-3 Journal Entry Review and ApprovalManual journal entries are reviewed and approved by someone other than the preparer with supporting documentation.
Where matrices usually fall short: Risk-based criteria for entry selection not defined or not refreshed; Same user posts and approves entries below threshold, breaking segregation; Support documentation not consistently attached for manual entries; Review of high-risk entries evidenced only by signature without documented inquiry; Recurring or templated entries not periodically validated for continued validity
Source: SOX 404 and ICFR
SOX FRAUD-2 Management Override ControlsControls mitigate management override risk including independent review of top-side journal entries and unusual transactions.
Where matrices usually fall short: Top-side and topside-only entries not separately identified and reviewed; Manual journal entries posted by management without independent review; Late entries near period close not subject to enhanced scrutiny; Compensating controls not documented when normal segregation fails; Reports used to identify override risk are IPE without ITGC testing
Source: SOX 404 and ICFR
ISO/IEC 27001 5.3 Segregation of dutiesSplit conflicting duties so no single person can run a sensitive process end to end unchecked.
Where matrices usually fall short: Combining conflicting roles in small teams; Lack of documented exceptions; Infrequent access rights reviews; Reliance on informal approvals
Source: ISO/IEC 27001:2022
NIST SP 800-53 AC-5 Separation of dutiesRequires the organization to identify and document the individual duties that must be kept apart to limit malevolent activity without collusion, and to define system access authorizations so that those duties cannot be exercised by one person.
Where matrices usually fall short: Conflicting duties named for finance processes only and never for system administration; Small teams create unavoidable conflicts that are tolerated rather than documented and compensated; Separation enforced at role definition but broken by direct entitlement grants
Source: NIST SP 800-53 Rev 5
COBIT DSS06.03 Manage roles, responsibilities, access privileges and levels of authorityBusiness roles, responsibilities, levels of authority and segregation of duties supporting the process objectives are managed, and access to all information assets related to business processes is authorised: roles and responsibilities follow approved job descriptions and process activities; levels of authority for approving transactions, transaction limits and other decisions follow approved job roles; sensitive activities are allocated so that duties are clearly segregated; access rights and privileges are the minimum needed for predefined job roles, removed or revised immediately on role change or termination; regular awareness and training cover roles, responsibilities, the importance of controls and the security, integrity, confidentiality and privacy of information; administrative privileges are secured, tracked and controlled to prevent misuse; and access control definitions, logs and exception reports are periodically reviewed so that privileges remain valid and aligned with current staff and roles.
Where matrices usually fall short: Transaction limits not enforced in the system; Access accumulated across role changes
Source: COBIT 2019