Delegation of Authority Matrix Validator
Regime

ISO/IEC 27001:2022: what it asks of an approval matrix

The Annex A controls that bear on an approval matrix: segregation of duties, roles and responsibilities, access rights, privileged access and change management.

Quoted for every matrix.

Approval families anchored here

35
FamilyClause
Purchase ordersISO/IEC 27001 5.3
Invoices with no purchase orderISO/IEC 27001 5.3
Capital expenditureISO/IEC 27001 5.3
Leases and rental commitmentsISO/IEC 27001 5.3
Spend over budget and budget transfersISO/IEC 27001 5.3
Payment run releaseISO/IEC 27001 5.3
Urgent and manual paymentsISO/IEC 27001 5.3
Bank account opening and changesISO/IEC 27001 5.3
Vendor master data changeISO/IEC 27001 5.3
Employee expense claimsISO/IEC 27001 5.3
Payroll releaseISO/IEC 27001 5.3
Customer and sales contractsISO/IEC 27001 5.3
Supplier contractsISO/IEC 27001 5.3
Contracts signed for the companyISO/IEC 27001 5.3
Confidentiality agreementsISO/IEC 27001 5.3
Guarantees, indemnities and letters of creditISO/IEC 27001 5.3
Journal entriesISO/IEC 27001 5.3
Accruals and prepaymentsISO/IEC 27001 5.3
Provisions and reservesISO/IEC 27001 5.3
Write-offsISO/IEC 27001 5.3
Reconciliation sign-offISO/IEC 27001 5.3
FX, hedging and treasury dealsISO/IEC 27001 5.3
Price and price list changesISO/IEC 27001 5.3
Discounts and rebatesISO/IEC 27001 5.3
Credit notesISO/IEC 27001 5.3
Customer refundsISO/IEC 27001 5.3
Customer credit limitsISO/IEC 27001 5.3
New hires and headcountISO/IEC 27001 5.2
Pay changesISO/IEC 27001 5.2
Terminations and severanceISO/IEC 27001 5.2
Bonuses and incentivesISO/IEC 27001 5.2
Privileged system access grantsISO/IEC 27001 8.2 · ISO/IEC 27001 5.15
User access review sign-offISO/IEC 27001 5.18 · ISO/IEC 27001 5.15
Changes to production systemsISO/IEC 27001 8.32
Changes to approval workflows and limits in the systemISO/IEC 27001 8.32 · ISO/IEC 27001 5.37

ISO/IEC 27001:2022: every clause cited, quoted

7 of the 93 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

ISO/IEC 27001 5.2 Information security roles and responsibilities

Name who owns what in security and make the allocation explicit and traceable.

What an auditor asks to see: Role definitions; Responsibility matrix; Assignment records; Authority delegation
Where matrices usually fall short: Roles not updated after staff changes; No documented acceptance of responsibilities; Unclear separation between ownership and operational duties; Delegated authority not reflected in policy documents
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.3 Segregation of duties

Split conflicting duties so no single person can run a sensitive process end to end unchecked.

What an auditor asks to see: Role separation matrix; Approval workflow records; Access rights review reports; Segregation conflict log
Where matrices usually fall short: Combining conflicting roles in small teams; Lack of documented exceptions; Infrequent access rights reviews; Reliance on informal approvals
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.15 Access control

Set rules for physical and logical access based on business and security requirements.

What an auditor asks to see: Physical access policy; Logical access policy; Access rights review; Privileged account management
Where matrices usually fall short: Infrequent review of access rights; Missing documentation for temporary access; Overly broad role definitions; Inadequate segregation of duties enforcement
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.18 Access rights

Provision, review, modify and remove access rights in line with the access control policy.

What an auditor asks to see: Access provision records; Access review reports; Access revocation logs; Role definition documents
Where matrices usually fall short: Reviews lack documented corrective actions; Access changes not tied to approved request workflow; Legacy accounts remain active after employee departure; Role definitions not updated to reflect current business processes
Source: ISO/IEC 27001:2022
ISO/IEC 27001 5.37 Documented operating procedures

Document operating procedures for information processing facilities and make them available to those who need them.

What an auditor asks to see: Operating procedure manuals; Procedure distribution records; Procedure revision history; Access control logs
Where matrices usually fall short: Outdated procedures still in use; No evidence of distribution to staff; Missing version control for revisions; Procedures not aligned with actual practice
Source: ISO/IEC 27001:2022
ISO/IEC 27001 8.2 Privileged access rights

Restrict and manage the allocation and use of privileged access.

What an auditor asks to see: Privileged account inventory; Privileged access approval; Privileged access review; Privileged access logging
Where matrices usually fall short: Outdated privileged account inventory; Missing or informal approval documentation; Infrequent or superficial access reviews; Privileged activity logs not retained or insufficiently protected
Source: ISO/IEC 27001:2022
ISO/IEC 27001 8.32 Change management

Put changes to facilities and systems through change management procedures.

What an auditor asks to see: Change requests; Change approvals; Implementation testing; Post implementation reviews
Where matrices usually fall short: Missing formal approval; No rollback plan documented; Testing performed after production deployment; Change records not linked to assets
Source: ISO/IEC 27001:2022