GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

GOV-009 Segregation of Duties

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Conflicting duties and responsibilities that could enable fraud or error are identified and separated across different individuals or automated controls. Roles are designed so that no single individual can both initiate and approve a sensitive operation; conflicting role combinations are recorded in a conflict matrix and their assignment to one account is prevented or detected. Where full separation is not feasible because of organisational size, compensating controls are documented.

Rationale

Segregation of duties is a fundamental internal control preventing any single individual from having end-to-end control over a critical business process, reducing the risk of both fraud and undetected errors.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (7)

IAM-04Separation of Dutiesfull
IAM-17Output Modification and Special Authorizationinformative
IAM-04Separation of Dutiesfull
5.3Segregation of dutiesfull
NIS2-CIR-1.2Roles, Responsibilities and Authoritiesinformative
AC-5Separation of Dutiesfull
CC6.3Role-Based Access Controls and Least Privilegepartial

Evidence (3)

policydocumentmanual

Segregation of duties matrix or documented SoD policy identifying conflicting roles and the required separations or compensating controls.

Example: Segregation of Duties Policy and conflict matrix (Confluence / GRC platform), identifying roles that must not be combined (e.g. code deploy and production access approval), with compensating controls documented for any exceptions due to organisational size.

Test: Request the SoD policy and conflict matrix. Verify: (1) conflicting role combinations are explicitly listed, (2) each conflict has either a required separation or a documented compensating control, (3) the policy has been approved by management within the last 12 months.

configurationtechnicalautomated

System access configuration records showing that conflicting roles are not simultaneously assigned to the same user accounts.

Example: Access control export from IAM system (Okta, Azure AD, AWS IAM) or ticketing system showing user-to-role assignments, confirming no user account holds both sides of a defined SoD conflict.

Test: Export user-role assignments from the IAM system. Cross-reference against the SoD conflict matrix. Verify: (1) no active user account is assigned both roles in any identified conflict pair, (2) for any exceptions, a documented compensating control record exists with a named approver.

reportdocumentmanual

SoD violation report from the most recent access review or IGA tool run, showing any detected conflicts and their remediation status.

Example: SailPoint, Saviynt, or custom IGA report listing SoD conflicts identified in the last review cycle, with a disposition column showing each conflict was remediated, accepted with a documented business justification, or has an open remediation ticket.

Test: Request the most recent SoD conflict report. Verify: (1) the report was generated within the last review period, (2) all conflicts are in one of three states: remediated, accepted with documented compensating controls, or have an open time-bound remediation ticket, (3) the total number of open unmitigated conflicts is zero.

Questions (3)

boolean

Has your organisation recorded the conflicting role combinations that must not be held by one account?

A segregation of duties (SoD) matrix or conflict register should list role pairs that must not be combined, with compensating controls for any necessary exceptions.

select

How does your organisation verify that SoD conflicts are not present in the live IAM environment?

Automated IAM controls prevent conflicting role assignmentsRegular automated reports cross-reference role assignments against the SoD matrixManual periodic review of user-role assignments against the SoD matrixAd hoc review only when access changes are requestedSoD enforcement is not currently verified

An IAM export cross-referenced against the SoD conflict matrix, showing no user holds both sides of a conflict, is the expected evidence.

boolean

Where full separation of a conflicting pair is not feasible, is a compensating control documented for it?

Answer yes only where each conflict left in place carries a named compensating control and the person who accepted it. A small organisation will have such pairs; what fails the control is leaving them unrecorded.