unified
UC-GOV-08 — Segregate conflicting duties and areas of responsibility
Identify duties and areas of responsibility that conflict — such as requesting versus approving access, development versus production deployment, or initiating versus approving transactions — and segregate them among different individuals or roles. Where segregation is impracticable, apply and document compensating controls such as enhanced monitoring, logging, or independent review.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- domain
- Governance, Policy & Oversight
- type
- preventive
- category
- administrative
Details
- unified_id
- UC-GOV-08
- title
- Segregate conflicting duties and areas of responsibility
- statement
- Identify duties and areas of responsibility that conflict — such as requesting versus approving access, development versus production deployment, or initiating versus approving transactions — and segregate them among different individuals or roles. Where segregation is impracticable, apply and document compensating controls such as enhanced monitoring, logging, or independent review.
- domain
- Governance, Policy & Oversight
- control_type
- preventive
- control_category
- administrative
- members
- framework
- iso-27001
- control_id
- A.5.3
- coverage
- full
- relationship
- equal
- guidance
Source
No record-specific source URL is provided.
Connections
- UC-GOV-08 — Segregate conflicting duties and areas of responsibility mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Segregating conflicting duties directly remedies the absent segregation of duties the risk names.
- UC-GOV-08 — Segregate conflicting duties and areas of responsibility maps_to A.5.3 — Segregation of duties
- framework
- iso-27001
- control_id
- A.5.3
- coverage
- full
- relationship
- equal
- delta
- Not provided
- source_version
- 2022
- provenance
- mapper
- coworkcanvas-compliance-graph
- reviewDate
- 2026-09-07
- direction
- canonical_to_source
- defaultConfidence
- medium
- defaultStatus
- active
- note
- Each member is a documented relationship claim from the canonical unified control to a source control or guidance proposition. relationship: equal|superset_of (full) / intersects_with|subset_of (partial) / informs (guidance). confidence 'medium' = single-mapper, documented, not yet externally corroborated. source_version is the member framework's edition from the standard version register.
- SOX ITGC Testing tests UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- UC-GOV-08 — Segregate conflicting duties and areas of responsibility mitigates Unauthorized activity — rogue trading, position mismarking, concealment
- strength
- primary
- rationale
- Initiate-versus-approve and front/back-office segregation is a core barrier to concealed rogue trading and position mismarking.
- ISO 27001 SoA Review & Controls Assessment oversees UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- Joiner-Mover-Leaver Access Lifecycle operates UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- ISO 27001 Stage 2 Annex A Controls Audit tests UC-GOV-08 — Segregate conflicting duties and areas of responsibility
- UC-GOV-08 — Segregate conflicting duties and areas of responsibility mitigates Ineffective ICFR / undisclosed material weakness
- strength
- related
- rationale
- SoD over transaction initiation and approval reduces undetected errors and misstatement feeding ICFR weakness.
- UC-GOV-08 — Segregate conflicting duties and areas of responsibility mitigates Internal fraud — asset misappropriation, embezzlement, forgery
- strength
- primary
- rationale
- Separating initiate-versus-approve prevents one person from both perpetrating and concealing misappropriation.