
How to Review Segregation of Duties
Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Review segregation of duties end to end — risk-based conflict definitions, privileged and emergency access, users matched to current roles, tested compensating controls and remediation prioritized by business impact.
© Salih Ahmed Islam

Identify combinations that let one person initiate and complete a risky transaction, test them against actual user access, and judge whether compensating controls really work.
PDF • 6 Pages • Free

Verify access and core IT general controls: approved least-privilege access, prompt leaver removal, controlled privileged and service accounts, evidence-based access reviews, approved changes and tested backups.
PDF • 6 Pages • Free

Map key activities to Responsible, Accountable, Consulted and Informed roles to expose ownership gaps, conflicting accountability and concentration of duties.
PDF • 6 Pages • Free

Build a practical risk and control matrix that links each business objective and risk to its control, owner, frequency and evidence, then records the planned test and conclusion.
PDF • 6 Pages • Free