Skip to content
arrow_back
search
Annex A 5.3 verified ISO/IEC 27001:2022

Segregation of Duties

Ensure no one person can perform conflicting duties alone to prevent misuse.

record_voice_over

Plain language

Segregation of duties means dividing tasks and responsibilities among different people to prevent any one person from having too much control or power. This matters because if one person can approve and execute their own actions, there's a higher risk of mistakes or even fraud, like someone paying fake invoices to themselves or approving their own access changes.

Framework

ISO/IEC 27001:2022

Control effect

Preventative

ISO 27001 domain

Organisational controls

Classifications

N/A

Official last update

24 Oct 2022

Control Stack last updated

19 Mar 2026

Maturity levels

N/A

Official control statement

Conflicting duties and conflicting areas of responsibility shall be segregated.
verified ISO/IEC 27001:2022 Annex A 5.3
priority_high

Why it matters

Without segregation of duties, fraud, unauthorised transactions or data tampering may occur and go undetected due to reduced independent oversight.

settings

Operational notes

Review role/duty assignments for conflicts, enforce dual approval for high-risk actions, and monitor audit logs for signs of unauthorised activity.

Mapping detail

Mapping

Direction

Controls