Separation of duties is a security and compliance principle that divides critical business processes across multiple individuals to prevent fraud, embezzlement, and unauthorized access. By ensuring no single person controls an entire workflow from start to finish, organizations create built-in checks and balances that deter and detect misconduct.
Separation of Duties
I've heard a lot of stories about people within a company embezzling money. These were people that were trusted — they trusted a certain person and they ended up stealing from the company. This wouldn't happen if you had a policy that was around separation of duties.
Let's do a little scenario here so we can understand what this looks like. First of all, let's say we work for a company that has a process, and the process is that we choose a vendor or a product. From there we create what's called a purchase order. A purchase order just gives the detail of who we're buying this from and what we're buying. Then it goes through some sort of approval process, that somebody of proper clearance can do this approval and approve of this purchase. Then we cut this check, and then that check goes to this vendor, and then we get the product sent to us.
So the scenario is that I work for a company, and I need some work done on my house. So I choose a contractor that can do that work. I create the purchase order, and let's say I also can do the approvals for that, so I sign it off and approve it, and I also write the check for this construction company that's going to come and work on my house. Now what I've just done is, the company that I work for, I've spent that money from that company on something that's personal to me, fixing up my home. This is a big problem — I'm stealing from the company in this scenario, and so we want to avoid this from happening.
This is where separation of duties comes into place: that maybe I can't do all of the steps in here. Maybe I can choose the vendor and product, and then from there I will create the purchase order and prepare the purchase order, but then maybe it's got to go for approval and my boss has to approve this. They might take a look at it and say, why are you paying for this construction company, we don't have any project like this within our company, why is it that you're doing this? And so they would question why this purchase order is coming through there, and now that ability has ended just there. And then if I have somebody else that actually cuts the check, that would be another step along the process, that accounting has to cut the check for this. Now we've got a separation of duties, and there's this checks and balances that happens through here and protects against this type of embezzlement from happening.
A lot of times this can be a time intensive process. Maybe I need to purchase something right away and it doesn't make sense to get all of the approvals for whatever I need to purchase, and maybe I'm in charge of my own budget. For instance, when I was a director I was able to do some approvals, but there were limits to how much approvals that I could do — that is, I could approve anything that was below 10,000. It was a threshold for the company that they deemed that it was acceptable for me to sign things up to $110,000, and then above that they wanted to go through this checks and balances of an official approval from somebody else, somebody higher up that could give this approval. But even then we still had somebody cutting their own checks, and there's also audits that would happen to make sure that this was the right stuff that we went through. So even though it skipped the process to make it more streamlined in cases where it was under $10,000, there is still checks and balances to make sure that there couldn't be any stealing of money, couldn't be any embezzlement happening.
This happens in other areas of the company as well. For instance, let's say somebody needs access to data. Separation of duties, what it would look like, is maybe that person submits a request, so now there's an official document, a request that's being made. Maybe the next step now is that the resource owner has to give approvals for that, so the resource owner is going to reply to that email and say, yes, I accept this — or maybe we need to reach out and get approval from that resource owner. And then it would then implement the changes and give access to that user.
Now there's this checks and balances, so if there are ever steps that were skipped — maybe somebody gained access to a resource, we've implemented something but there's no documented proof that this was needed or approved of — we can go back and we have a paper trail that we can see. Okay, what is happening here, why have we not followed our policies and procedures? And we can take a look to see if there's some sort of action that's happening.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →