Nobody designs a segregation of duties conflict. It accumulates: a role added to cover month-end, an ERP upgrade that widened a permission, a new starter whose access was copied from a colleague who has since changed jobs.
A segregation of duties (SoD) review finds those conflicts before an auditor or a fraud does. This free SoD review checklist is for controllers, internal audit, SOX teams and the IT staff who administer ERP access. It updates the conflict matrix, extracts access from each system, confirms conflicts with their owners, then removes each one or covers it with a documented alternative control. A conditional phase handles finance teams too small to separate every duty. The output is a signed conflict register in which every conflict has an outcome, an owner and evidence.
Four Duties, One Rule, and Two Kinds of Fallback Control
The PCAOB’s staff guidance for auditors of smaller public companies names the four duties that should sit with different people: authorising transactions, recording them, reconciling information and keeping custody of assets. One person holding two of them can make an error or a theft and then hide it: a clerk who can create a supplier and release payments to it, or a developer who can change code and deploy it.
COSO’s 2013 Internal Control – Integrated Framework places segregation of duties under Principle 10, the principle on selecting and developing control activities. Its point of focus reads, in short: segregate incompatible duties, and where that is not practical, select and develop alternative control activities. The review has to prove both halves, and the wording matters because auditors use two different terms.
Alternative control
Designed in, because separation is not practical
Source: COSO Principle 10; the note to AS 2201.42 on smaller companies.
When: management knows a person holds conflicting duties and designs a control that meets the same objective.
Auditor’s view: evaluates whether the alternative control is effective.
Compensating control
Relied on after a deficiency is found
Source: AS 2201.68, on evaluating deficiencies.
When: an unplanned conflict is found and another control is put forward to limit its severity.
Test: it must operate at a level of precision that would prevent or detect a misstatement that could be material.
Auditor’s view: weighs it in judging whether there is a material weakness.
Where this template stops
An SoD review, not the whole SOX programme
Scoping, risk assessment and the 302 and 404 reporting cycle belong to the SOX 404 Compliance Checklist. Testing controls, including the alternative controls recorded here, belongs to the SOX Internal Control Testing Checklist. A general user access review asks whether each account is still needed; this review asks whether the combination of access is safe.
What the Segregation of Duties Review Checklist Covers
Six phases take the review from rule set to sign-off. A seventh appears only when the team is too small to separate every duty.
Phase 1
Phase 1: Scope & Approve the Rule Set
The scope answers on the first task decide whether Phase 7 and the SOX hand-off task in Phase 6 appear.
Define the review scope and period — systems, legal entities and processes in scope, and whether this is a scheduled cycle or a triggered re-run
Map the four duties to each in-scope process — which activities authorise, record, hold custody and reconcile in purchasing, payroll, revenue, treasury and IT change
Update the conflict matrix — add rules for new processes, roles and functions, and retire rules for anything decommissioned
Rate each rule by risk — what could go wrong, and whether it could lead to fraud or a material misstatement
Approve the rule set before any access is extracted — the process owners and the controller sign it, so results are not re-argued later
Phase 2
Phase 2: Extract User & Role Access
Extract user-to-role assignments from each in-scope system — dated, complete and taken from the system itself, not a spreadsheet copy
Extract role-to-permission detail — conflicts live in permissions and transaction codes, not in role names
Include non-human and privileged accounts — service accounts, integrations, bots, AI agents that can post, shared IDs and emergency access
Reconcile the user list to the HR roster — leavers, movers and contractors, and people who hold access in more than one system
Record how the extract was proven complete — the report used, its parameters, the row counts and who ran it
Phase 3
Phase 3: Identify Conflicts
The last task appears only when the usage check finds conflicting access that was exercised.
Run the rule set against role design — a conflict built into a role affects everyone who holds it
Run the rule set against user assignments — conflicts created by combining roles that are safe on their own
Check for conflicts that span systems — for example, supplier master data in the ERP and payment release in the banking portal
Log every conflict in the conflict register — user, rule, systems, risk rating and a named owner
Check usage logs for conflicting access that was exercised — a conflict used in the period is a stronger finding than one that only exists
Review the transactions performed through exercised conflicts — self-approved entries, new suppliers paid quickly, unusual amounts or timing
Phase 4
Phase 4: Validate With Owners
Send each conflict to the user’s manager and the process owner — confirm whether the access is needed for the job as it is done today
Separate false positives from real conflicts — record the reason, such as a permission that is display-only in practice
Decide the outcome for each conflict — remove the access, redesign the role, or accept it only where removal would stop the work
Escalate conflicts with no owner response by the due date — to the controller or CFO, with the risk rating attached
Phase 5
Phase 5: Remove or Mitigate
Remove or change access through the normal access-change process — the ticket reference recorded against each conflict
Redesign roles that carry built-in conflicts — split the role, re-run the rules against the new design, then reassign
Document an alternative control for every accepted conflict — who performs it, how often, from which report, and what it would catch
Confirm the alternative control actually operated — evidence of each occurrence in the period, reviewed by someone other than the conflicted user
Set an expiry date on every accepted conflict — temporary cover access ends on a date, not when someone remembers to remove it
Phase 6
Phase 6: Re-run, Sign Off & Schedule
The hand-off task appears only when the review supports a SOX 404 programme. Sign-off is assigned to someone whose own access was not in the review.
Re-run the analysis after remediation — confirm removed conflicts are gone and that no new ones appeared in the meantime
Summarise the results — conflicts found, removed, accepted with alternative controls, and still open
Hand unmitigated conflicts to the SOX deficiency evaluation — with the conflict, the exposure period and any transactions reviewed
Sign off the review — the controller or CFO approves the conflict register and the accepted conflicts
Set the next review date and the re-run triggers — an ERP change, a role redesign, a reorganisation, an acquisition or a change in finance headcount
Phase 7 — Small Teams Only
Phase 7: Small-Team Alternative Controls
Shown only when the first task records that incompatible duties cannot be fully separated with current staff.
Draw a duty map by person — every duty each finance team member holds, on one page
Appoint an independent reviewer — a director, the owner or an outside accountant, with no access to cash, payments or the ledger
Give the reviewer direct access to bank activity — statements or read-only online banking, and review of each bank reconciliation
Route high-risk transactions to the reviewer for approval — new suppliers, bank detail changes, payment runs, payroll and manual journals
Review system change and audit logs monthly — entries made by the person who holds conflicting duties, with questions and answers recorded
Consider handing a whole function to an external party — for example outsourced payroll, which separates the duty without a new hire
Where Segregation of Duties Is Required, and What Evidences It
Sarbanes-Oxley itself never uses the phrase. The expectation comes from the control framework management assesses against, such as COSO, and from auditing standards. The table maps each source to the part of the review that produces evidence for it. Your obligations depend on your reporting regime and your auditor, so treat the table as a starting point, not legal advice.
Source
What it says about segregation of duties
Evidenced in
COSO 2013, Principle 10
Point of focus “Addresses Segregation of Duties”: segregate incompatible duties, or develop alternative control activities where that is not practical
Phases 1, 3 and 5
COSO 2013, Principles 3 and 11
Authorities and responsibilities are defined and limited; technology access rights are restricted to authorised users in line with their job responsibilities
Phases 1, 2 and 4
PCAOB AS 2201.42 (note)
A smaller company with fewer accounting staff may use alternative controls; the auditor evaluates whether they are effective
Phases 5 and 7
PCAOB AS 2201.68
A compensating control counts only if it operates at a precision that would prevent or detect a potentially material misstatement
Phases 5 and 6
SOC 2: CC5.1, CC6.3, CC8.1
CC5.1 carries COSO Principle 10 and its SoD point of focus; CC6.3 grants access considering least privilege and segregation of duties; a CC8.1 point of focus deploys changes with segregation of responsibilities
Phases 2–5
GAO Green Book (2025 revision), 10.21–10.23 and 11.16
Separate authority, custody and accounting; design alternative controls where limited personnel prevent it; separate critical IT responsibilities
Phases 1, 5 and 7
ISO/IEC 27001:2022, Annex A 5.3
Conflicting duties and conflicting areas of responsibility are segregated
Phases 1 and 3
The Green Book’s 2025 revision applies to US federal entities from fiscal year 2026. In February 2026 COSO published guidance on internal control over generative AI that applies the 2013 framework rather than replacing it. Its taxonomy includes a posting capability, a good reason to treat any AI agent that can post or approve as a user in Phase 2.
Why Run Your Segregation of Duties Review in CheckFlow?
1
The conflict register lives in the checklist
Keep the conflict matrix as a data set and the register as a table inside the Phase 3 task. Access extracts and change tickets are attached to the conflict they resolve, not stored in a folder nobody links back.
2
Owners decide, and the decision is recorded
Validation tasks go to the managers who own the access. Accepted conflicts go through an approval step with an expiry date, and the activity trail records who approved what and when. Enforced step order means sign-off cannot happen before the re-run.
3
The next cycle starts itself
A recurring schedule opens the review on your chosen cycle, and the Phase 5 alternative controls run on their own monthly checklists. Template versioning ties each review to the rule set it used.
CheckFlow is not an identity governance platform, a GRC tool or an SoD analysis engine. It does not calculate conflicts inside your ERP; you attach the extract or push it in through the REST API, webhooks or Zapier. CheckFlow runs the human part: validation, decisions, approvals and evidence. CheckFlow for SOC 2 teams shows how the same pattern covers the access and change controls a service auditor samples.
It is a periodic check that no one person holds a combination of access that would let them commit and conceal an error or fraud. You compare each user’s actual access against conflict rules, confirm the results with the access owners, then remove each conflict or cover it with a documented control, ending with a signed register.
What are the four incompatible duties?
+
Authorisation, recording, custody of assets, and reconciliation or verification. The PCAOB’s staff guidance for smaller public companies describes assigning these to different people, and ISACA and state auditors use the same model. So the person who approves a purchase should not also create the supplier, receive the goods or reconcile the supplier account.
How often should segregation of duties be reviewed?
+
None of the frameworks above fixes a frequency, so set one from risk and record why. The Washington State Auditor’s guide, updated in March 2026, suggests reviewing system access at least annually, and more often after staffing changes or in a new system’s first year. Where the review supports SOX or SOC 2, consider a shorter cycle for the ERP and payment systems. Re-run it after any of the triggers in Phase 6.
What is the difference between an alternative control and a compensating control?
+
An alternative control is designed in advance because separating the duties is not practical: COSO Principle 10 and the note to AS 2201.42 use that term. A compensating control is one put forward after a deficiency has been found, to argue the deficiency is less severe. The PCAOB staff guidance draws exactly this distinction. Under AS 2201.68 a compensating control only helps if it would catch a misstatement that could be material, so a high-level monthly review of totals is unlikely to qualify.
How can a small business handle segregation of duties with limited staff?
+
Bring in oversight from someone who does not handle the money. The Washington State Auditor’s guide suggests a governing-body member, an outside accountant or a swap of review duties with a neighbouring organisation. The PCAOB staff guidance adds outsourcing a whole function and management review of transactions, reconciliations and asset counts. Phase 7 of this template sets these up.
Is a segregation of duties conflict automatically a SOX deficiency?
+
Not automatically: a conflict with an effective alternative control may not be a deficiency at all. An unmitigated conflict is evaluated like any other control deficiency: its severity depends on whether there is a reasonable possibility that it could lead to a misstatement, and how large that misstatement could be. The PCAOB staff guidance warns that a pervasive lack of segregation without alternative controls can make the design of other controls ineffective.
Is CheckFlow free for this template?
+
14-day free trial, no card required. The Business plan is $10 per user per month after the trial. Full details at checkflow.io/pricing.
Every Conflict Removed or Covered, and Signed For
Free trial — no credit card required.
Do you like cookies? 🍪 We use cookies to ensure you get the best experience on our website. Learn more