Segregation of duties is a control principle that divides incompatible responsibilities among different authorized people or roles. In procurement, an organization may separate requesting, supplier creation, evaluation, approval, receipt, invoice resolution, and payment activities. The exact conflicts and compensating controls depend on risk and operating context; system roles must align with the approved control design.
In plain English
It reduces control risk by keeping one person from controlling every critical step.
Illustrative example
At Northstar Industrial Systems, the person who creates a supplier record cannot also approve that supplier and release a related payment without separate authorization.
- Related terms
- Role-based access control; Approval workflow; Access control; Audit trail
- Lifecycle stages
- All stages
- Stakeholders
- Audit; Finance; Procurement; IT and Security