What is SoD Compliance?
Definition
SoD Compliance means ensuring that segregation of duties rules are followed across finance, accounting, compliance, and operational activities. It prevents one person from having end-to-end control over sensitive activities such as creating a vendor, approving an invoice, releasing a payment, posting a journal entry, and reviewing the related reconciliation.
In finance operations, segregation of duties supports reliable financial reporting by dividing responsibility between makers, reviewers, approvers, and administrators. The goal is to create clear accountability, independent review, and controlled access for activities that affect cash, liabilities, expenses, revenue, tax, and management reporting.
How SoD Compliance Works
SoD compliance usually begins with a role and access matrix. The matrix identifies which duties should not be performed by the same person. For example, a user who can create a supplier should not also approve supplier bank changes and release payments. A person who prepares a journal entry should not be the only person approving and posting that same entry.
Finance teams apply SoD rules through user access reviews, approval workflows, maker-checker controls, ERP role design, and periodic control testing. These activities support Compliance Oversight (Global Ops) because they give finance leaders visibility into who has access, who performs sensitive tasks, and whether conflicts are reviewed before they affect reporting or cash movement.
Core Components
A strong SoD compliance model connects roles, access rights, approval rules, and monitoring. It should not only define restricted combinations, but also explain who owns review, how exceptions are approved, and how evidence is retained for audit.
Role design: Defines what each finance, accounting, treasury, tax, or procurement role is allowed to do.
Conflict rules: Identifies combinations of access that require review, such as vendor creation and payment release.
Approval authority: Assigns review responsibility based on transaction value, entity, department, and risk level.
Access review: Confirms that user permissions remain aligned with current job responsibilities.
Evidence retention: Maintains documentation of reviews, approvals, exceptions, and remediation actions.
Where It Matters in Finance
SoD compliance is especially important in accounts payable, treasury, general ledger, tax, procurement, payroll, and vendor master data. In accounts payable, it separates invoice entry, payment approvals, vendor updates, and payment release. In general ledger, it separates journal preparation, review, posting, and reconciliation approval. In treasury, it supports Treasury Internal Controls by separating bank administration, payment initiation, and payment authorization.
SoD also supports wider compliance areas. For example, Foreign Corrupt Practices Act (FCPA) Compliance and Anti-Bribery and Corruption (ABC) Compliance depend on controlled approvals, vendor due diligence, and transparent payment activity. In regulated finance activities, Know Your Customer (KYC) Compliance and Anti-Money Laundering (AML) Compliance also rely on clear separation between data entry, screening, approval, and monitoring responsibilities.
Key Metrics
SoD compliance can be monitored using operational control metrics. These metrics help finance and compliance leaders understand whether access conflicts are visible, reviewed, and resolved within policy timelines.
SoD conflict rate = Users with SoD conflicts ÷ Total users reviewed × 100
SoD remediation rate = Resolved SoD conflicts ÷ Identified SoD conflicts × 100
For example, assume a finance team reviews access for 600 users. If 45 users have conflicting permissions, the SoD conflict rate is 45 ÷ 600 × 100 = 7.5%. If 36 conflicts are resolved by removing access, changing roles, or documenting approved compensating controls, the SoD remediation rate is 36 ÷ 45 × 100 = 80%. These metrics help the Chief Compliance Officer (CCO) and finance leadership prioritize access cleanup, role redesign, and control monitoring.
Governance and Monitoring
SoD compliance works best when it is part of a broader Compliance-by-Design Operating Model. This means duties are separated during role setup, ERP configuration, approval design, and finance transformation planning instead of being reviewed only after conflicts appear. It also supports Real-Time Compliance Surveillance by helping teams monitor sensitive access and transaction patterns continuously.
A Compliance Risk Heat Map can help leadership classify SoD conflicts by severity. For example, conflicts involving payment release, bank master changes, journal posting, or revenue adjustments may receive higher priority than lower-risk reporting access. This allows finance teams to focus review effort on areas with the greatest financial reporting and cash flow impact.
Best Practices
Effective SoD compliance requires clear ownership between finance, IT, compliance, and business leaders. Finance should define sensitive activities, IT should manage role configuration, and compliance should monitor adherence to policy. Together, they create a controlled environment where access supports job responsibilities without combining incompatible duties.
Define incompatible duties for payments, journals, vendor master data, payroll, tax, and reconciliations.
Review ERP access whenever employees change roles, teams, entities, or approval authority.
Use compensating controls when temporary access is approved for a documented purpose.
Track SoD conflicts by owner, severity, age, and remediation status.
Align SoD reviews with internal audit, close certification, and compliance reporting calendars.
Summary
SoD Compliance ensures that sensitive finance responsibilities are separated across different people, roles, or approval levels. It strengthens accountability, improves financial reporting quality, and supports controlled cash movement. When connected with access reviews, maker-checker approvals, compliance monitoring, and clear ownership, SoD compliance helps finance teams maintain disciplined, auditable, and efficient control operations.







