When separation of duties (SoD) cannot be fully implemented—typically due to limited personnel—acompensating controlmust provide comparable assurance that no individual can exploit a conflict of interest or perform unauthorized actions without detection.
According to the CRISC study guide and ISACA’s Control Objectives for Information and Related Technologies (COBIT):
Compensating controlssubstitute for missing primary controlswhen business or technical constraints prevent their full implementation.
The most effective compensating control for SoD issues isindependent review or monitoringof activities performed by those with multiple roles.
Obtaining an independent analysis of transaction logsensures that another trusted party validates the actions taken by employees, detecting inappropriate or fraudulent activities.
Option explanations:
A. Control self-assessmentsare self-reviews, not independent, and therefore insufficient for SoD conflicts.
B. Reports from staff with multiple dutiesstill depend on self-reporting, which lacks independence.
D. Assigning activities to fewer employeesincreases risk rather than mitigating it.
This aligns with CRISC’s emphasis that“an independent review of audit logs is the best compensating control when segregation of duties conflict exists in a small IT department.”(CRISC Notes, Slide 349).
Submit