Logical Access and Segregation of Duties Controls
In CIA Part 2, engagement planning requires the internal auditor to understand the control environment surrounding information systems, and two critical areas are logical access controls and segregation of duties (SoD). Logical access controls are technology-based safeguards that restrict who can v… In CIA Part 2, engagement planning requires the internal auditor to understand the control environment surrounding information systems, and two critical areas are logical access controls and segregation of duties (SoD). Logical access controls are technology-based safeguards that restrict who can view, change, or execute data, applications, and system resources. They include user identification and authentication (passwords, multifactor authentication, biometrics), authorization based on the principle of least privilege, role-based access control, encryption, firewalls, and activity logging. Key processes the auditor should consider include user provisioning and deprovisioning, periodic access recertification, management of privileged or administrator accounts, password policies, and monitoring of access violations. Segregation of duties is the principle that no single individual should control all phases of a transaction. The four functions typically separated are authorization, custody of assets, recordkeeping, and reconciliation or review. In IT environments, SoD also means separating system development from production operations, and separating security administration from end-user functions. Logical access controls are the main mechanism for enforcing SoD in automated systems, because access rights determine which tasks each user can perform. During engagement planning, the auditor performs a preliminary risk assessment to identify where weak access or conflicting duties could enable fraud, error, or unauthorized changes. Planning activities include reviewing organizational charts, access policies, role matrices, and prior audit findings, interviewing process owners and IT staff, and identifying high-risk systems such as financial, payroll, and procurement applications. The auditor then defines engagement objectives and scope, and designs work program steps such as testing user access lists against job responsibilities, reviewing SoD conflict reports, sampling terminated employees to confirm timely removal, and evaluating compensating controls like supervisory review where full segregation is impractical in small units. Data analytics can help detect conflicting access combinations across large user populations. Strong logical access and SoD controls reduce opportunities for fraud and provide assurance over data integrity and confidentiality.
Logical Access and Segregation of Duties Controls (CIA Part 2: Engagement Planning)
Introduction
In CIA Part 2 (Practice of Internal Auditing), engagement planning asks the internal auditor to understand the area under review, assess its risks, and decide which controls to test. In almost every engagement that touches an information system, two control families come up again and again: logical access controls and segregation of duties (SoD) controls. This guide explains why they matter, what they are, how they work in practice, and how to answer exam questions about them.
Why Logical Access and Segregation of Duties Controls Are Important
1. They protect the integrity of data and transactions. If the wrong people can read, change, or delete data, financial statements, operational reports, and management decisions become unreliable.
2. They prevent and detect fraud. The fraud triangle says fraud needs pressure, rationalization, and opportunity. Weak access and poor segregation create the opportunity. When one person can both commit and conceal an irregularity, the risk of fraud rises sharply.
3. They support compliance. Regulations such as SOX (ICFR), GDPR, HIPAA, and PCI DSS expect access restricted on a need-to-know basis and incompatible duties separated.
4. They are pervasive controls. Logical access is an IT general control (ITGC). If ITGCs fail, the auditor cannot rely on the automated application controls that depend on them. This affects the nature, timing, and extent of testing in the whole engagement.
5. They shape the engagement plan. During planning, the auditor's risk assessment considers whether access and SoD are well designed. That assessment drives the objectives, scope, work program, and sample sizes.
What Logical Access Controls Are
Logical access controls are software-based controls that restrict who can access systems, applications, data, and functions, and what they can do once inside. They differ from physical access controls such as locks, badges, and guards, which protect facilities and hardware.
Key concepts:
- Identification: claiming an identity, for example a user ID.
- Authentication: proving the identity. This uses something you know (a password or PIN), something you have (a token, smart card, or phone), or something you are (a biometric). Multi-factor authentication (MFA) combines two or more different categories.
- Authorization: determining what an authenticated user may do, such as read, write, update, delete, or approve.
- Accountability: logging and audit trails that tie actions to unique users.
The AAA model (Authentication, Authorization, Accounting) is a common way to remember these elements.
Core principles
- Least privilege: users receive only the minimum access needed for their job.
- Need-to-know: access to information is limited to those who require it.
- Default deny: anything not explicitly permitted is denied.
Common access control models
- Role-Based Access Control (RBAC): rights are assigned to roles, such as AP Clerk, and users are assigned to roles. This makes administration and SoD enforcement easier.
- Discretionary Access Control (DAC): the data owner decides who gets access.
- Mandatory Access Control (MAC): access is based on security labels or classifications. It is common in military and government settings.
- Attribute-Based Access Control (ABAC): access is based on attributes such as department, location, or time.
Typical logical access controls an auditor examines
- User provisioning (formal request, owner approval, and creation of the account).
- Timely de-provisioning when employees leave or transfer, so that no orphan accounts remain.
- Periodic user access reviews (recertification) by business owners.
- Password policies (length, complexity, expiration, lockout after failed attempts).
- Control over privileged and administrator accounts, including restriction, monitoring, and logging.
- Control over generic or shared accounts and default vendor passwords.
- Session controls (automatic logoff, timeouts).
- Network controls (firewalls, VPNs, encryption of data in transit and at rest).
- Logging and monitoring of access violations, with security logs reviewed by someone independent.
- Access to production versus development environments, and controls over program changes.
What Segregation of Duties Is
Segregation (or separation) of duties means dividing the key steps of a transaction among different people so that no one individual can both perpetrate and conceal errors or fraud.
The classic framework separates four incompatible functions:
1. Authorization (approving transactions).
2. Custody of assets (handling cash or inventory).
3. Recording (bookkeeping and data entry).
4. Reconciliation or verification (independent checking). Some texts merge this with recording or treat it as a separate review function.
Examples of incompatible duties
- Creating a vendor in the vendor master file and approving payments to vendors.
- Receiving cash and recording cash receipts or reconciling the bank account.
- Approving payroll changes and distributing paychecks.
- Ordering goods and receiving goods.
- Writing program code and moving it into production.
- Being a security administrator and also an application end user who processes transactions.
Segregation within IT
Traditional IT segregation separates:
- Systems development and programming.
- Computer operations.
- Data control and the librarian function.
- Security administration.
- End users.
The key rule: programmers should not have access to production data or programs, and operators should not be able to modify programs.
How Logical Access and SoD Work Together
In modern ERP systems such as SAP or Oracle, segregation of duties is largely enforced through logical access. If a user's role contains both the 'create vendor' and 'approve payment' transactions, SoD is broken even if the job descriptions say otherwise. That is why auditors analyze role design and run SoD conflict reports using an SoD ruleset or matrix.
Compensating controls
In small organizations or small departments, full segregation may be impractical. Compensating controls reduce the risk. Examples include:
- Independent management review of transactions or reports.
- Detailed review of exception and audit logs.
- Mandatory vacations and job rotation.
- Surprise counts.
- Owner or manager involvement in approvals.
- Dual control, where two people are required.
Compensating controls are usually detective. They reduce risk but are generally less effective than proper preventive segregation.
How These Controls Fit into Engagement Planning
1. Understand the process and system. Use walkthroughs, flowcharts, and narratives, and identify the key applications and the roles within them.
2. Identify risks. Typical risks are unauthorized access, inappropriate privileges, terminated users who still have access, SoD conflicts, and unmonitored superuser activity.
3. Identify the controls designed to mitigate those risks, such as RBAC, access reviews, MFA, and SoD rulesets.
4. Evaluate design adequacy. Ask whether the controls, if operating, would mitigate the risk.
5. Plan tests of operating effectiveness. Typical tests:
- Compare a list of terminated employees from HR to active system accounts.
- Select new users and trace them to approved access requests.
- Inspect evidence of periodic access reviews and any follow-up removals.
- Use CAATs or data analytics to run SoD conflict analysis across all users.
- Review privileged account lists and inspect logs for monitoring.
- Inspect system password configuration settings directly rather than relying only on the written policy.
- Observe and reperform where possible.
6. Determine scope and resources. Involve IT audit specialists if needed, as the Standards expect auditors to have or obtain the necessary competencies.
Control Classification Reminders
- Preventive: passwords, MFA, RBAC, SoD built into roles, and edit checks.
- Detective: access log review, user access recertification, SoD conflict reports, and reconciliations.
- Corrective: disabling compromised accounts and restoring from backups.
- Directive: access policies and acceptable use policies.
Logical access is an ITGC, while input, processing, and output controls are application controls.
Exam Tips: Answering Questions on Logical Access and Segregation of Duties Controls
1. Look for the 'perpetrate and conceal' combination. When a question describes one person performing two functions, ask whether that person could both commit an error or fraud and hide it. If yes, that is the SoD weakness the question wants.
2. Memorize the four incompatible functions. These are authorization, custody, recording, and reconciliation. The most commonly tested pairs are custody with recording, and authorization with custody.
3. In IT questions, programmers versus production is the classic answer. If a programmer can change live programs or data, that is the most serious weakness. Change management should require testing, approval, and migration by someone other than the developer.
4. Know that the best authentication combines different factors. A password plus a PIN is not true multi-factor authentication, because both are something you know. A password plus a token or biometric is.
5. Least privilege is usually the best principle answer. When asked how access should be granted, choose job-based, minimum necessary access over convenience-based answers.
6. Terminated-user tests are favorites. The best test for timely removal is to compare the HR termination list to active user accounts. The direction of testing matters: start from the HR terminations and trace to the system.
7. Prefer system evidence over inquiry. Inspecting actual configuration settings or running reports is stronger evidence than asking IT staff or reading a policy document. The hierarchy runs: reperformance and direct inspection are strongest, then documentation, then inquiry.
8. Recognize compensating controls in small-entity scenarios. If the question says segregation is impossible due to limited staff, the best answer is usually increased owner or management review, or another independent detective control. Do not choose 'hire more staff' unless no other option fits.
9. The security administrator should be independent. They should not process transactions or develop programs. Review of security logs should be performed by someone other than the person whose activities are logged.
10. Distinguish identification, authentication, and authorization. Exam distractors often swap these. Identification is who you claim to be, authentication proves it, and authorization defines what you can do.
11. Watch for 'MOST effective' or 'BEST' wording. Preventive controls are generally preferred over detective ones. Automated controls are generally preferred over manual ones. Controls addressing root causes are better than those treating symptoms.
12. Link to planning. If a question asks what the auditor should do first during planning, think: understand the system and roles, assess risk, then design tests. Do not jump to testing before understanding.
13. Remember ITGC dependency. If logical access ITGCs are ineffective, the auditor cannot rely on automated application controls without additional testing. Expect questions on how this impacts the extent of substantive testing.
14. Use data analytics answers wisely. For testing SoD across thousands of users, the most efficient and effective approach is a CAAT that compares user roles to an SoD conflict matrix (100% population testing), rather than manual sampling.
15. Eliminate distractors that weaken accountability. Shared IDs, generic accounts, and unchanged vendor default passwords are always weaknesses. They are never best practice.
Quick Example Questions and Reasoning
Example 1: An accounts payable clerk can add new vendors and enter invoices for payment. What is the primary risk?
Reasoning: the clerk could create a fictitious vendor and pay it. The answer is fictitious vendor fraud. Vendor master maintenance should be segregated from invoice processing.
Example 2: Which is the BEST test of whether access for terminated employees is removed timely?
Reasoning: compare HR termination records with active system user lists and termination dates with disable dates. The answer is reconcile the HR termination list to active accounts, not interviewing the IT manager.
Example 3: A small company has one bookkeeper who handles receipts and records them. What is the best compensating control?
Reasoning: segregation is impractical. The answer is the owner independently reviews bank statements and reconciliations, or receives the bank statements directly.
Summary
Logical access controls ensure only authorized users reach systems and data, with only the privileges they need. Segregation of duties ensures no single person controls a transaction from start to finish. Together they are foundational controls that internal auditors must evaluate during engagement planning, because they affect fraud risk, data reliability, and how much reliance can be placed on other controls. On the exam, focus on these points:
- Identify incompatible duties.
- Apply least privilege.
- Distinguish authentication factors.
- Prefer strong, direct evidence.
- Recognize appropriate compensating controls when segregation is not feasible.
Unlock Premium Access
Certified Internal Auditor Part 2
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2980 Superior-grade Certified Internal Auditor Part 2 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 2: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!