Definition
A control failure in which responsibilities that should be divided among multiple persons or units—such as initiation, authorization, custody and reconciliation—are combined in a single individual or organizational unit, thereby enabling that actor to commit, conceal or perpetuate errors, misstatements or unauthorized transactions without timely detection.

Principle

Principle
Segregating incompatible duties reduces the capacity of any single agent to both perpetrate and conceal an adverse action; concentrating those duties increases the probability of undetected error or fraud because it removes independent checks and verifications.

Demonstration

Demonstration
Illustrative scenario: In a mid-sized company, the same employee creates vendor records, approves vendor invoices and executes payments. That combination allows creation of a fictitious vendor and misdirected payments that go unnoticed until an external audit discovers anomalies — Situation → Recognition → Action → Consequence.

Misapplication

Misapplication
Mistaken interpretation: assuming that documenting role descriptions or maintaining separate physical locations alone satisfies segregation. Semantic error: conflating nominal role separation with effective control—segregation requires enforced separation of authority, access controls, independent review and monitoring, not merely paperwork.

Consequence

Consequence
Failure of segregation increases likelihood and potential scale of misstatements, fraud or operational error, delays detection, raises remediation costs, undermines auditability and can lead to regulatory or contractual breaches; the causal path is removal of independent verification and consolidation of opportunity and control.

Reversal

Reversal
In very small organizations or where concentrated expertise is necessary, strict segregation may be infeasible; in such cases the risk can be mitigated by compensating controls (supervisory review, mandatory rotations, external reconciliations, automated controls) that recreate independent checks functionally.

Boundary

Boundary
Clearly within: one person has authority to both set up payees and execute payments with bank access. Boundary case: temporary dual-role during a planned staff transition where supervisory review is in place — heightened risk but potentially managed. Clearly outside: processes where duties are formally and operationally separated with independent reconciliation and restricted access.

Semantic Tension

Semantic Tension
Tension between control/risk reduction and operational efficiency/agility: stricter segregation improves assurance but increases staffing and transaction costs and may slow decision-making, creating a trade-off organizations must manage.

Synthesis

Synthesis
Segregation of duties is an organizational design principle that transforms a fraud-prevention requirement into operational structures; when segregation cannot be absolute, equivalent independent controls must be deliberately designed and enforced to restore the same preventive effect.