Day 17 of 22ITGC · SOC 1 / SOC 2· ~60 min

Build a segregation-of-duties matrix

Scenario

KaizenMotors' Finance function has 12 roles: 1. AP Clerk 2. AP Manager 3. AR Clerk 4. AR Manager 5. GL Accountant 6. Sr GL Accountant 7. Treasury Analyst 8. Treasury Manager 9. Payroll Admin 10. Financial Controller 11. CFO 12. Audit Committee Member And 6 critical transactions: A. Create Vendor B. Approve Vendor C. Post Journal Entry D. Approve Journal Entry E. Initiate Payment F. Approve Payment

Your role

You are designing the SoD matrix that will become part of the ITGC control set.

Your task

Produce: 1. 12x6 SoD matrix — for each role, which transactions they CAN or CANNOT do 2. List of forbidden combinations (e.g. same person cannot do Create Vendor + Approve Vendor) 3. Compensating controls where SoD can't be enforced (small teams) 4. Monitoring approach — how you'd detect a SoD violation weekly

Deliverable format: Matrix table + narrative ~500 words

Toolkit

  • Universal rules: 4-eye principle for approvals; person who creates cannot approve; person who initiates cannot authorise release
  • Small-team compensating controls: transaction log review, exception reporting, manager attestation
  • Monitoring: audit-log analysis, red-flag reports, quarterly certification
  • CFO is a tough spot — often has broad access; controlled by audit-committee visibility

Success criteria (what the AI grades against)

  • Matrix is internally consistent (no forbidden combinations in any single role)
  • Compensating controls proposed where segregation isn't feasible
  • Monitoring detection is proactive (not just annual review)
  • CFO access appropriately constrained (or compensated)
  • Payroll admin has appropriate constraint (can process but not approve own team)

Log in to submit your deliverable for AI review.

Log in / Register