Discover our industry leading expertise
Upcoming Live Webinars
No upcoming events available at the moment. Stay tuned.
Empower your security team
Save time, enhance risk visibility and be audit-ready with ALLOut Security for JD Edwards.
Looking towards this post-pandemic age, it’s key to kickstart your Internal Control Health Check, beginning with monitoring SoD practices...

Post-Pandemic Recovery Plan I: Segregation of Duties by Dr Frosoulla Kofterou
Nobody can predict the future, but there are things you can do to prepare for it. Why is fraud on the rise, and why is it essential that organizations implement robust internal controls? The COVID-19 pandemic, current socioeconomic and political instability has changed the landscape of global business and work practices. Looking towards this post-pandemic age, it’s key to kickstart your Internal Control Health Check, beginning with monitoring SoD practices.
As most organizations have experienced, the world is in a constant state of flux: a truth reflected by industry experts:
ACFE’s Occupational Fraud 2022 global study states that we are facing an upward trend in occupational fraud regarding Asset Misappropriation, Corruption, and Financial Statement Fraud. The good news is that even though this trend will likely continue as businesses mobilize employees via long-term remote and hybrid work environments, proactive internal control tools result in frauds “being caught faster and causing smaller losses.”
However, this ‘new normal’ makes businesses more susceptible to what Donald Cressey identified as the fraud triangle (motivational factors contributing to fraud): pressure, opportunity, and rationalization. In fact, ISACA’s July 2022 report claims: "the disruption caused by the Covid-19 pandemic means that all elements of the fraud triangle have been heightened."
So with conditions conducive to fraud on the rise, there’s never been a better time to redefine your internal controls environment, starting with a Segregation of Duties (SoD) Health check.
Segregation of duties (SoD) is a fundamental internal control principle that divides tasks between people across a specific process. By restricting power, access, and responsibility, the SoD principle helps prevent unauthorized and fraudulent actions and human error.
1. Awareness
Establish a reliable management control framework by ensuring that your organization operates within an advanced internal control system. Use the roles and responsibilities function within software applications effectively to adhere to an SoD matrix. This proactive risk-management tool will become your most valued asset that prevents unilateral actions from being carried out during key tasks, reducing the possibility of fraud and its financial implications.
2. Identify where your SoD risks are coming from
Define and determine in which departments and during what transactions SoD risks are taking place. Risk assessment is key to preventing the following example scenarios whereby a user can:
Inappropriately access personal data held by the organization.
Set up a fictitious supplier through which to process payments.
Create a “customer” and initiate refunds.
Change the sourcing of a product to favor a particular supplier.
Create false employee records and initiate payments to them.
Make unauthorized changes to the composition of a product.
3. Document SoD
Enhance communication efficiency with your IT department by strengthening a document and report culture that provides an accurate landscape of your organization’s level of risk when it comes to SoD exposure. Ensure that you are documenting SoD occurrences and managing the associated risks in a way that your intended audience can act upon.
4. Prioritize risk
Utilizing the evidence and information gained from the aforementioned steps, prioritize SoD conflicts according to the level of risk they pose to your secure control environment, both internally and externally.
5. Commit to an ongoing SoD process
Maintaining a healthy control environment is a continuous activity involving both reactive remediation and proactive efforts. Be sure to align your business practices with the actionable elements discussed above via regular reviews. Vigilance is key to sustaining best business practices with positive long-term impacts.
Was this article helpful? Get in touch with our ALLOut Experts today to find out more!
No upcoming events available at the moment. Stay tuned.
Save time, enhance risk visibility and be audit-ready with ALLOut Security for JD Edwards.
We use cookies to give you the best online experience. By agreeing you accept the use of cookies in accordance with our cookie policy. You can always revoke your consent by clicking on the icon at the bottom left of the screen.
When you visit any web site, it may store or retrieve information on your browser, mostly in the form of cookies. Control your personal Cookie Services here.
| Cookie name | Default expiration time | Description |
|---|---|---|
| _ga | 2 years | Used to distinguish users. |
| _gid | 24 hours | Used to distinguish users. |
| _ga_<container-id> | 2 years | Used to persist session state. |
| _gac_gb_<container-id> | 90 days | Contains campaign related information. If you have linked your Google Analytics and Google Ads accounts, Google Ads website conversion tags will read this cookie unless you opt-out. Learn more. |
| visitor_id<accountid> | The visitor cookie includes a unique visitor ID and the unique identifier for your account. For example, the cookie name visitor_id12345 stores the visitor ID 1010101010. The account identifier, 12345, makes sure that the visitor is tracked on the correct Pardot account. The visitor value is the visitor_id in your Pardot account. This cookie is set for visitors by the Pardot tracking code. |
| pi_opt_in<accountid> | If Tracking Opt-in preferences is enabled, the pi_opt_in cookie is set with a true or false value when the visitor opts in or out of tracking. If a visitor opts in, the value is set to true, and the visitor is cookied and tracked. If the visitor opts out or ignores the opt-in banner, the opt-in cookie value is set to false. The visitor cookie is disabled, and the visitor is not tracked. |
| visitor_id<accountid>-hash | The visitor hash cookie contains the account ID and stores a unique hash. For example, the cookie name visitor_id12345-hash stores the hash “855c3697d9979e78ac404c4ba2c66533”, and the account ID is 12345. This cookie is a security measure to make sure that a malicious user can’t fake a visitor from Pardot and access corresponding prospect information. |
| lpv<accountid> | This LPV cookie is set to keep Pardot from tracking multiple page views on a single asset over a 30-minute session. For example, if a visitor reloads a landing page several times over a 30-minute period, this cookie keeps each reload from being tracked as a page view. |
| pardot | A session cookie named pardot is set in your browser while you’re logged in to Pardot as a user or when a visitor accesses a form, landing page, or page with Pardot tracking code. The cookie denotes an active session and isn’t used for tracking. |
| Cookie name | Default expiration time | Description |
|---|---|---|
| _ga | 2 years | Used to distinguish users. |
| _gid | 24 hours | Used to distinguish users. |
| _ga_<container-id> | 2 years | Used to persist session state. |
| _gac_gb_<container-id> | 90 days | Contains campaign related information. If you have linked your Google Analytics and Google Ads accounts, Google Ads website conversion tags will read this cookie unless you opt-out. Learn more. |
| visitor_id<accountid> | The visitor cookie includes a unique visitor ID and the unique identifier for your account. For example, the cookie name visitor_id12345 stores the visitor ID 1010101010. The account identifier, 12345, makes sure that the visitor is tracked on the correct Pardot account. The visitor value is the visitor_id in your Pardot account. This cookie is set for visitors by the Pardot tracking code. |
| pi_opt_in<accountid> | If Tracking Opt-in preferences is enabled, the pi_opt_in cookie is set with a true or false value when the visitor opts in or out of tracking. If a visitor opts in, the value is set to true, and the visitor is cookied and tracked. If the visitor opts out or ignores the opt-in banner, the opt-in cookie value is set to false. The visitor cookie is disabled, and the visitor is not tracked. |
| visitor_id<accountid>-hash | The visitor hash cookie contains the account ID and stores a unique hash. For example, the cookie name visitor_id12345-hash stores the hash “855c3697d9979e78ac404c4ba2c66533”, and the account ID is 12345. This cookie is a security measure to make sure that a malicious user can’t fake a visitor from Pardot and access corresponding prospect information. |
| lpv<accountid> | This LPV cookie is set to keep Pardot from tracking multiple page views on a single asset over a 30-minute session. For example, if a visitor reloads a landing page several times over a 30-minute period, this cookie keeps each reload from being tracked as a page view. |
| pardot | A session cookie named pardot is set in your browser while you’re logged in to Pardot as a user or when a visitor accesses a form, landing page, or page with Pardot tracking code. The cookie denotes an active session and isn’t used for tracking. |