ISO 27001:2022 Annex A Control 5.3: Segregation of Duties
Annex 5.3 of the 2022 version of the ISO 27001 standard can be mapped to ISO 27001:2013 Annex 6.1.2.

In addition to establishing the information security roles for personnel within an organisation, it is necessary to identify the segregation of duties – formalising where each individual’s responsibilities begin and end.
Creating a functional management framework will enable an organisation to effectively control many aspects of information security, including the implementation and day-to-day operation of various functions.
Segregating information security duties will help to avoid any conflict of duty or duplication of effort. Documenting the management framework can also serve to identify any gaps or vulnerabilities, forming part of the risk evaluation and treatment process.
In smaller organisations it may be necessary for personnel to assume mixed roles or have overlapping roles and responsibilities. While this cannot be avoided in all instances, the principle of role segregation should be applied as much as possible to mitigate the risk of fraud and unauthorised access. In these instances, proper governance and controls should focus on information assets with the greatest risk and the highest value.
{{snapshot}}
Segregation of duties at a glance
- Purpose: formalise where each person’s responsibilities begin and end to avoid conflict of duty and duplication of effort.
- Risks mitigated: fraud, error, unauthorised access and any one person overriding information security controls.
- Small organisations: where full separation is not feasible, monitor activity, ensure management supervision and retain audit trails.
- Lineage: updates ISO 27001:2013 Annex A control 6.1.2.
{{/snapshot}}
Understanding conflicting duties and responsibility segregation
The effective running of an organisation requires established processes, procedures and policies to govern internal operations. Documenting these processes and establishing a framework for employee duties is a key to best practice and maintaining business as usual.
Failure to document roles clearly and delineate between responsibilities risks inefficiency, conflicting operational activity and the potential for fraudulent behaviour. By effectively segregating duties, an organisation can help to avoid these types of issue, improving productivity and mitigating risk in the process.
The purpose and requirements of Annex 5.3
In simple terms, Annex 5.3 identifies how a person may be prevented from committing, concealing or justifying actions that negatively impact the organisation. The segregation of roles and responsibilities also prevents an individual from overriding information security controls.
Through the effective delegation of tasks, an organisation is able to implement checks and balances that mitigate the risk of errors, fraud or lost productivity.
Just as overlapping responsibilities is problematic, attributing all responsibilities to one individual is also deemed to be a significant risk to business as usual.
In order to achieve ISO 27001:2022 compliance, an organisation is required to identify which duties should be separated and document steps to action separation controls. In small organisations where this separation is not practical or feasible, measures should be implemented to monitor activity, ensure management supervision and retain audit trails.
Automated tools may play a role in identifying and segregating roles within larger organisations to prevent conflicting roles.
{{snapshot}}
Making segregation work
- Prevent wrongdoing: stops individuals committing, concealing or justifying harmful actions and overriding controls.
- Checks and balances: delegating tasks mitigates errors, fraud and lost productivity.
- Avoid extremes: neither overlapping duties nor concentrating all responsibility in one person is acceptable.
- Compliance: identify which duties to separate and document the separation controls.
- Where impractical: automated tools plus supervision and audit trails keep smaller teams covered.
{{/snapshot}}
Who is responsible for Annex A 5.3?
Depending on the size of an organisation, a group of qualified employees should hold responsibility for the effective segregation of duties. This begins with a senior management team member who is responsible for the conducting of an initial risk assessment.
Maintaining company security requires that further tasks are assigned to functioning work units and departments.
An effective risk management strategy is essential to creating a suitable control environment for duties to be segregated.
What’s changed from ISO 27001:2013?
ISO27001:2022 Annex A control 5.3 Segregation of Duties updates Annex A control 6.1.2 from the ISO 27001:2013 standard. In the most recent version of the standard, a number of activities that require segregation during implementation are defined. This includes:
| Activity area | Duties to keep separate |
|---|---|
| Change management | Initiating, approving and executing a change |
| Access rights | Requesting, approving and implementing access rights |
| Code | Designing, implementing and reviewing code |
| Software vs production | Developing software and administering production systems |
| Applications | Using and administering applications |
| Databases | Using applications and administering databases |
| Security assurance | Designing, auditing and assuring information security controls |
{{snapshot}}
From the Hicomply team
Segregation of duties is where small teams get stuck — you simply don’t have enough people to split every role. That’s fine: document the conflicts you can’t avoid, add compensating supervision and keep tamper-evident audit trails, then let the system flag toxic access combinations automatically. Our ISO 27001 hub shows how to evidence this for an assessor.
{{/snapshot}}
Ready to Take Control of Your Privacy Compliance?
See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.




