February 26, 2024

ISO 27001:2022 Annex A Control 5.3: Segregation of Duties

Annex 5.3 of the 2022 version of the ISO 27001 standard can be mapped to ISO 27001:2013 Annex 6.1.2.

By
Full name
Share this post
https://www.hicomply.com/hub/iso-27001-annex-a-5-3-segregation-of-duties
A woman smiles while using a tablet, surrounded by digital notifications and a data chart.

In addition to establishing the information security roles for personnel within an organisation, it is necessary to identify the segregation of duties – formalising where each individual’s responsibilities begin and end.

Creating a functional management framework will enable an organisation to effectively control many aspects of information security, including the implementation and day-to-day operation of various functions.

Segregating information security duties will help to avoid any conflict of duty or duplication of effort. Documenting the management framework can also serve to identify any gaps or vulnerabilities, forming part of the risk evaluation and treatment process.

In smaller organisations it may be necessary for personnel to assume mixed roles or have overlapping roles and responsibilities. While this cannot be avoided in all instances, the principle of role segregation should be applied as much as possible to mitigate the risk of fraud and unauthorised access. In these instances, proper governance and controls should focus on information assets with the greatest risk and the highest value.

{{snapshot}}

Segregation of duties at a glance

  • Purpose: formalise where each person’s responsibilities begin and end to avoid conflict of duty and duplication of effort.
  • Risks mitigated: fraud, error, unauthorised access and any one person overriding information security controls.
  • Small organisations: where full separation is not feasible, monitor activity, ensure management supervision and retain audit trails.
  • Lineage: updates ISO 27001:2013 Annex A control 6.1.2.

{{/snapshot}}

Understanding conflicting duties and responsibility segregation

The effective running of an organisation requires established processes, procedures and policies to govern internal operations. Documenting these processes and establishing a framework for employee duties is a key to best practice and maintaining business as usual.

Failure to document roles clearly and delineate between responsibilities risks inefficiency, conflicting operational activity and the potential for fraudulent behaviour. By effectively segregating duties, an organisation can help to avoid these types of issue, improving productivity and mitigating risk in the process.

The purpose and requirements of Annex 5.3

In simple terms, Annex 5.3 identifies how a person may be prevented from committing, concealing or justifying actions that negatively impact the organisation. The segregation of roles and responsibilities also prevents an individual from overriding information security controls.

Through the effective delegation of tasks, an organisation is able to implement checks and balances that mitigate the risk of errors, fraud or lost productivity.

Just as overlapping responsibilities is problematic, attributing all responsibilities to one individual is also deemed to be a significant risk to business as usual.

In order to achieve ISO 27001:2022 compliance, an organisation is required to identify which duties should be separated and document steps to action separation controls. In small organisations where this separation is not practical or feasible, measures should be implemented to monitor activity, ensure management supervision and retain audit trails.

Automated tools may play a role in identifying and segregating roles within larger organisations to prevent conflicting roles.

{{snapshot}}

Making segregation work

  • Prevent wrongdoing: stops individuals committing, concealing or justifying harmful actions and overriding controls.
  • Checks and balances: delegating tasks mitigates errors, fraud and lost productivity.
  • Avoid extremes: neither overlapping duties nor concentrating all responsibility in one person is acceptable.
  • Compliance: identify which duties to separate and document the separation controls.
  • Where impractical: automated tools plus supervision and audit trails keep smaller teams covered.

{{/snapshot}}

Who is responsible for Annex A 5.3?

Depending on the size of an organisation, a group of qualified employees should hold responsibility for the effective segregation of duties. This begins with a senior management team member who is responsible for the conducting of an initial risk assessment.

Maintaining company security requires that further tasks are assigned to functioning work units and departments.

An effective risk management strategy is essential to creating a suitable control environment for duties to be segregated.

What’s changed from ISO 27001:2013?

ISO27001:2022 Annex A control 5.3 Segregation of Duties updates Annex A control 6.1.2 from the ISO 27001:2013 standard. In the most recent version of the standard, a number of activities that require segregation during implementation are defined. This includes:

Activity areaDuties to keep separate
Change managementInitiating, approving and executing a change
Access rightsRequesting, approving and implementing access rights
CodeDesigning, implementing and reviewing code
Software vs productionDeveloping software and administering production systems
ApplicationsUsing and administering applications
DatabasesUsing applications and administering databases
Security assuranceDesigning, auditing and assuring information security controls

{{snapshot}}

From the Hicomply team

Segregation of duties is where small teams get stuck — you simply don’t have enough people to split every role. That’s fine: document the conflicts you can’t avoid, add compensating supervision and keep tamper-evident audit trails, then let the system flag toxic access combinations automatically. Our ISO 27001 hub shows how to evidence this for an assessor.

{{/snapshot}}

Risk Management
Compliance Reporting
Policy Management
Incident Management
Audits and Assessments

Ready to Take Control of Your Privacy Compliance?

See how Hicomply can accelerate your path to CAF compliance in a 15-minute demo.

Risk Management

Identify, assess, and mitigate security risks with an integrated risk register.Hicomply’s automated risk management software maps controls across ISO 27001, SOC 2, and NIST frameworks — helping teams track risk treatment plans, assign ownership, and monitor real-time compliance status. Build a resilient ISMS that reduces audit findings and demonstrates continuous improvement.

Compliance Reporting

Generate instant, audit-ready compliance reports across multiple frameworks — from ISO 27001 and SOC 2 to GDPR, DORA, and NHS DSPT.Automated evidence collection and built-in dashboards provide a single source of truth for your compliance posture, saving weeks of manual work during audits.

Policy Management

Centralise, version, and publish all your information security policies in one place.Hicomply automates approvals, reminders, and distribution, ensuring your ISMS documentation stays current and aligned with frameworks like ISO 42001 and NIST CSF.Say goodbye to outdated PDFs — manage policies dynamically and maintain full traceability.

Incident Management

Capture, investigate, and resolve security incidents with structured workflows and automated evidence trails.Hicomply integrates with ticketing tools like Jira, Zendesk, and Azure DevOps to streamline incident response and link findings to risk and control updates — a key step for SOC 2 Type II readiness.

Audits and Assessments

Simplify internal and external audit preparation with built-in audit templates and automated task assignments.
Hicomply’s audit management platform aligns with ISO 27001, ISO 9001, and ISO 14001, giving teams a clear overview of control effectiveness, audit evidence, and corrective actions — all from one dashboard.

Preparing for Your Audit
Computer Software
IT and Services
Enterprise