Note (September 2026): This guide was expanded to separate two different kinds of conflict: technical conflicts between processes, which databases resolve with concurrency control, and segregation of duties (SoD) conflicts between people’s access rights, which SoD control monitoring is designed to detect.
To stay compliant while resolving conflicts in data management tools, handle two problems separately. Technical conflicts, such as two processes writing the same record, are prevented with database concurrency control (locking or optimistic checks). Access conflicts, where one person holds duties that should be split, are found with segregation of duties (SoD) analysis, fixed by removing access or adding compensating controls, and documented for auditors.
Key Takeaways
- Segregation of duties (SoD) means more than one person is required to complete a sensitive task, so that no single person can commit and hide fraud or errors.
- Process, data and resource conflicts are technical problems solved by concurrency control; SoD conflicts are people-and-permission problems solved by access design and monitoring.
- Section 404 of the Sarbanes-Oxley Act (2002) requires management and the external auditor of US public companies to report on internal control over financial reporting, where SoD is a core control.
- GDPR Article 32 requires appropriate technical and organisational measures to secure personal data; ISO/IEC 27001:2022 lists segregation of duties as Annex A control 5.3.
- When duties cannot be split, for example in a small team, a documented compensating control such as independent review is the accepted fallback.
As data volumes continue to grow, it becomes increasingly difficult for businesses to keep track of their information and ensure that they are in compliance with all relevant regulations. Many organizations turn to data management tools to help them stay organized, but these tools can often lead to conflict.
This guide explains how to resolve these conflicts while staying compliant with rules such as the Sarbanes-Oxley Act (SOX) and the EU General Data Protection Regulation (GDPR), including by using SoD control monitoring.

Understand The Different Types Of Conflicts
In data management, the word “conflict” covers two different problems. Technical conflicts between processes can generally be classified into three categories:
Process conflicts: Occur when two or more processes are trying to access the same data at the same time.
Data conflicts: Occur when two or more processes are trying to write to the same data set.
Resource conflicts: Occur when two or more processes are trying to use the same resources, such as CPU time or memory space.
These three are technical conflicts, which database systems handle with concurrency control such as locking. They are different from segregation of duties (SoD) conflicts, where one person holds two permissions that should be split, such as setting up a vendor and approving payments to it. Businesses need to understand both kinds, and how each is resolved, so they can prevent them from happening in the first place. One way to do this is by mapping out your data and its management processes.
Mapping Out Your Data And Its Management Processes
Creating a map of your data and its management processes can help you to identify potential conflicts before they happen. This will allow you to take steps to prevent them or, at the very least, mitigate their impact. To create a map of your data, you will need to:
- Identify all of the data sets that are managed by your organization.
- For each data set, identify who is responsible for managing it and what processes are used to do so.
- For each process, identify what resources are required, how they are used, and which user roles can read, change or approve the data.
Once you have created a map of your data and its management processes, you can use it to identify potential conflicts. You can also use it to create a plan to resolve any conflicts that are identified.
Implementing A Resolution Plan
Once you have identified a conflict, you will need to implement a resolution plan. This plan should include:
- The steps required to resolve the conflict.
- Who is responsible for each step.
- What resources are required and how they will be used.
- How the resolution process will be tested and verified.
Training Staff On How To Resolve Conflicts
In order for your resolution plan to be effective, staff must be trained on how to use it. They should also be familiar with the different types of conflicts and how they can be resolved.
Training staff on how to respond to conflict situations is an important part of maintaining compliance with your data management tools.
Monitoring The Resolution Process Using SoD Control Monitoring
Once you have implemented your resolution plan and trained staff on how to use it, you will need to monitor the process to ensure that it is effective. One way to do this is by using SoD control monitoring. SoD control monitoring can help you to:
- Identify any issues with the resolution process.
- Ensure that staff are following the correct procedures and that no user has gained a conflicting combination of access rights.
- Track the progress of the resolution process and identify any areas where improvements can be made.
SoD control monitoring does not make a process compliant on its own, but it produces the evidence auditors ask for: who holds which access, which conflicts were flagged, and how each one was removed or approved with a compensating control.
In conclusion, staying compliant while using data management tools can be a challenge, but it is possible to resolve conflicts and remain compliant by combining concurrency controls for technical conflicts with SoD control monitoring for access conflicts.
By understanding the different types of conflicts and implementing a resolution plan, you can keep your data management processes running smoothly.
What Is a Segregation of Duties (SoD) Conflict?
A segregation of duties (SoD) conflict exists when one person can perform two or more steps of a sensitive process that should be handled by different people. Segregation of duties, also called separation of duties, is an administrative control that requires more than one person to complete a task, in order to prevent fraud, theft, misuse of information and errors.
The classic example is the requirement for two signatures on a cheque. In SoD theory, business-critical duties fall into four types of function: authorization, custody of assets, record keeping, and reconciliation. Ideally, no single person handles more than one of these functions for the same process.
Common examples of SoD conflicts
- Receiving customer cheques and also approving write-offs.
- Depositing cash and also reconciling the bank statements.
- Approving employee time cards and also having custody of the pay cheques.
- In IT systems, creating a login account and also authorizing that account’s creation.
- Implementing source code or database changes and also approving those changes.
These conflicts matter in data management tools because modern ERP, finance and database platforms grant these powers through roles and permissions. A user who collects roles over time can end up holding a risky combination without anyone intending it, which is one route for internal threats to data security.
Technical Conflicts vs. SoD Conflicts: What Is the Difference?
Technical conflicts happen between processes or transactions; SoD conflicts happen between the duties assigned to people. The table below compares the main types.
| Conflict type | What happens | Typical fix |
|---|---|---|
| Lost update | A second transaction writes a value on top of a value written by a first concurrent transaction, so the first value is lost. | Concurrency control: locking or optimistic validation at commit |
| Dirty read | A transaction reads a value written by another transaction that is later aborted. | Transaction isolation and concurrency control |
| Resource contention | Processes compete for the same CPU time, memory or storage. | Scheduling, capacity planning, queueing |
| SoD conflict | One user holds two duties that should be split, such as authorization and custody. | Remove or split access, or document a compensating control |
Optimistic vs. pessimistic concurrency control
Database systems use two main categories of concurrency control. Optimistic control lets transactions proceed without blocking and checks for rule violations only when each transaction commits; a transaction that violates the rules is aborted and restarted. Pessimistic control blocks an operation that might cause a violation until the risk has passed, which protects data at some cost to performance. Optimistic control is very efficient when few transactions need to be aborted.
Which Rules and Standards Require These Controls?
Several laws and standards make access control and segregation of duties part of compliance. The main ones for data management teams are summarized below, as of September 2026.
| Rule or standard | What it requires | Who it applies to |
|---|---|---|
| Sarbanes-Oxley Act (SOX), enacted July 30, 2002 | Section 404 requires management and the external auditor to report on the adequacy of internal control over financial reporting. | US public companies (some provisions also apply to private companies) |
| EU GDPR (Regulation (EU) 2016/679), effective May 25, 2018 | Article 32 requires appropriate technical and organisational measures to secure personal data; Article 5 requires integrity and confidentiality and makes the controller accountable for demonstrating compliance. | Organizations in the EU/EEA, and organizations elsewhere that process personal data of people in the EU |
| ISO/IEC 27001:2022 | Annex A control 5.3, Segregation of duties, calls for conflicting duties to be separated. | Any organization that adopts or certifies an information security management system (certification is optional unless a law or contract requires it) |
| NIST/ANSI/INCITS RBAC standard (2004) | Its “constrained RBAC” level adds separation of duties to role-based access control. | A reference model used when designing roles in software |
Under the GDPR, the highest tier of fines reaches €20 million or 4% of annual worldwide turnover for the preceding financial year, whichever is greater, for breaches such as the basic processing principles in Article 5. Controllers must also report personal data breaches that have an adverse effect on privacy to their national supervisory authority within 72 hours. For the UK position after Brexit, see this guide to UK GDPR as the domestic data law.
SOX compliance has a strong IT dimension: according to the Wikipedia summary of separation of duties, a high percentage of Sarbanes-Oxley internal audit issues come from IT.
How to Resolve an SoD Conflict Step by Step
- Inventory roles and permissions. Export every user, role and permission from each data management tool, including service accounts and administrator accounts.
- Define the conflict rules. List which pairs of duties must not be combined, using the four functions (authorization, custody, record keeping, reconciliation). ISACA’s Segregation of Duties Control matrix is a general guideline for IT positions, not an industry standard.
- Run the analysis. Compare each user’s combined access against the rules and list every violation, including conflicts that arise across two different systems.
- Remediate. Remove the unnecessary permission, split the role into two, or reassign the task. Apply the principle of least privilege: each user or process should have only the access needed for its legitimate purpose.
- Document exceptions. Where a conflict must stay, record the business reason, the approver and the compensating control that offsets the risk.
- Monitor continuously. Re-run the analysis whenever roles change and review access on a fixed schedule, so new conflicts are caught before an auditor finds them.
What If Your Team Is Too Small to Split Duties?
Small organizations often cannot give every duty to a different person, and those lacking SoD typically face the most risk in disbursement cycles, where unauthorized purchases and payments can occur. The accepted answer is a compensating control rather than ignoring the conflict.
- Four-eyes principle: a second person reviews and approves the action.
- Two-signature rule: payments need two approvers, the traditional cheque example of SoD.
- Independent reconciliation: someone who did not record the transactions reconciles them, for example an owner or outside accountant reviewing bank statements.
- Activity logs: logs of changes made by privileged users, reviewed by someone else.
These measures complement broader ways to enhance data security and the wider case for prioritising business compliance.
Common Mistakes to Avoid
- Treating SoD as a one-time project instead of re-checking access when people change jobs.
- Checking each application separately and missing conflicts that span two systems, such as vendor setup in one tool and payment release in another.
- Leaving shared or generic administrator accounts in place, which make it impossible to prove who did what.
- Approving exceptions without naming a compensating control and an owner.
- Assuming a tool’s default roles are conflict-free instead of reviewing them against the organization’s own rules.
For the bigger picture of why structured data handling matters, see why data management is vital.
Frequently Asked Questions
What is SoD control monitoring?
SoD control monitoring is the ongoing check that no user holds a combination of access rights that breaks the organization’s segregation of duties rules. It compares each user’s roles against a conflict rule set, flags violations, and records how each one was fixed or approved.
What is an example of a segregation of duties conflict?
A common segregation of duties conflict is one employee who can both deposit cash and reconcile the bank statements. The same person could take money and hide the shortfall. Splitting the two tasks, or adding an independent review, reduces the risk.
Is segregation of duties required by law?
Segregation of duties is rarely written as a standalone legal rule, but it is a core internal control relevant to the internal control reporting required by Section 404 of the Sarbanes-Oxley Act for US public companies. ISO/IEC 27001:2022 lists it as Annex A control 5.3, and the GDPR requires appropriate organisational measures to secure personal data.
How is a data conflict different from an SoD conflict?
A data conflict is a technical clash, such as two processes writing to the same record at once, and it is prevented by database concurrency control. An SoD conflict is an access problem in which one person holds duties that should be split, and it is prevented by role design and monitoring.
What is a compensating control?
A compensating control is an alternative safeguard used when duties cannot be separated, such as a second person reviewing transactions, a two-signature rule for payments, or independent reconciliation of accounts. It should be documented with an owner so auditors can test it.