---
title: Segregation of duties
description: Segregation of duties
---

[Skip to content](https://knowledge.sensiba.com/cdr-guides/network-security/segregation-of-duties#main-content)

English

Show submenu for translations

- Sensiba

Open main navigation

Close main navigation

- Sensiba
- English
  
  Show submenu for translations
- [Go to sensiba.com](https://sensiba.com/)

[Go to sensiba.com](https://sensiba.com/)

 Hi There! How can we help you?

- There are no suggestions because the search field is empty.

1. [Sensiba Knowledge Base](https://knowledge.sensiba.com/?hsLang=en)
2. [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en)
3. [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)

# Segregation of duties

## Segregation of duties supports role-based access control and change control by separating roles that should be performed by separate personnel.

Segregation of duties is the practice of limiting conflicts of interest and the opportunity to perform inappropriate activities. This is achieved by the design of roles and responsibilities and system access privileges.

The Consumer Data Right gives Australians control of their data. That enables innovation in new products and services to those consumers. To participate as a data recipient, there are five governance requirements and 24 information security requirements. These are independently audited by a qualified firm like Sensiba, and included in an assurance report for accreditation.

Approval processes are the most common segregation of duties practice. Whatever the approval relates to, having this approval ensures that a second person is involved. This is usually at a higher level of seniority that is accountable for the matter being approved. Another key method of segregating duties is through access control, separating system functions that can be performed by role; for example, developers work in the code base but can't migrate those changes into production.

As it relates to the Consumer Data Right (CDR), change control segregation of duties is the key area of focus. This segregation provides the foundation of the Change Control practices, supporting the [Change Control Policy and environment](https://knowledge.assurancelab.cpa/cdr-guides/vulnerability-management/change-control-policy-environment). You may have a well-defined process for raising change tickets, defining requirements, testing, and approving changes prior to implementation. But without segregation of duties, that may be bypassed by a developer has the ability to. That's why segregation of duties is important to ensure high-quality changes, that are authorised, appropriate and secure.

The common method of implementing this is in your version control software like Github, Bitbucket or Gitlab. These each have a setting in the configurations to "enforce a minimum number of approving reviewers".

 

**The CDR Perspective**

Segregation of duties supports two areas of the 24 information security requirements:

- **Secure coding:** changes to the accredited data recipient's systems (including its CDR data environment) are designed and developed consistent with industry accepted secure coding practices, and are appropriately tested prior to release into the production environment.
- **Role based access:** involves assigning specific access rights to a role and providing a user with access to that role as opposed to assigning rights directly to an account. This allows simplifying the user access management process. Further, RBAC should be used to minimise the access rights provided to each user to only that necessary for the user to perform their assigned duties.

 

- [Platform](https://knowledge.sensiba.com/platform?hsLang=en#main-content)

    - [Vanta](https://knowledge.sensiba.com/platform?hsLang=en#vanta)
    - [Drata](https://knowledge.sensiba.com/platform?hsLang=en#drata)
    - [Scrut](https://knowledge.sensiba.com/platform?hsLang=en#scrut)
    - [Sprinto](https://knowledge.sensiba.com/platform?hsLang=en#sprinto)
- [Best Practices Series](https://knowledge.sensiba.com/best-practices-series?hsLang=en#main-content)

    - [Risk management & internal controls](https://knowledge.sensiba.com/best-practices-series?hsLang=en#risk-management-internal-controls)
    - [Information & communication](https://knowledge.sensiba.com/best-practices-series?hsLang=en#information-communication)
    - [Data protection](https://knowledge.sensiba.com/best-practices-series?hsLang=en#data-protection)
    - [System security](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-security)
    - [Change management](https://knowledge.sensiba.com/best-practices-series?hsLang=en#change-management)
    - [System operations](https://knowledge.sensiba.com/best-practices-series?hsLang=en#system-operations)
    - [Control environment](https://knowledge.sensiba.com/best-practices-series?hsLang=en#control-environment)
- [Consumer Data Right Guides](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#main-content)

    - [Network Security](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#network-security)
    - [Vulnerability Management](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#vulnerability-management)
    - [Security Awareness](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#security-awareness)
    - [Anti-malware](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#anti-malware)
    - [Information Asset Lifecycle](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#information-asset-lifecycle)
    - [Access Control](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#access-control)
    - [Governance Requirements](https://knowledge.sensiba.com/consumer-data-right-guides?hsLang=en#governance-requirements)
- [ISO 27001](https://knowledge.sensiba.com/iso-27001?hsLang=en)
- [Control Environment](https://knowledge.sensiba.com/control-environment?hsLang=en)
- [Information and Communication](https://knowledge.sensiba.com/information-and-communication?hsLang=en)
- [Risk Management](https://knowledge.sensiba.com/risk-management?hsLang=en)
- [Vendor Management](https://knowledge.sensiba.com/vendor-management?hsLang=en)
- [System Security](https://knowledge.sensiba.com/system-security?hsLang=en)
- [System Operations](https://knowledge.sensiba.com/system-operations?hsLang=en)
- [Change Management](https://knowledge.sensiba.com/change-management?hsLang=en)
- [Confidentiality](https://knowledge.sensiba.com/confidentiality?hsLang=en)
- [Privacy](https://knowledge.sensiba.com/privacy?hsLang=en)
- [CDR Reps](https://knowledge.sensiba.com/cdr-reps?hsLang=en)
- [Access reviews](https://knowledge.sensiba.com/access-reviews?hsLang=en)
- [Governance](https://knowledge.sensiba.com/governance?hsLang=en)
- [Employee management](https://knowledge.sensiba.com/employee-management?hsLang=en)
- [FAQs](https://knowledge.sensiba.com/faqs?hsLang=en)
- [Sensiba Audit Tools](https://knowledge.sensiba.com/sensiba-audit-tools?hsLang=en)

- Sensiba

[![Sensiba Logo](https://knowledge.sensiba.com/hs-fs/hubfs/Sensiba_Logo_Hubspot-01.png?width=247&height=48&name=Sensiba_Logo_Hubspot-01.png "Sensiba Logo")](https://sensiba.com/)

Copyright © 2026, Sensiba LLP