Segregation of Duties (SOD) is a concept that advocates the division of responsibilities within organizations. It is enforced by the Sarbanes Oxley Act (SOX) Act of 2002. This US law governs the accounting practices of publicly listed companies and fully-owned subsidiaries. Other similar global mandates call for appropriate and up-to-date user entitlements and SOD controls to reduce fraud.
Apart from ensuring compliance, many organizations implement SOD controls to keep a check on individual duties. To put it simply, SOD requires more than one person to complete a task. By doing so, organizations discourage giving complete access to a function to one individual. By controlling the access, SOD reduces risk and fraudulent activities.
Several organizations rely on manual processes to implement and audit user access controls. However, it is an inefficient approach. Apart from being time-consuming and expensive, it can also lead to inaccuracies in the control system.
Realizing that there was a need for an advanced tool to manage this risk effectively, Doyensys seized the opportunity and developed a tool, “Segregation of Duties.”
What are the salient features of the Segregation of Duties Tool by Doyensys?
- It is a configurable tool that identifies access-level conflicts. It also alerts the appropriate stakeholders about these conflicts for immediate action.
- It can be used as an audit module to identify and report user access level compliances. The Audit Module has the following features.
- The module is self-sufficient in recognizing user and responsibility level assignments and usage patterns.
- The audit module has the provision to create & maintain multiple base-lines of customer-specific data. Users can also compare two base-lines to identify incremental changes and understand the exceptions that were fixed, newly introduced, or not changed.
- The tool can also generate reports at the organization or individual user level.
- The SOD module has a User Access Module to control and track the EBS user creation and modification. The module has other features as well.
- The module allows one to create or modify users with a custom approval workflow.
- It also enables adding or deleting responsibilities in the workflow, adding or deleting a role, and maintaining the allocation history.
- The module also proactively notifies the stakeholders in case of access control conflicts during a new user creation process.
- The module displays users that may get impacted when a new role is added, or an existing one is modified. It sends notifications in case of any conflicts while creating new roles.
- The tool has an audit history-based provision to give a start or end date to user responsibilities.
- There is a provision to find unused responsibilities over a period and revoke the allocation to avoid misuse.
- The SOD tool has a License Tracking Module to track EBS license usage. The module offers the following reports to make informed decisions in the future.
- It gives a real-time report on planned versus actual usage.
- You also get a module-wise drilled down report on license usage.
- The report offers user & responsibilities-wise data.
- It presents the actual usage trend over a period.
What are the benefits of the SOD tool by Doyensys?
- It offers a systematic way of enforcing system compliance levels.
- The tool shares several reports that can help in making crucial decisions.
- By automating system controls, the tool allows greater flexibility and ease in creating new or modifying existing accesses.
- As it maintains the audit history, it becomes easier to track in the future.
Summary
At a time when organizations require effective controls to reduce the risks for the benefit of their shareholders, the SOD tool by Doyensys is a comprehensive solution. It is efficient, minimizes human error, and is a cost-effective way to ensure compliance.