Back to all 93 controls
Annex A 5.3
Organizational
A.5.3 Segregation of duties
Prevent fraud and error by separating conflicting duties.
What good looks like
Conflicting duties (e.g. request vs approve vs deploy) are split across people or compensating controls exist.
Evidence an auditor will ask for
Role matrix, SoD analysis, approval workflows, sample tickets.
Reviewed & Verified by a Certified ISO/IEC 27001 Lead Implementer
Built for practitioners, by practitioners. Every template, control definition, and audit checklist in this directory is aligned with the latest ISO 27001:2022 standard and structured around real-world certification audit requirements.
Certified Lead Implementer
2022 Standard Aligned
Audit-Ready Materials
Put this control into practice
Check whether your organisation already meets Annex A 5.3 with the free Gap Analysis tool, or get implementation-ready templates for every Annex A control with the Document Pack.
