Auditors Overemphasize Segregation of Duties, Neglecting Critical Sensitive Access Risks
Auditors are spending too much time on Segregation of Duties (SoD) conflicts and not enough on sensitive access risks, especially in modern ERP systems. Many traditional SoD conflicts are mitigated by effective workflow designs, making their extensive testing redundant. The article advocates for a shift in focus towards identifying and auditing sensitive access risks, which can lead to significant financial fraud independently.