For decades, segregation of duties (SoD) has been one of finance’s most reliable safeguards. SoD is a simple, well-understood principle: No single individual should be able to request, approve and execute a financially material action.
It worked because work was human. Processes were linear, systems were centralized, and the boundaries of control were visible.
Those assumptions no longer hold.
Today, financial workflows are shared by humans, AI agents, automation scripts, API-driven systems and cloud services that operate independently of traditional policy checkpoints. The modern enterprise is now a hybrid workforce, where nonhuman identities often carry privileges that rival or exceed those of employees.
While boards now dedicate more agenda time to cyber risk, identity risk remains dramatically under-addressed. Directors know about ransomware and worry about outages. But many still underestimate the core issue behind nearly every material breach: Compromised credentials and privilege abuse remain dominant attack paths across industries, countries and years.
When the credentials belong to a human, the escalation path is familiar. When they belong to a machine identity, the risk becomes invisible, high-velocity and often unmonitored.
This gap is widening quickly with AI agents creating vendors, modifying financial records, approving workflows and accessing sensitive data.
As a result, the uncomfortable truth is that most organizations cannot prove that their machine identities comply with SoD, least privilege, ownership or even basic life cycle hygiene.
Classical SoD frameworks assume:
In a hybrid workforce, none of this is guaranteed.
AI agents don’t fit job descriptions. They scale elastically. They inherit permissions from scripts, cloud templates or legacy directories. They accumulate privileges as systems evolve. And because they don’t complain, resign or submit expense reports, no one notices when their access becomes dangerously broad.
Even worse, machine workflows often cross the very boundaries SoD was designed to enforce:
SoD collapses the moment one agent spans two conflicting control surfaces. CFOs worry about people stealing cash, but the more immediate risk is silent automation operating with excessive, unmonitored privilege.
Boards often consider SoD a compliance checkbox, not a strategic risk. But in a hybrid human-machine environment, SoD failure becomes a:
When identity risk is not visible, SoD becomes an assumption rather than an assurance. Assumptions do not satisfy auditors, insurers or regulators.
The new SoD framework must move beyond static roles and quarterly certifications. It must account for:
This kind of visibility cannot be produced manually. It requires technology that models access relationships the way finance models cash flows—holistically, dynamically and with clear lineage.
Modern approaches use identity digital twins and knowledge graphs to rebuild a daily picture of people, systems, entitlements and machine interactions (full disclosure: Gathid offers this solution). With this, organizations can detect SoD violations every day, simulate privilege changes before implementation and surface which identities (human or machine) are at the heart of financial risk.
Most importantly, it transforms SoD from a static policy into a living, measurable control.
Boards do not need technical detail. Here are a few questions boards should be asking:
These questions shift the conversation. Identity risk becomes quantifiable, SoD becomes board-visible, and automation becomes safe to scale.
CFOs are now central to this evolution because, at its core, SoD is a financial control. A modern SoD program should begin with a simple premise: You cannot segregate duties you cannot see.
From there, the road map becomes straightforward:
Traditional SoD was built for a world that no longer exists. The new SoD must be dynamic, identity-anchored, machine-aware and demonstrable. CFOs are uniquely positioned to lead this shift. Boards are expecting it. Insurers are pricing it. Auditors are testing it. AI is accelerating it.
Companies that modernize SoD now don’t just reduce risk; they can also gain the confidence to scale automation safely, responsibly and at the speed the market demands.