Which concept focuses on preventing fraud by separating duties among individuals?

Prepare for the Certified Identity and Access Manager Exam using flashcards and multiple-choice questions. Gain insights into the exam format, practice with real-world scenarios, and ensure your success in becoming a certified professional.

Multiple Choice

Which concept focuses on preventing fraud by separating duties among individuals?

Explanation:
Segregation of duties is a fundamental internal control that prevents fraud by distributing key steps of a process among multiple people. When authorization, execution, recordkeeping, and custody of assets are handled by different individuals, no one has end-to-end control, making it much harder to commit and conceal fraud. It also makes it easier to detect inconsistencies, since a second person is required to review or reconcile activity. For example, in a payment workflow, the person who approves a vendor, the person who processes the payment, and the person who reconciles the bank statement should be different. This creates checks and balances that reduce opportunity for misuse. The other concepts don’t implement this separation of duties by design: metrics indicators focus on measurement, a centralized repository is about data storage, and an access review ensures appropriate access levels but doesn’t inherently split duties across steps of a process.

Segregation of duties is a fundamental internal control that prevents fraud by distributing key steps of a process among multiple people. When authorization, execution, recordkeeping, and custody of assets are handled by different individuals, no one has end-to-end control, making it much harder to commit and conceal fraud. It also makes it easier to detect inconsistencies, since a second person is required to review or reconcile activity. For example, in a payment workflow, the person who approves a vendor, the person who processes the payment, and the person who reconciles the bank statement should be different. This creates checks and balances that reduce opportunity for misuse. The other concepts don’t implement this separation of duties by design: metrics indicators focus on measurement, a centralized repository is about data storage, and an access review ensures appropriate access levels but doesn’t inherently split duties across steps of a process.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy