US · guidance
BOP Program Statement 8052.04 § 5
SEGREGATION OF DUTIES (SOD).
SOD conflicts are risks or transactions that present an opportunity for an individual to control a
process, from beginning to end, without the involvement of others.
The process of segregating is the ability to separate out transactions within a role, or the stacking
of roles to eliminate the threat of an individual controlling an entire process, as a matter of
security and/or internal control management.
SOD conflicts are identified using the GRC tool maintained by the GRC Administrator or
designee. A role or user account with a combination of roles that present SOD conflicts are
reported to the BPO to either:
■ Assign an existing mitigating control.
■ Create a new mitigating control.
■ Remove the role or transaction causing the conflict.
a. Mitigating Controls (MC). This is action taken to monitor activities when a business
condition requires personnel to have the opportunity to exploit operational weakness through
additional access to FPI’s financial information system.
BPOs are responsible for writing MCs to monitor a conflict. The MCs should:
3
8052.04
P8052.XX 3/19/2026
04/16/2025 PROPERTY OF US GOVERNMENT 55
■ Identify how the risk is specifically monitored.
■ Identify how often the risk is monitored.
■ Identify who or what tool is responsible for conducting the monitoring task.
■ List the potential violations the monitoring task should identify.
The ICCG reviews MCs for accuracy and compliance with current policies.
An approved MC is submitted to the GRC Administrator. This position is responsible for:
■ Maintaining approved MC documentation.
■ Inputting approved MC into the GRC tool.
■ Assigning users to MCs within the GRC tool.
■ Maintaining the BPO listings and monitoring listings within the GRC tool.
■ Notifying BPOs of any unmitigated SOD conflicts.
■ Generating SOD audits and general reports.
b. Annual Mitigating Controls Recertification. BPOs must review the MCs report for all
known controlled risks at least annually to maintain compliance with policy and consistency
within the FPI financial information system environment.
The GRC Administrator executes a SOD user report without mitigating risk. The BPO identifies
the MC to apply or which role to remove for each listed user account that has conflicts.
Changes to user accounts as the result of the recertification process are carried out by the SAP
User Administrator via instructions from the SAP Access Administrator help desk service ticket.
Changes to the GRC tool, as the result of the recertification process, are carried out by the SAP
Security Administrator.
History
PS 8052.04 dated 2026-03-19
Provenance
- Source
- bop.gov
- Retrieved
- 2026-09-20
- Edition
- bop-ps-2026-09-20
- Content hash
ff60113e6a0fcd297cac895ec03e2e30ae386e16a6280055ab412e265d8e7428
The link goes to the issuing authority’s own document — the one we read to produce this record. Where a source publishes whole titles rather than sections, your browser may need a moment to jump to the provision.
Unofficial copy of government-published law, reproduced from official sources with full provenance. Not an official publication; verify against official sources before relying on it in a filing. Records in the 'guidance' corpus, and only that corpus, are sub-regulatory (interpretive guidelines, survey procedures) and are not binding law. Validity bounds follow each jurisdiction's declared temporalBasis.