Skip to content
Institute For Oil & Gas Training
OGI-1215 New

Segregation of Duties in Finance & ERP Systems Training Course

Duration
5 days
CPD hours
15
Language
English
Next date
12 Oct 2026

We use your details only to answer this enquiry. See our privacy policy.

Overview

The Segregation of Duties Training Course from Institute For Oil & Gas Training equips finance, internal control, ERP, audit, compliance and risk professionals to design, assess and strengthen Segregation of Duties across complex oil and gas organisations. The course addresses the control risks created when incompatible duties are assigned to the same individual across finance processes, procurement, joint ventures, revenue, payroll, treasury, inventory and enterprise resource planning systems.

Oil and gas organisations operate through interconnected financial processes, multiple approval levels, shared services, joint venture arrangements and sophisticated ERP environments. These structures create a strong requirement for clearly defined responsibility boundaries. Effective Segregation of Duties ensures that authorisation versus recording versus custody are appropriately separated, reducing the risk of unauthorised transactions, inappropriate access, financial misstatement, duplicate processing and control breakdowns.

The course provides a practical framework for identifying incompatible duties and analysing access risks within ERP environments. Participants examine how a SoD conflict matrix supports systematic control assessment, how role based access control establishes appropriate user permissions, and how user access review processes identify excessive or inappropriate access. The programme also addresses privileged access, compensating controls, ERP role redesign, and access provisioning and deprovisioning.

Institute For Oil & Gas Training positions Segregation of Duties within the wider finance and enterprise control environment. Participants work with practical scenarios involving procure to pay, order to cash, record to report, treasury, fixed assets, inventory, payroll and master data. The course connects business responsibilities with system permissions so that organisations can establish controls that operate effectively across both manual processes and ERP platforms.

The programme also examines the relationship between SoD design and operational accountability. A well-designed control environment distinguishes transaction initiation, approval, recording, reconciliation, asset custody and review responsibilities. This approach provides finance and control teams with a structured basis for determining whether an individual has excessive authority within a business process.

ERP environments require particular attention because a single system role can provide access to multiple functions that would remain separated in a manual environment. Participants therefore assess how role combinations create conflicts, how access risks are prioritised, and how ERP role redesign supports a sustainable control structure.

The course also addresses the practical management of exceptions. Not every incompatible access combination can be eliminated immediately, particularly in smaller finance teams, specialist operations or emergency response environments. Participants learn how compensating controls support risk management when complete separation is operationally impractical. The focus remains on documented ownership, monitoring, review and evidence.

Institute For Oil & Gas Training delivers this programme for organisations seeking stronger financial governance, more disciplined ERP access management and clearer accountability across oil and gas operations. The approach combines control principles with practical implementation techniques, enabling participants to translate Segregation of Duties requirements into workable finance and system controls.

Objectives

  • Understand the principles and business purpose of Segregation of Duties across oil and gas finance environments

  • Identify incompatible duties across financial, operational and ERP processes

  • Distinguish authorisation versus recording versus custody responsibilities

  • Develop and apply an effective SoD conflict matrix

  • Assess finance process risks created by overlapping responsibilities

  • Evaluate ERP roles against defined job responsibilities

  • Apply role based access control principles to finance and operational systems

  • Conduct structured user access review activities

  • Identify excessive, inappropriate and unnecessary system privileges

  • Evaluate privileged access and its associated control requirements

  • Design practical access provisioning and deprovisioning controls

  • Determine when ERP role redesign is required

  • Develop appropriate compensating controls for unavoidable conflicts

  • Strengthen evidence, ownership and accountability within access control processes

  • Improve collaboration between finance, IT, internal audit, compliance and business process owners

  • Support stronger financial governance through sustainable access management

  • Establish repeatable approaches for monitoring and resolving SoD conflicts

Training methodology

Institute For Oil & Gas Training uses a practical corporate delivery model focused on real finance and ERP control situations. The programme combines instructor-led technical discussion with case studies, process mapping, access analysis, control design exercises and group-based problem solving.

Participants analyse realistic oil and gas scenarios involving incompatible duties across finance and operational workflows. These scenarios demonstrate how conflicts emerge when users receive overlapping transaction creation, approval, recording, master data and payment responsibilities.

Case studies focus on finance processes such as procure to pay, order to cash, record to report, treasury, payroll, inventory and fixed assets. Participants assess where responsibility separation is required and identify the system permissions that create control exposure.

ERP simulations provide a practical environment for reviewing user roles and identifying access combinations that create SoD conflicts. Participants work with role structures, permission combinations and approval workflows to understand the relationship between business responsibilities and system access.

Group exercises focus on developing a SoD conflict matrix. Participants identify conflicting activities, assess the significance of each conflict, establish appropriate control ownership and determine whether role redesign or compensating controls provide the appropriate response.

User access review exercises demonstrate how organisations assess existing user permissions against job responsibilities. Participants examine access provisioning and deprovisioning, inactive users, transferred employees, temporary access and privileged access.

Real-world scenarios also address organisational changes. Participants consider how employee transfers, restructures, new ERP implementations, acquisitions, outsourcing arrangements and changes in finance responsibilities affect Segregation of Duties.

The methodology emphasises evidence-based decision making. Participants learn to distinguish between theoretical access conflicts and genuine business control risks by considering process ownership, transaction authority, system functionality and existing monitoring controls.

Organisational impact

Effective Segregation of Duties strengthens the control environment by ensuring critical responsibilities are distributed across appropriate individuals and functions. Sponsoring organisations gain a structured approach for identifying control weaknesses before they develop into larger financial, operational or compliance issues.

The course supports stronger finance process integrity by separating transaction initiation, approval, recording, reconciliation and custody responsibilities. This reduces excessive concentration of authority and strengthens accountability across core financial workflows.

ERP governance also benefits from clearer role structures. Organisations gain practical methods for identifying conflicting permissions and determining when ERP role redesign is required. This supports cleaner access structures and improves alignment between employee responsibilities and system privileges.

A structured SoD conflict matrix provides management with a consistent method for documenting conflicts, assigning ownership and tracking remediation. It also supports more disciplined communication between finance, IT, internal audit, compliance and business process owners.

User access review becomes more systematic when access is assessed against actual job responsibilities rather than simply reviewing user accounts in isolation. This strengthens the organisation's ability to identify unnecessary access, transferred-user permissions, inactive accounts and inappropriate combinations of system privileges.

Access provisioning and deprovisioning controls also become more robust. Clear processes ensure that new access follows defined approval requirements and that access is removed or adjusted when employees leave, transfer roles or change responsibilities.

The course strengthens privileged access governance by focusing attention on accounts with elevated system authority. Appropriate monitoring, ownership and review processes help organisations maintain stronger control over high-risk access.

Compensating controls provide a structured response where complete separation of duties is not operationally practical. Organisations can establish alternative review, monitoring and approval mechanisms while maintaining documented responsibility for the underlying risk.

The programme also improves audit readiness through clearer control ownership and stronger documentation. Finance and control teams gain a common framework for demonstrating how access risks are identified, assessed, remediated and monitored.

For oil and gas organisations operating across multiple assets, entities, jurisdictions and joint venture structures, consistent control principles improve governance across different operating environments. The resulting control framework supports greater consistency between business processes and ERP access structures.

Personal impact

Participants develop a stronger understanding of how Segregation of Duties operates across finance, technology and operational environments. They gain the ability to identify control conflicts and explain their business significance to stakeholders.

Finance professionals strengthen their ability to evaluate whether system access supports or undermines financial control objectives. They learn to connect financial responsibilities with ERP permissions and approval structures.

ERP and IT professionals gain practical skills for translating business control requirements into system roles. They develop greater confidence in identifying inappropriate access combinations and supporting ERP role redesign.

Internal auditors and compliance professionals strengthen their ability to assess SoD frameworks, review access controls and challenge weaknesses in control ownership and documentation.

Risk professionals develop a clearer understanding of how access conflicts contribute to financial and operational exposure. They gain structured approaches for evaluating conflicts and determining appropriate control responses.

Managers gain stronger oversight capability. They can assess whether responsibilities are appropriately distributed, challenge excessive access and support decisions concerning role changes and compensating controls.

Participants also develop practical skills in user access review, privileged access assessment and access provisioning and deprovisioning. These capabilities support stronger professional performance across finance transformation, ERP governance, internal control and assurance functions.

The programme improves cross-functional communication because participants learn a common language for discussing access conflicts, control ownership, role design and remediation. This is particularly valuable where finance, IT and operational teams share responsibility for ERP governance.

Who should attend

  • Finance Managers and Controllers — responsible for financial controls, transaction approvals and accounting governance.

  • Financial Accountants — involved in transaction processing, reconciliations and financial reporting controls.

  • Internal Auditors — responsible for assessing SoD effectiveness, access risks and control design.

  • Compliance Managers — responsible for monitoring control requirements and organisational compliance processes.

  • Risk Managers — responsible for identifying and evaluating operational and financial control exposure.

  • ERP Managers — responsible for system roles, permissions and finance application governance.

  • ERP Security Specialists — responsible for access architecture, permissions and privileged access.

  • IT Managers — responsible for technology controls supporting financial and operational systems.

  • Internal Control Professionals — responsible for designing, documenting and monitoring control frameworks.

  • Finance Transformation Managers — responsible for improving finance processes and ERP structures.

  • Process Owners — responsible for business workflows and control effectiveness.

  • Procurement Managers — responsible for purchasing, supplier approval and procure to pay controls.

  • Treasury Professionals — responsible for payment, banking and cash management activities.

  • Shared Services Managers — responsible for centralised transaction processing and access structures.

  • Senior Finance and Operations Managers — responsible for governance, accountability and control performance.

Course outline

This module establishes the principles of Segregation of Duties and explains how responsibility separation supports financial control across oil and gas organisations. Participants examine the distinction between authorisation versus recording versus custody and identify incompatible duties within common finance workflows.

  1. COSO Internal Control Framework

    • Provides a recognised framework for designing and evaluating internal control systems.

    • Supports clear assignment of responsibilities and control activities.

    • Provides a foundation for assessing whether controls address identified risks.

    • Helps organisations structure monitoring and accountability around internal controls.

    Learning Outcomes

    • Explain the core principles of Segregation of Duties

    • Identify incompatible duties within finance processes

    • Distinguish transaction authorisation, recording, custody and review

    • Recognise common SoD weaknesses in oil and gas environments

    • Define appropriate control ownership

    • Connect responsibility separation with financial control objectives

This module focuses on identifying, documenting and prioritising conflicts through a structured SoD conflict matrix. Participants assess process responsibilities and determine appropriate responses to identified conflicts.

  1. ISO 31000 Risk Management

    • Provides principles and guidance for structured risk management.

    • Supports consistent identification and assessment of risks.

    • Encourages risk-based decision making and defined accountability.

    • Provides a recognised basis for evaluating control responses.

    Learning Outcomes

    • Build a practical SoD conflict matrix

    • Identify conflicts across finance and operational workflows

    • Assess the significance of identified conflicts

    • Assign ownership for conflict resolution

    • Prioritise remediation activities

    • Document control decisions consistently

This module addresses the relationship between business responsibilities and ERP access. Participants examine role based access control, privileged access and the process of aligning system permissions with approved job responsibilities.

  1. ISO IEC 27001 Information Security

    • Establishes requirements for an information security management system.

    • Supports controlled access to information and systems.

    • Provides recognised principles for managing access responsibilities.

    • Supports governance of privileged and authorised system access.

    Learning Outcomes

    • Assess ERP access against business responsibilities

    • Apply role based access control principles

    • Identify excessive and conflicting permissions

    • Evaluate privileged access risks

    • Determine when ERP role redesign is necessary

    • Strengthen alignment between job responsibilities and system roles

This module examines the complete user access lifecycle, from initial provisioning through changes in responsibility and final deprovisioning. Participants develop structured approaches for reviewing access and maintaining accurate permissions.

  1. COBIT Governance Framework

    • Provides recognised governance and management practices for enterprise information and technology.

    • Supports alignment between business requirements and technology controls.

    • Provides principles for governance, accountability and control oversight.

    • Supports structured management of technology-related risks.

    Learning Outcomes

    • Conduct structured user access review activities

    • Evaluate access against current job responsibilities

    • Strengthen access provisioning and deprovisioning

    • Identify stale, unnecessary or inappropriate access

    • Establish clear review ownership

    • Improve evidence and documentation for access decisions

This module focuses on resolving identified SoD conflicts and establishing sustainable governance arrangements. Participants assess ERP role redesign, compensating controls, privileged access monitoring and ongoing control review.

  1. NIST Cybersecurity Framework

    • Provides a recognised approach to managing cybersecurity risk.

    • Supports governance, identification, protection, detection, response and recovery activities.

    • Provides useful principles for managing access-related risks.

    • Supports structured risk governance and continuous improvement.

    Learning Outcomes

    • Develop practical responses to identified SoD conflicts

    • Determine when role redesign is preferable to compensating controls

    • Design appropriate compensating controls

    • Strengthen privileged access oversight

    • Establish sustainable SoD monitoring practices

    • Improve governance reporting and control ownership

    • Integrate finance and ERP access management responsibilities

Certificate

Attendees receive a Certificate of Completion from Institute For Oil & Gas Training upon successfully finishing the course.

The certificate confirms participation and completion of the programme. Attendees are required to meet the course attendance requirement and complete the scheduled programme activities.

Course dates

  • Europe

    Middle East

    Asia

    Africa

    North America

    Online

    Fee: £3,700

  • Europe

    Middle East

    Asia

    Africa

    North America

    Online

    Fee: £3,700

  • Europe

    Middle East

    Asia

    Africa

    North America

    Online

    Fee: £3,700

  • Europe

    Middle East

    Asia

    Africa

    North America

    Online

    Fee: £3,700

Fees include tuition, course materials and refreshments. Need different dates or a different city? Ask about your preferred date.

Frequently asked questions

What is the focus of the Segregation of Duties Training Course?

The course focuses on identifying incompatible duties, analysing ERP access conflicts, developing a SoD conflict matrix and strengthening finance and system controls.

Who is the course designed for?

The programme is designed for finance, internal audit, compliance, risk, ERP, IT, internal control, procurement, treasury and senior management professionals.

Does the course cover ERP access management?

Yes. The course covers role based access control, privileged access, user access review, ERP role redesign and access provisioning and deprovisioning.

How are SoD conflicts addressed when duties cannot be fully separated?

Participants examine compensating controls, independent reviews, additional approvals, monitoring and documented exception management as practical control responses.

What certificate is provided after completing the course?

Attendees receive a Certificate of Completion from Institute For Oil & Gas Training upon finishing the course and meeting the attendance requirement.

Next: 12 Oct 2026

4 dates available

Register Now

Related training courses

Get the training calendar in your inbox

New courses, dates and industry insight. No more than twice a month.