CompTIA Data+ (DA0-002)Data Governance, Quality and ControlsHard

To reduce the risk of fraud, a company requires that the employee who initiates a vendor payment record cannot be the same employee who approves that payment for processing. This control is an example of which governance principle?

  1. ALeast privilege
  2. BData minimization
  3. CRole escalation
  4. DSeparation of duties
Show answer & explanation

Correct answer: D. Separation of duties

Separation of duties requires that critical tasks, such as initiating and approving a transaction, be divided among different individuals to prevent a single person from committing and concealing fraud or error.

Why the other options are wrong

  • A. Least privilege limits each user's access to only what is needed, but does not specifically require splitting tasks between two people.
  • B. Data minimization limits the amount of data collected, unrelated to task division.
  • C. Role escalation is not a recognized governance control principle; it is a distractor term.

Separation of Duties (SoD)

A control principle that divides critical tasks, such as authorization, execution, and review, among multiple individuals to reduce the risk of fraud or error.

  • Prevents any single person from controlling an entire process
  • Commonly applied to financial transactions and approvals
  • Complements least privilege but focuses on task division, not access scope

Memory trick: No one person should both write the check and sign it.

More Data Governance, Quality and Controls questions