Exception & SoD Responsibility Matrix
Fixes the ambiguity over who requests, who assesses risk, who approves and who monitors, which is where exception processes usually stall.
Available soon
- Format
- Excel
- Size
- 67 KB
- Length
- 11 sheets
- Version
- 1.1
- Updated
What's inside
- Instructions
- Responsibility Matrix
- Role Holders
- Role Combinations
- Combined Roles Check
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Read the Responsibility Matrix. Each row is one activity, with the rule in the Standard it comes from. R = does the work; A = accountable, signs it off, exactly one per activity; C = consulted before it is done; I = informed after. A/R means the accountable role also does the work. |
| 2 | Adjust the letters to how your organisation works, using the drop-down in each yellow cell. Keep exactly one A (or A/R) and at least one R per row: the Check column says OK only when both hold. |
| 3 | Keep the approval rows (EX-A05 to EX-A08) as they are unless your approved Standard changes the bands. They follow the approvers and decision times in the Exception Risk Scoring & Expiry Model. |
| 4 | On Role Holders, name the post that holds each role and its deputy. A deputy may act for the role only as set out on that sheet; approval authority is never delegated downwards. |
| 5 | If one person holds several roles, list them on Combined Roles Check and mark each role they hold. The Result column shows whether any combination is never acceptable, or needs the safeguard on the Role Combinations sheet. |
| 6 | Resolve every Never acceptable combination before approving this matrix, by moving a role to someone else or to an external reviewer. Record the safeguard you use for each Acceptable with safeguard combination. |
| 7 | Review the matrix with the conflict matrix (annually, and after any restructure or new core system) and whenever a role holder changes. |
| 8 | Delete the EXAMPLE rows on Combined Roles Check before the matrix is approved. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Tailoring — small organisation: the managing director is often executive management and risk owner, and the IT manager is control owner, information security and service desk. That is workable with the safeguards on the Role Combinations sheet. The one thing that must be bought in is an independent reviewer: an external adviser or your auditor, once a year.
Tailoring — regulated entity (NIS2, DORA): keep the independent reviewer separate from information security and from executive management; DORA expects the control function for ICT risk to be independent and separate from internal audit. Name the management body as the Critical approver.
Tailoring — IT run by a service provider: the provider's desk usually does the IT service desk work, including the conflict check before granting access (SD-A02). Put that duty and the emergency-access records into the service agreement. Accountability (the A) stays with people in your organisation.
Delegation: a deputy may act for a role while its holder is absent, at the same or a higher level of authority. Nobody may approve an exception above the authority the Standard gives their role, and a deputy is bound by the same combination rules as the person they stand in for.
Responsibility Matrix
R = responsible (does it) · A = accountable (exactly one per activity) · C = consulted · I = informed · A/R = accountable and does it. Yellow cells are yours to adjust.
| Ref | Process | Activity | Rule | Requester | Risk owner | Control owner | Information security | Executive management | Independent reviewer | IT service desk | Output, evidence or note | A count | R count | Check |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EX-A01 | Exception | Raise an exception request: requirement not met, reason, risk, compensating controls, remediation plan and end date | EX-01, EX-03 | A/R | C | C | I | Completed Security Exception Request & Approval Form, before the requirement is breached where possible | 1 | 1 | OK | |||
| EX-A02 | Exception | Check the request is complete, in scope and not something that may never be excepted | EX-02, EX-03 | I | A/R | Request accepted for assessment, or returned with reasons | 1 | 1 | OK | |||||
| EX-A03 | Exception | Assess the risk: score impact and likelihood, and set the band | EX-04 | C | C | C | A/R | Scored request, using the Exception Risk Scoring & Expiry Model. The requester and risk owner may comment on the score but not set it | 1 | 1 | OK | |||
| EX-A04 | Exception | Confirm the compensating control is in place and has been tested | EX-07 | R | A | C | Test evidence. A planned control does not lower the score | 1 | 1 | OK | ||||
| EX-A05 | Exception | Approve or refuse a Low exception (score 1–3): control owner | EX-05 | I | I | A/R | C | Decided within 5 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form | 1 | 1 | OK | |||
| EX-A06 | Exception | Approve or refuse a Medium exception (score 4–6): head of Information Security | EX-05 | I | C | C | A/R | Decided within 10 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form | 1 | 1 | OK | |||
| EX-A07 | Exception | Approve or refuse a High exception (score 8–9): head of Information Security and the accountable executive (risk owner) | EX-05 | I | A | C | R | I | Decided within 10 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form. Both sign; the risk owner is accountable for accepting the risk | 1 | 1 | OK | ||
| EX-A08 | Exception | Approve or refuse a Critical exception (score 12–16): the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management | EX-05 | I | R | C | R | A | Decided within 5 working days from a complete request; signed approval recorded on the Security Exception Request & Approval Form. The risk owner presents the case; information security presents the assessment | 1 | 2 | OK | ||
| EX-A09 | Exception | Record the decision in the register, with an expiry no later than the band's maximum | EX-06, EX-11 | I | I | A/R | Row in the Security Exception Register, refused requests included | 1 | 1 | OK | ||||
| EX-A10 | Exception | Run the compensating control, and re-test it while the exception is open | EX-07 | A/R | C | I | Evidence the control is still in place, checked at each monthly review. Whoever runs it does not approve the exception | 1 | 1 | OK | ||||
| EX-A11 | Exception | Remind the requester and risk owner 30 days before expiry | EX-09 | I | I | I | A/R | Reminder sent and noted in the register | 1 | 1 | OK | |||
| EX-A12 | Exception | Request a renewal before expiry, with an updated risk assessment and a progress report | EX-08 | R | A | C | Renewal request; approved as for its band (EX-A05 to EX-A08) | 1 | 1 | OK | ||||
| EX-A13 | Exception | Refer a renewal beyond the band's limit to the next approval level up | EX-08 | I | C | A/R | I | The next level up decides. Above Critical: [[the full board, or its equivalent]] | 1 | 1 | OK | |||
| EX-A14 | Exception | Deal with an expired exception within 10 working days: remediate, renew or escalate | EX-10 | R | A | C | R | I | Expired High and Critical exceptions reported to their approver on the first working day after expiry | 1 | 2 | OK | ||
| EX-A15 | Exception | Close the exception, checking and filing the closure evidence | EX-13 | R | I | C | A | Closed date and evidence reference in the register | 1 | 1 | OK | |||
| EX-A16 | Exception | Review the whole register (monthly) | EX-11 | I | C | A/R | Review record on the register's Monthly Review sheet | 1 | 1 | OK | ||||
| EX-A17 | Exception | Report exceptions to executive management (quarterly) | EX-12 | I | A/R | I | Report from the Exception Ageing & Expiry Dashboard: the headline measures, every High and Critical exception, and chronic exceptions by name | 1 | 1 | OK | ||||
| EX-A18 | Exception | Decide on chronic exceptions: fund the fix or formally carry the risk | EX-08, EX-12 | C | C | A/R | Decision minuted | 1 | 1 | OK | ||||
| EX-A19 | Exception | Check a sample of decisions, renewals and closures against the Standard | EX-11, EX-12 | C | I | A/R | Independent review findings | 1 | 1 | OK | ||||
| SD-A01 | SoD | Maintain the conflict matrix and rate each conflict (annually, and after any restructure or new core system) | SD-02 | C | C | A/R | I | C | Segregation of Duties Conflict Matrix, reviewed and dated | 1 | 1 | OK | ||
| SD-A02 | SoD | Check the conflict matrix before granting or changing a role or access right | SD-03 | I | C | C | A/R | Conflict check recorded on the access request | 1 | 1 | OK | |||
| SD-A03 | SoD | Rate a newly found conflict High, Medium or Low and add it to the matrix | SD-02 | C | C | A/R | Matrix entry; rating as the Security Exception & Waiver Standard defines it | 1 | 1 | OK | ||||
| SD-A04 | SoD | Record a conflict that cannot be separated as an exception, with a compensating control performed by someone without the conflict | SD-04 | R | C | C | A | Row in the Security Exception Register; approved as for its band (EX-A05 to EX-A08). Method in the SoD Conflict Review & Compensating Control Procedure | 1 | 1 | OK | |||
| SD-A05 | SoD | Perform the compensating control for an accepted conflict (for example, independent review of the person's activity) | SD-04 | A | R | I | Evidence of each review. Never performed by the person with the conflict, nor by whoever approved the exception | 1 | 1 | OK | ||||
| SD-A06 | SoD | Review each accepted conflict and its evidence: High quarterly, Medium every six months, Low at the annual matrix review | SD-05 | C | C | A/R | Review record. A High conflict with no control reviewed in the last quarter is reported as unmitigated | 1 | 1 | OK | ||||
| SD-A07 | SoD | Review each use of emergency or privileged access after the event | SD-06 | I | A | R | C | Review within [[2 working days]], by someone other than the user; administrators never review their own logs | 1 | 1 | OK | |||
| SD-A08 | SoD | Keep the records of conflict checks, accepted conflicts, compensating control evidence, reviews and emergency access | SD-07 | A/R | R | Records an independent reviewer can follow from detection to latest review | 1 | 2 | OK | |||||
| SD-A09 | SoD | Check independently that conflicts are detected, decided and reviewed as the Standard requires | SD-01, SD-05 | C | I | A/R | Independent review findings | 1 | 1 | OK |
Role Holders
Name who holds each role and who deputises. The counts show how much of the matrix each role carries.
| Role | What the role does here | Held by (post) | Deputy (post) | What the deputy may do | Accountable for (A) | Responsible for (R) |
|---|---|---|---|---|---|---|
| Requester | Raises the request, runs the compensating controls, delivers the remediation plan, and asks for renewal or closure in time. | [[e.g. system owner, project lead]] | [[Deputy post]] | May raise or renew a request on the holder's behalf. | 2 | 7 |
| Risk owner | Accepts the residual risk for the affected service and answers for it until closure. Co-approves High exceptions and presents Critical ones. | [[the accountable business executive for the affected service]] | [[Deputy post]] | Another executive of the same or higher level; never someone who reports to the requester. | 4 | 1 |
| Control owner | Owns the requirement that is not met and confirms the compensating control works. Approves Low exceptions. | [[e.g. IT Operations Manager]] | [[Deputy post]] | May approve Low exceptions if at the same level of authority and not the requester. | 2 | 2 |
| Information security | Keeps the Standard, the register and the conflict matrix; assesses every request; approves Medium and co-approves High exceptions; runs the monthly review and quarterly report. | [[e.g. Head of Information Security]] | [[Deputy post]] | A named deputy may assess requests and run the monthly review. Medium and High approvals need someone of equal authority, never a member of the requester's team. | 15 | 15 |
| Executive management | Approves Critical exceptions where the organisation has no board; otherwise takes them to the board or its equivalent, as the approval bands set out; approves escalated renewals, receives the quarterly report and decides on chronic exceptions. | [[e.g. Executive Committee or its risk committee]] | [[Deputy post]] | Acts as a body; a quorum under its terms of reference, excluding anyone with an interest in the request. | 2 | 1 |
| Independent reviewer | Checks that exceptions and conflicts are decided and recorded as the Standard requires, and reviews emergency and privileged access. | [[e.g. internal audit, or an external reviewer for small organisations]] | [[Deputy post]] | Another reviewer independent of the process, internal or external. | 2 | 3 |
| IT service desk | Grants and changes access after checking the conflict matrix, and keeps the emergency-access log. | [[e.g. IT service desk, or the managed service provider's desk]] | [[Deputy post]] | Any trained desk member, except for access to their own accounts. | 1 | 2 |
Role Combinations
The small-organisation variant: which duties and roles one person may hold together. The first rows apply in every organisation.
| Combination | Verdict | Why | Safeguard, or what to do instead |
|---|---|---|---|
| Deciding an exception you requested | Never acceptable | The approval is the only independent look at the request. | The decision passes to the next level up (EX-05). |
| Deciding an exception to a control you operate yourself | Never acceptable | You would be judging your own shortfall. | The decision passes to the next level up (EX-05). |
| Approving an exception whose compensating control you perform | Never acceptable | The exception is only acceptable because the control works; you would be vouching for your own work. | Someone else performs the control, or the decision passes to the next level up (EX-05). |
| Co-approving a High exception as its risk owner | Acceptable | Expected: the Standard makes the risk owner co-approve High exceptions, because they carry the risk. | Not if the risk owner also requested it or performs its compensating control (rows above). |
| Reviewing a conflict you hold, or performing its compensating control | Never acceptable | The compensating control exists because nobody else sees your work. | Someone without the conflict reviews it (SD-04, SD-05). |
| Granting access or a role to yourself | Never acceptable | The conflict check before granting (SD-03) needs a second person. | Another administrator, or the service desk, grants it. |
| Reviewing your own use of emergency or privileged access | Never acceptable | Administrators do not review the logs of their own activity (SD-06). | The reviewer named in SD-A07. |
| Requester + Risk owner | Acceptable with safeguard | Risk owners often ask for exceptions on their own service. | For a High exception, which the risk owner co-approves, executive management decides instead. |
| Requester + Control owner | Acceptable with safeguard | Common where the owner of a requirement also runs the system. | For a Low exception, which the control owner approves, the Medium approver decides instead. |
| Requester + Information security | Acceptable with safeguard | Security staff raise exceptions for their own tools. | Another person checks the risk assessment, and the decision passes to the next level up. |
| Requester + Executive management | Acceptable with safeguard | Executives request exceptions for their own areas. | For a Critical exception, they declare the interest and take no part in the decision. |
| Requester + Independent reviewer | Acceptable with safeguard | An internal reviewer may need exceptions for their own systems. | Exceptions they raised are sampled by another reviewer. |
| Requester + IT service desk | Acceptable | The service desk raises exceptions for the tools it runs. | — |
| Risk owner + Control owner | Acceptable | In small organisations the person accountable for a service often owns its requirements too. | Low approvals then come from the risk owner's own area; keep the Medium and higher bands unchanged. |
| Risk owner + Information security | Acceptable with safeguard | The risk assessment (EX-04) is meant to be independent of the business that wants the exception. | For a High exception, which needs both signatures, executive management signs in place of the second. |
| Risk owner + Executive management | Acceptable | Risk owners are usually executives. | For a Critical exception on their own service, they present it and do not decide it. |
| Risk owner + Independent reviewer | Never acceptable | The reviewer would be checking risk decisions they made themselves. | Use another reviewer, or an external one. |
| Risk owner + IT service desk | Acceptable | Unusual, but no duty in the process conflicts. | — |
| Control owner + Information security | Acceptable with safeguard | Typical where the IT manager also covers security: they would assess exceptions to requirements they own. | The independent reviewer samples these exceptions, and approvals for them pass to the next level up. |
| Control owner + Executive management | Acceptable | Executives often own policy requirements. | — |
| Control owner + Independent reviewer | Never acceptable | The reviewer would be checking exceptions to requirements they own. | Use another reviewer, or an external one. |
| Control owner + IT service desk | Acceptable with safeguard | The person who grants access also owns the access requirements. | Emergency and privileged access is reviewed by someone else (SD-A07). |
| Information security + Executive management | Acceptable | A head of security may sit on the executive committee. | For a Critical exception, the rest of the committee decides on information security's assessment. |
| Information security + Independent reviewer | Never acceptable | The reviewer would be checking the register and matrix they keep. | Use internal audit, or an external reviewer once a year. |
| Information security + IT service desk | Acceptable with safeguard | In small IT teams one person grants access and checks conflicts. | Every grant they make to an administrator, and all emergency access, is reviewed by someone else (SD-06). |
| Executive management + Independent reviewer | Never acceptable | The reviewer would be checking decisions they took. | Use internal audit reporting to the board, or an external reviewer. |
| Executive management + IT service desk | Acceptable | Possible in very small organisations. | — |
| Independent reviewer + IT service desk | Never acceptable | The reviewer would be checking access they granted, including emergency access. | Use another reviewer, or an external one. |
Combined Roles Check
One row per person who holds more than one role. Mark each role they hold; the Result shows whether the combination is allowed.
| Example | Person or post | Requester | Risk owner | Control owner | Information security | Executive management | Independent reviewer | IT service desk | Roles held | Never-acceptable pairs | Pairs needing a safeguard | Result | First pair to resolve |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | Managing Director | Yes | Yes | 2 | 0 | 0 | OK | ||||||
| EXAMPLE | IT Manager | Yes | Yes | Yes | 3 | 0 | 3 | Allowed with safeguard | Control owner + Information security (safeguard) | ||||
| EXAMPLE | Finance Director | Yes | Yes | Yes | 3 | 2 | 0 | Conflict — move a role | Risk owner + Independent reviewer (never) | ||||
| EXAMPLE | External adviser (annual review) | Yes | 1 | 0 | 0 | OK |
Lists
| RACI | YesNo | Verdict |
|---|---|---|
| R | Yes | Never acceptable |
| A | No | Acceptable with safeguard |
| A/R | Acceptable |
C
I
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| R — Responsible | Does the work. There may be more than one. |
| A — Accountable | Owns the outcome and signs it off. Exactly one per activity, so there is never doubt about who decides. |
| C — Consulted | Asked for input before the activity is done. |
| I — Informed | Told of the outcome after the activity is done. |
| A/R | Accountable and also does the work. Counts as both an A and an R in the Check column. |
| Requester | Raises the request, runs the compensating controls, delivers the remediation plan, and asks for renewal or closure in time. [[e.g. system owner, project lead]] |
| Risk owner | Accepts the residual risk for the affected service and answers for it until closure. Co-approves High exceptions and presents Critical ones. [[the accountable business executive for the affected service]] |
| Control owner | Owns the requirement that is not met and confirms the compensating control works. Approves Low exceptions. [[e.g. IT Operations Manager]] |
| Information security | Keeps the Standard, the register and the conflict matrix; assesses every request; approves Medium and co-approves High exceptions; runs the monthly review and quarterly report. [[e.g. Head of Information Security]] |
| Executive management | Approves Critical exceptions where the organisation has no board; otherwise takes them to the board or its equivalent, as the approval bands set out; approves escalated renewals, receives the quarterly report and decides on chronic exceptions. [[e.g. Executive Committee or its risk committee]] |
| Independent reviewer | Checks that exceptions and conflicts are decided and recorded as the Standard requires, and reviews emergency and privileged access. [[e.g. internal audit, or an external reviewer for small organisations]] |
| IT service desk | Grants and changes access after checking the conflict matrix, and keeps the emergency-access log. [[e.g. IT service desk, or the managed service provider's desk]] |
| Security exception | An approved, time-limited decision to operate without meeting a named requirement of a security policy or standard, with a named risk owner and a compensating control. |
| Band | The level an exception's score (impact × likelihood, 1–16) falls in, which sets its approver and decision time: Low 1–3 — control owner, within 5 working days from a complete request; Medium 4–6 — head of Information Security, within 10 working days from a complete request; High 8–9 — head of Information Security and the accountable executive (risk owner), within 10 working days from a complete request; Critical 12–16 — the board, or a board risk committee it has delegated this to; in a two-tier structure, the management board; where there is no board, such as in an owner-managed company, executive management, within 5 working days from a complete request. |
| Segregation of duties (SoD) | Splitting duties so that no one person can make, approve and conceal an unauthorised change, payment or access grant (SD-01). |
| Conflict | A combination of duties or access rights one person should not hold together. Rated: High — one person could make and hide an unauthorised change, payment or access grant with no second person seeing it. Medium — one person could make an unauthorised change that another control would probably, but not certainly, detect later. Low — the combination is undesirable but the damage is small or detected quickly by routine checks. |
| Compensating control | A measure that reduces the risk while a requirement is not met or a conflict cannot be separated, performed by someone without the conflict. |
| Emergency (break-glass) access | Privileged access granted outside the normal process for an urgent need, for a stated purpose and a limited time, and reviewed after use (SD-06). |
| Deputy | The person who acts for a role holder while they are absent, with no more authority than the role holds. |
| Never acceptable | A combination that defeats the purpose of the control. Move one of the roles to someone else. |
| Acceptable with safeguard | A combination that is workable if the safeguard shown is applied and recorded. |
| EXAMPLE row | A worked example on Combined Roles Check. Delete before approval. |
| EX-05, SD-04 … | Rule numbers in the Security Exception & Waiver Standard. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 5.3 — Organizational roles, responsibilities and authorities | Responsibility Matrix and Role Holders |
| ISO/IEC 27001:2022 | Annex A 5.2 — Information security roles and responsibilities | Responsibility Matrix: one accountable role per activity |
| ISO/IEC 27001:2022 | Annex A 5.3 — Segregation of duties | SoD activities; Role Combinations; Combined Roles Check |
| NIST CSF 2.0 | GV.RR-02 — “Roles, responsibilities, and authorities related to cybersecurity risk management are established, communicated, understood, and enforced” | Responsibility Matrix and Role Holders |
| DORA — Regulation (EU) 2022/2554 | Article 6(4) — a control function for ICT risk, independent enough to avoid conflicts of interest, and segregation of ICT risk management, control and internal audit functions | Independent reviewer kept separate from the roles it checks |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 2(2)(g) — ICT security policies specify segregation-of-duties arrangements to avoid conflicts of interest | Role Combinations and Combined Roles Check |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774