nerdexam
Isaca

CRISC · Question #372

Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?

The correct answer is A. Segregation of duties. Segregation of duties is the most effective control to prevent fraudulent transactions by ensuring no single individual has complete control over a process.

Submitted by obi.ng· Apr 18, 2026Risk Response and Reporting

Question

Which of the following is the BEST control for a large organization to implement to effectively mitigate risk related to fraudulent transactions?

Options

  • ASegregation of duties
  • BMonetary approval limits
  • CClear roles and responsibilities
  • DPassword policies

How the community answered

(37 responses)
  • A
    92% (34)
  • C
    5% (2)
  • D
    3% (1)

Why each option

Segregation of duties is the most effective control to prevent fraudulent transactions by ensuring no single individual has complete control over a process.

ASegregation of dutiesCorrect

Segregation of duties prevents a single individual from being able to complete all critical steps in a transaction process, thereby significantly reducing the opportunity for a lone actor to perpetrate and conceal fraudulent activities. This control ensures that at least two individuals are required to authorize, record, and reconcile transactions, creating a system of checks and balances.

BMonetary approval limits

Monetary approval limits can mitigate the *size* of individual fraudulent transactions but do not prevent fraudulent transactions from occurring if an individual can still bypass other controls for smaller amounts.

CClear roles and responsibilities

Clear roles and responsibilities define who does what, but without segregation of duties, one person could still perform conflicting tasks that enable fraud.

DPassword policies

Password policies enhance system security against unauthorized access but do not directly mitigate internal fraud perpetuated by authorized users who exploit process weaknesses.

Concept tested: Fraud risk mitigation controls

Source: https://www.isaca.org/resources/isaca-journal/2014-volume-2/how-to-implement-segregation-of-duties-in-a-sap-environment

Topics

#Segregation of duties (SoD)#Fraud prevention#Internal controls#Risk mitigation

Community Discussion

No community discussion yet for this question.

Full CRISC Practice