Governance & Compliance · Data artifact

Separation of Duties Policy

Data artifactGovernance & ComplianceSafety, Security & Governancearc:SeparationOfDutiesPolicy

An organizational control policy requiring that no single individual can both develop and authorize deployment or modification of an AI system without independent approval.

Responsibility. Prevents any single individual from holding unchecked authority over AI system changes.

Also known as: Segregation of duties

constrainsconfiguresStage Promotion Controller: constrainsStage Promotion ControllerAuthorization Policy Decision Point: configuresAuthorization Policy Dec…
Direct neighbourhood (hover for relationship types)

Relationships

configures structural

constrains control

Classification

Quality attributes
Security (ISO/IEC 25010 | NIST AI RMF: secure and resilient)Transparency and accountability (NIST AI RMF: accountable and transparent)
Risks mitigated
Unchecked unilateral changes to production AI systems
Frameworks & regulations
NIST AI RMF: MANAGEISO/IEC 42001 §8 Operation (change control)

Sources

  1. Ch9.8: T. Nguyen, "Standards and Frameworks for AI Governance," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.8. ISBN: 9798244538229.