⚠ CONFIDENTIAL & PROPRIETARY — SAJEED MULLAJI GOVERNANCE FRAMEWORK (SAMPLE ARTIFACT) — FOR ILLUSTRATIVE PURPOSES ONLY
sajeedmullaji.com · sajeed@sajeedmullaji.com
Client: Apex Global Distribution Ltd.
Document Ref: APEX-SOD-2026-Q3
Version: v2.1 Final — Approved
Date: 17 August 2026
Segregation of Duties (SoD) Conflict Resolution Matrix
D365 Finance & Operations — Post-Audit Remediation Report · ITGC Control Area: Access to Programs & Data
Microsoft Dynamics 365 F&O
SOX Section 404 · COSO · ISAE 3402
Sajeed Mullaji — D365 Security Architect
K. Patel — IT Audit Manager
Production · Cloud · 10.0.47
6
Conflicts Identified
6
Conflicts Remediated
3
Critical Risk
2
High Risk
1
Medium Risk
100%
Closure Rate
Conflict ID Business Process Risk Rating Toxic Combination Description Standard Role (AOT) Duty 1 (AOT) Duty 2 (AOT) Conflict Type Remediation Action Custom Duty Created Privilege Removed Evidence Reference Status Remediation Date Sign-off
SOD-AP-001 Accounts Payable Critical User can create and edit Vendor Master bank account and independently generate Vendor Payment against it — enabling ghost vendor fraud VendManager VendTableMaintain VendPaymMaintain Master Data vs. Transaction Cloned VendManager. Stripped Vendor Master access. Isolated Vendor Master maintenance to centralised MDM team only APEX_VendManager_Custom VendTableMaintain SecurityUserRole table export · APEX-EV-001 Closed 08-Oct-2025 K. Patel
SOD-PR-042 Procurement Critical User can create a Purchase Order and independently approve their own Purchase Order — bypassing authorisation controls PurchAgent PurchOrderMaintain PurchOrderApprove Execution vs. Authorisation Cloned PurchAgent. Stripped native approval privilege. Enforced approval strictly via D365 Workflow hierarchy with independent approver APEX_PurchAgent_NoApprove PurchOrderApprove Security Configuration UI export · APEX-EV-042 Closed 14-Oct-2025 K. Patel
SOD-GL-015 General Ledger High User can create manual General Ledger journals and post the same journals without secondary review — enabling backdated financial manipulation LedgerAccountant LedgerJournalMaintain LedgerJournalPost Execution vs. Authorisation Cloned standard Accountant role. Removed direct posting privilege. Configured GL workflow requiring independent posting review before finalisation APEX_LedgerJournalMaintain_NoPost LedgerJournalPost Data Management role export · APEX-EV-015 Closed 02-Nov-2025 K. Patel
SOD-AR-022 Accounts Receivable Medium User can maintain Customer Master data and post Free Text Invoices — enabling AR aging manipulation and fictitious revenue recording CustClerk CustTableMaintain CustFreeTextInvoicePost Master Data vs. Transaction Removed CustTableMaintain from AR transactional clerks. Re-assigned Customer Master maintenance exclusively to Master Data Stewards role N/A — Standard role split applied CustTableMaintain SecurityUserRole table export · APEX-EV-022 Closed 15-Nov-2025 K. Patel
SOD-FA-009 Fixed Assets High User can manually acquire a Fixed Asset and independently adjust depreciation parameters — enabling asset valuation manipulation AssetAccountant AssetTableMaintain AssetJournalMaintain Asset Control vs. Valuation Created two custom FA roles separating initial asset capitalisation from month-end depreciation posting. Assigned to separate individuals APEX_AssetDepreciation_Only AssetTableMaintain Effective access report vs AssetTable · APEX-EV-009 Closed 04-Dec-2025 K. Patel
SOD-IT-002 System Administration Critical 14 IT Support users held full System Administrator access — bypassing all application controls, SoD engine, and audit logging SystemAdministrator N/A — Full Access Role N/A — Full Access Role IT Privileged Access vs. Business Operations Revoked SystemAdministrator from 14 IT users. Created scoped L2 Support role. Implemented time-bound Firefighter process for elevated access requests APEX_IT_Support_ReadOnly SystemAdministrator SecurityUserRole count query — SysAdmin count reduced to 2 · APEX-EV-002 Closed 10-Jan-2026 K. Patel