Latest
How Much AI Is Too Much in Writing? 83 Writers Drew the Same LinePost an AI Image and Unfriend MeShe Asked How to Publish Her Bedtime Story. They Called Her a Thief.The AI Hype Cycle: Why the Crash Is Coming, and Who’s Causing ItSix Claude Prompts That Get You Unstuck, and Why the Order MattersDogpiled Over AI Art at the Renaissance FaireClaude Opus 5.5: What the New Release Means for WritersTrump’s AI Force Is a Fire Department With No Fire CodeMonthly or Milestone: How Ghostwriting Gets BilledThe Hugging Face AI Agent Attack: An Operations ReadingWhat It Costs to Fix an AI-Written ManuscriptWhen Your Memoir Should Be a NovelWhat Belongs on a Copyright PageThe Clients Who Pay and VanishWhat an AI Detector Score on Your Manuscript Is WorthThe Quotation Marks That Get Authors SuedThe One-Hour Call Before I Quote Your BookWhen Your Own Memoir Sounds Like BraggingThe Work You Would Never Have StartedWhen a Client Thinks the Ghostwriter Used AIBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionBooks to Give a WriterResurrection as a Narrative StructureThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreBlack Tuesday: The Web Ring War Nobody Outside It NoticedThe Web Got Fenced: What AI Search Costs Small Sites
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

Documenting Roles, Not Just Rules: A NIST Project That Got Personal

This entry is part 49 of 53 in the series Technology
TL;DR: Most companies document policies. I documented roles: which person is responsible for which piece of which policy, and the procedure each role follows. The NIST engagement ran four to five months of interviews, C-suite down, department by department. It made the policies bulletproof, nobody could claim they didn’t know a task was theirs. It also revealed something uncomfortable: the CFO didn’t know what segregation of duties was, and once he learned, he opposed it.

A client hired me to build their NIST documentation, and I took an approach most policy projects skip. The standard deliverable in this world is a policies-and-procedures manual: here’s our access-control policy, here’s our change-management procedure, signed, dated, shelved. That’s what most companies still produce, and it’s why most policy manuals are furniture.

I documented roles. For every policy, the manual named which role was responsible for which piece of it, and gave each role its own procedure to follow. Not “checks shall be authorized and issued under appropriate controls” but this person authorizes, following this procedure; this different person issues, following that one. The policy stopped being an abstract statement about the company and became a set of specific obligations attached to specific chairs.

Four to five months of interviews

You can’t write role-level documentation from a template, because the roles are facts about the organization, and the only place those facts live is in people’s heads. So I interviewed everybody I could get my hands on, C-suite down, department by department, for four to five months.

Some people cooperated. Some were unhappy about it and did it anyway. Some simply didn’t, and against the C-suite a consultant has very few levers. When an executive declines to engage with the documentation of his own controls, the documentation notes what it can and the gap remains, visible to anyone who later asks why. That still bothers me, because the people with the most authority over the controls were the ones most free to skip the conversation about them.

How do you document roles for segregation of duties?

The method was interviews, and the craft was in what the interviews extracted. Policies tell you what should happen; only people can tell you who does each piece of it, and their answers disagree in instructive ways. Ask three people who approves a vendor change and you may get three names. That mismatch is a finding in its own right, and it’s the most useful thing an interview like that can produce.

Every one of those disagreements was a place where accountability existed in nobody’s job and everybody’s assumption, and reconciling them, in writing, with names attached to roles and roles attached to procedures, was the actual work of the four to five months.

The drafts then went back to the people they described, and that’s where the second round of truth arrived. Reading your own responsibilities in print concentrates the mind. Some people discovered obligations they had been carrying informally for years; a few discovered obligations they’d assumed belonged to someone else, and the someone else had assumed the reverse. Every such gap closed on paper was an incident that would never need a post-mortem.

The CFO wanted to approve the checks and cut them too. That’s the shape of fraud, not a workflow preference.
Share on X

Why does the CFO matter in segregation of duties?

The revealing moment of the project involved segregation of duties, the control that says the person who authorizes a payment mustn’t be the person who executes it. This is one of the oldest fraud controls in existence, and I assumed everyone in finance carried it in their bones.

The CFO didn’t know what it was. That surprised me. What came next surprised me more: once he understood it, he opposed it. He wanted to be able to cut checks even though he approved them. He wasn’t confused about the control; he objected to the constraint, meaning he wanted to retain exactly the combination of powers the control exists to separate.

We wrote the segregation into the roles anyway. And the reason the control earns its inconvenience isn’t hypothetical to me. At another company I worked with, a colleague uncovered an employee cooking the books, systematic fraud from inside the finance function, and that person went to jail. Fraud happens precisely where one person holds both sides of a transaction. The CFO who wants both sides isn’t describing a threat, necessarily. But he’s describing the shape of one.

Any board that lets its CFO both approve and cut checks is betting the company on one person’s character. I’d never advise a client to make that bet, however much they trust the person in the chair, because the control protects a CFO who’s doing nothing wrong too.

Why is role-level documentation bulletproof?

The payoff came in accountability. With policies mapped to roles and roles mapped to procedures, nobody could weasel out with “I didn’t know that was my job.” It’s right there in the manual: your role owns this step, here’s the procedure, and here’s where you bypassed it. Auditors love this structure, incident reviews resolve in minutes instead of meetings, and quietly, the organization gets more honest, because ambiguity was where the dishonesty used to live.

For executives writing about governance, this is the material readers can’t get from the structure documents: what NIST implementation looks like when it meets an actual org chart, an actual reluctant executive, and an actual fraud down the hall. The frameworks are public and everyone quotes them. I’d push any executive who has lived through a project like this to write about the resistance, because leaving it out produces one more governance book that reads like the standard it describes.

For more from this series, see The Cybersecurity Hub: breaches, audits, and hard-won security lessons from four decades in the trenches.

Frequently Asked Questions

What is segregation of duties?
A control that splits critical transactions between people, so the person who authorizes a payment isn’t the person who executes it. It exists because fraud concentrates where one person holds both sides of a transaction.
What makes NIST documentation effective instead of shelfware?
Mapping every policy to named roles, each with its own procedure. Role-level documentation removes the “I didn’t know it was my job” defense and gives auditors and incident reviews a precise accountability trail.
How long does a NIST documentation project take?
The engagement I led ran four to five months, built on interviews across the entire organization from the C-suite down. The duration is driven by interviews, because role responsibilities exist only in people’s heads until documented.

About the Author
Richard Lowe, professional ghostwriter

Richard Lowe is a professional ghostwriter and author with 113+ books authored and 54+ ghostwritten. Before writing full time he spent 33 years in enterprise technology, including 20 years as Director of Computer Operations and Technical Services at Trader Joe's. He writes nonfiction, fiction and memoir, and works with executives and experts on books that build authority.

More about Richard Lowe →

Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.