GRC versus GCN: When the Four-Eyes Principle Exists but Nobody Is Really Looking

Last Updated on 27/08/2026 by 75385885

How Governance Intelligence Can Strengthen Trusted Approval Processes Without Destroying Trust

Case limitation and analytical disclaimer

Four-Eyes Principle – This article presents an anonymised and partially reconstructed governance case inspired by publicly reported events. Certain circumstances, process details, transaction patterns and hypothetical Governance Control Navigator (GCN) observations have been adapted or added for analytical purposes. The case should therefore not be interpreted as a factual reconstruction of the organisation concerned, the individuals involved or the controls that actually operated at the time.

The underlying public case concerned a finance employee who progressed to become the senior finance executive of a logistics company and, over approximately 9 years, transferred around €3.7 million of company funds to himself. The publicly reported facts include the introduction of a four-eyes banking control, the role of trust within a small finance team and the eventual discovery of an unexplained balance following the acquisition of the company.

The purpose of this article is different. It explores how traditional Governance, Risk & Compliance (GRC) can be enriched by continuously evaluating whether the practical operation of controls remains aligned with their intended Governance Design.


1. It Started With €600

Imagine a medium-sized company with a small finance department.

People know one another. They have worked together for years. The finance team is experienced, trusted and close to the business. Payments are processed every day and, as in thousands of comparable organisations, efficiency depends partly on professional trust.

One employee transfers €600 of company money to himself.

That first amount is almost insignificant compared with what eventually follows.

In the real case that inspired this anonymised example, the employee later told the court that the first €600 was used to buy a racing bicycle. What began as a relatively small transfer ultimately developed into approximately €4.2 million being diverted over a period of about ten years. During those years, the employee progressed from finance employee to the person with ultimate responsibility for the company’s finances.

With hindsight, €600 therefore looks enormously significant.

But that is precisely the problem with hindsight.

At the moment the transaction occurred, it was simply €600 within the financial bloodstream of a functioning company.

That distinction matters.

Governance systems cannot operate on the assumption that every unusual payment represents fraud. Modern businesses process thousands, sometimes millions, of legitimate exceptions. Employees make mistakes. Suppliers change bank accounts. Expense reimbursements occur. Manual payments are necessary. Urgent transactions arise.

An effective governance system therefore needs more than anomaly detection.

It needs context.

And, above all, it needs to understand when seemingly insignificant individual events begin forming a meaningful pattern.

That gives us the first question in this case:

At what point does an individual transaction stop being an exception and become a governance pattern?

Traditional GRC and Governance Control Navigator approach that question from different directions.

GRC establishes the rules governing the transaction.

GCN adds a continuous view of how transactions, users, approvals and exceptions actually behave within those rules.

The distinction becomes particularly important when the organisation subsequently strengthens its controls.

Because that is exactly what happened.


2. The Company Improved Its Controls

One of the most instructive aspects of the underlying case is that the company did not simply continue operating indefinitely with one individual having unrestricted payment authority.

Its banking arrangements changed.

And with that change came an important improvement in internal control:

the four-eyes principle.

According to the reported case, payments initially could be made using a bank authentication device. Following a change of bank, a second person was required to approve payments. On paper, this represented an obvious improvement in Governance Design.

One person initiates.

Another person approves.

The fundamental logic is familiar to almost every finance professional.

Segregation of Duties reduces the risk that one individual can initiate and complete an inappropriate transaction without another person becoming involved.

In GRC terminology, the organisation had introduced a preventive control.

The control objective might have been expressed along the following lines:

Payments above the applicable threshold require independent authorisation by a second appropriately authorised employee before release.

Clear.

Logical.

Auditable.

And entirely sensible.

A conventional GRC environment could subsequently establish whether authorised roles had been configured correctly, whether incompatible permissions were separated and whether payment records contained the required second approval.

A control tester could select a sample of payments and establish:

Initiator: User A
Approver: User B
Authorised users: Yes
Required approval: Present
Payment released after approval: Yes

Control performed.

But something had changed that the technical evidence alone could not necessarily demonstrate.

The finance team was small.

The people involved knew and trusted one another.

The article describes the practical reality very simply: when the finance executive asked somebody to approve a payment, that colleague would do so. It was based on trust.

Suddenly, the distinction between Governance Design and Governance Execution becomes critical.

The control had improved.

But had independent scrutiny improved by the same amount?

Read more form the FBICommon Frauds and Scams.


3. The Problem Was Not Trust

The easiest lesson to draw from a case like this would be:

Do not trust employees.

It would also be the wrong lesson.

Organisations cannot function without trust.

A finance department in which every employee treats every colleague as a potential fraudster would quickly become dysfunctional. Controls would become obstacles rather than safeguards. Decisions would slow down, administrative costs would increase and experienced professionals would spend their time proving their innocence rather than running the business.

Trust is therefore not the enemy of internal control.

Indeed, trust is part of the organisational capital on which effective businesses depend.

The governance problem arises when trust silently begins to replace the substance of a control.

Consider the second approver.Four-Eyes Principle

A colleague asks:

“Could you approve this payment for me?”

The colleague has worked for the company for years.

He understands Finance.

He has greater knowledge of the underlying transactions than many of the people around him.

Nothing problematic has previously come to the approver’s attention.

Why would the approver distrust him?

So the payment is approved.

Tomorrow there is another one.

And another next month.

Gradually, an important behavioural transformation can occur.

The second approval remains technically present, but the mental process behind it changes.

Instead of:

“I am independently reviewing whether this payment should be released.”

it becomes:

“My trusted colleague has asked me to complete the second authorisation.”

The mouse click is identical.

The User ID is different.

The timestamp is recorded.

The audit trail is complete.

But the governance substance may no longer be the same.

That leads to one of the most important distinctions in this entire case:

Trust becomes a governance risk not because trust is undesirable, but when trust becomes an undocumented substitute for independent control execution.

This is also why simply introducing additional controls does not necessarily solve the underlying problem.

A third approver could eventually develop exactly the same behavioural routine.

The issue is not the number of electronic signatures.

The issue is whether those signatures continue to represent genuinely independent decisions.


4. Traditional GRC Sees a Valid Approval

This is where the distinction between GRC and GCN becomes particularly tangible.

Suppose an Internal Audit team tests payment controls.

The organisation’s control matrix states that certain payments require two authorised individuals.

The auditor extracts a sample.

For the selected payment, the system demonstrates that User A initiated the payment and User B subsequently approved it.

User A and User B are different employees.

Both had valid access rights.

Their respective authorisation limits were sufficient.

The approval occurred before the payment was released.

There is no obvious Segregation of Duties conflict in the access matrix.

From the evidence available for that individual transaction, the four-eyes control may appear to have operated exactly as designed.

That conclusion is not necessarily wrong.

This is important.

GCN should not be positioned by pretending that conventional GRC or Internal Audit has somehow failed merely because a later fraud becomes known.

The control test answers the question it was designed to answer:

Was the required second approval present?

Governance Control Navigator adds a different question:

Does the broader pattern of approvals provide evidence that the second approval is functioning as an independent review?

Now the unit of analysis changes.

Instead of examining only one payment, consider six months of payment behaviour.

Perhaps User B approves an unusually high proportion of User A’s payments.

Perhaps the relationship is reciprocal.

Perhaps User A also approves most payments initiated by User B.

Perhaps their approval times are consistently much shorter than those of comparable approvers.

Perhaps neither employee rejects, returns or questions payments initiated by the other.

Perhaps one approval relationship becomes increasingly dominant as the years progress.

None of these observations proves wrongdoing.

That cannot be emphasised strongly enough.

There may be perfectly legitimate explanations.

The two employees may work on the same portfolio.

One may be the designated deputy for the other.

A small finance team may simply have few realistic approval combinations.

Urgent payment processes may legitimately produce rapid approvals.

But taken together, these observations create a legitimate governance question:

Is the control still operating with the degree of independence its designers intended?

Traditional GRC establishes whether the control occurred.

GCN helps management examine the behaviour of the control itself.


5. The Difference Between Control Design and Control Substance

This brings us to the central proposition of Part 1.

Governance controls have both form and substance.

The form of a four-eyes control is relatively straightforward:

two appropriately authorised individuals participate in the transaction.

Its substance is more demanding:

the second individual provides a sufficiently independent challenge before the transaction is completed.

A computer system can establish the first relatively easily.

The second requires context.

This is where Governance Intelligence can enrich GRC.

GCN does not need to conclude that an approver failed to perform a proper review. Instead, it can continuously evaluate behavioural characteristics surrounding the control.

For example, does an approver normally take several minutes to approve significant payments but approve payments from one particular colleague almost immediately?

Does an approver occasionally reject transactions from most initiators but never reject those of one particular person?

Does one initiator-approver combination occur far more frequently than organisational structure alone would predict?

Are unusual beneficiaries disproportionately associated with the same approval pair?

Does approval behaviour change when people are absent?

Do transaction amounts gradually increase while the approval relationship remains unchanged?

Each observation is weak evidence on its own.

Together, they may become valuable Governance Intelligence.

And that is the crucial difference.

GCN is not attempting to prove that the four-eyes principle has failed.

It is continuously asking whether the observable behaviour surrounding the control remains consistent with its governance purpose.

The distinction can be expressed very simply:

Traditional GRC can demonstrate that two different User IDs approved the transaction.

GCN adds the question whether those two User IDs continue to behave like two independent decision-makers.

That does not weaken GRC.

It strengthens it.

The four-eyes principle remains the Governance Design.

Segregation of Duties remains essential.

Authorisation limits remain essential.

Internal Audit remains essential.

GCN adds a feedback loop between the control as designed and the control as experienced in organisational reality.

And that matters because, in the case that inspired this article, the introduction of a second approval did not bring the underlying behaviour to an end. The reported conduct continued for years and was ultimately exposed only after the company was acquired and an unexplained accounting item attracted attention during a review of the books.

That gives us a much more useful governance lesson than simply saying that somebody should have checked more carefully.

The lesson is that a control can exist, be executed and leave a complete electronic audit trail while still gradually losing part of the behavioural substance for which it was designed.

In the next chapter, we therefore move beyond the individual payment.

Because €600 tells us very little.

Even €10,000 may tell us very little.

The real power emerges when transactions, users, beneficiaries, approval relationships, timing and exceptions are connected over time.

That is the point at which a series of ordinary transactions can become something much more important:

a visible pattern of governance divergence.

6. One Payment Tells You Almost Nothing

The uncomfortable reality of payment fraud is that an individual transaction often looks remarkably ordinary.

A payment of €600 does not automatically attract attention. Neither does €2,500, €7,500 or even a substantially larger amount in an organisation processing significant payment volumes.

Businesses make unusual payments every day.

There are advances, refunds, settlements, urgent supplier payments, employee expenses, tax payments, intercompany transfers and manual corrections. Amounts vary. Beneficiaries change. Transactions sometimes fall outside the normal payment run.

That is why simply lowering authorisation limits or creating ever more exception reports is unlikely to solve the underlying governance problem. The result may simply be thousands of additional alerts that Finance has neither the time nor the reason to investigate.

The publicly reported case that inspired this article illustrates the difficulty particularly well. The behaviour reportedly began with a relatively small amount and continued over many years. At one point, an exceptionally large payment was made, followed by a period in which the behaviour stopped before eventually resuming.

That is very different from a simple scenario in which somebody suddenly transfers an enormous amount and everybody should obviously have noticed.

The individual payment is therefore not necessarily the most interesting governance object.

The pattern may be.

GCN would not ask only:

Is this payment unusual?

It would also ask:

Does this payment belong to a developing pattern that is unusual?

That sounds like a small distinction.

In practice, it changes the analysis completely.


7. The Approval Relationship Becomes Part of the Control

Consider again the four-eyes principle.

Traditional GRC defines the control appropriately:

one person initiates the payment and another authorised person approves it.

The control can be configured in the banking environment. Access rights can be tested. Authorisation limits can be reviewed. Internal Audit can select transactions and verify that two separate User IDs participated.

GCN does not need to change any of that.

Instead, it can add the relationship between those users to the analysis.

Suppose Finance has six people authorised to provide second approval.

Over twelve months, most payment initiators have their transactions approved by several different colleagues.

But one particular initiator behaves differently.

Perhaps 80% of that person’s manually initiated payments are approved by the same colleague.

Again, that may be perfectly reasonable.

They may work together closely.

Their responsibilities may overlap.

Other authorised colleagues may frequently be unavailable.

A pattern is not a finding.

Now add another dimension.

The same approver normally takes several minutes to review significant payments initiated by other colleagues but approves this person’s transactions considerably faster.

Still explainable.

Then another.

The approver occasionally returns or rejects payments submitted by other colleagues but virtually never does so for this particular initiator.

And another.

Payments involving unusual beneficiaries are disproportionately present within the same initiator-approver relationship.

No single observation proves anything.

But collectively they begin to tell management something about the practical operation of the control.

This is where GCN enriches GRC.

The question is no longer merely:

Were two people involved?

It becomes:

Does the observed relationship between those two people remain consistent with the independent review that the four-eyes principle was designed to create?

That is not fraud detection.

It is control intelligence.


8. GCN Does Not Need to Know That It Is Fraud

This distinction is crucial.

Governance Control Navigator should not attempt to determine from transaction patterns that an employee is stealing from the company.

That would turn Governance Intelligence into a pseudo-forensic system and create precisely the wrong management behaviour.

There are too many legitimate explanations for unusual transactions.

Instead, GCN looks for governance divergence.

Imagine that payments associated with one finance role gradually begin to differ from the normal population.

The differences might involve:

  • recurring beneficiary relationships;
  • unusual payment timing;
  • concentrations around particular approval combinations;
  • increasing transaction values;
  • payments outside normal processing cycles;
  • unusually rapid second approvals;
  • almost complete absence of rejected or returned transactions.

None of those characteristics means:

fraud.

They mean:

different.

And “different” is enough to justify a proportionate governance question.

This distinction also protects employees.

The purpose of continuous monitoring should never be to create an environment in which every deviation makes somebody a suspect.

A deviation may reveal a badly designed process.

It may reveal insufficient staffing.

It may show that the authorisation matrix no longer reflects actual responsibilities.

It may reveal that one experienced employee has become indispensable.

It may simply identify a perfectly legitimate business activity that should be incorporated into the normal governance model.

The objective is therefore to understand the deviation.

Not to criminalise it.

GCN does not detect the fraud.

GCN detects that Governance Reality no longer behaves as expected.

What management subsequently discovers is a matter for management, Compliance, Internal Audit or, where appropriate, a formal investigation.


9. When the Pattern Suddenly Changes

The original reported case contains another particularly interesting element.

At one stage, a very substantial payment was reportedly made to the employee himself. The explanation later given was that a decimal or comma error had caused a much larger amount to be transferred than intended. Following that event, the behaviour stopped for a period before subsequently resuming.

For a traditional transaction-control environment, the large payment itself is obviously interesting.

For GCN, the change in behaviour before and after the event may be equally interesting.

Imagine a payment pattern developing gradually over several years.

Then suddenly:

the pattern stops.

For months, the previous activity disappears.

Later it returns.

That behavioural interruption provides information.

Not proof.

Information.

GCN is not limited to detecting increasing transaction volumes. It can also identify changes in frequency, concentration, timing and relationships.

A pattern can accelerate.

It can migrate.

It can disappear.

It can reappear.

And these changes can be compared with other organisational events.

Did the approval matrix change?

Did someone go on leave?

Was a new bank introduced?

Did responsibilities move?

Was Internal Audit reviewing the process?

Did management introduce an additional control?

Again, correlation is not causation.

But governance becomes considerably more informative when management can observe how actual behaviour responds to changes in the control environment.

This is particularly important when controls are strengthened.

If management introduces dual authorisation, GCN should not merely record:

Control implemented: completed.

It should subsequently ask:

Did transaction and approval behaviour actually change?

That is the beginning of measurable governance improvement.


10. From Anomaly to Governance Divergence

Now imagine that GCN combines the available information.

Not one transaction.

Not one user.

Not one unusual beneficiary.

But several months or years of payment behaviour.

The resulting governance observation might read:

Payment activity associated with a finance role has progressively diverged from comparable payment behaviour. The same approval relationships recur disproportionately, selected payments fall outside normal processing patterns and second-authorisation behaviour differs from the wider peer group. Management review is recommended to determine whether the current payment-control design remains effective in practice.

Notice what GCN has not said.

It has not said:

Employee fraud detected.

It has not said:

The approver is colluding.

It has not even concluded:

The four-eyes control has failed.

There is insufficient evidence for any of those conclusions.

GCN has done something much more modest and, from a governance perspective, potentially much more useful.

It has made an emerging pattern visible.

Management can now investigate the explanation.

Perhaps Finance is understaffed and the same two people have little choice but to authorise each other’s payments.

Then the appropriate response is not disciplinary action.

It is to solve the staffing or authorisation problem.

Perhaps unusual manual payments have increased because the ERP workflow no longer accommodates a particular business process.

Then the process should be redesigned.

Perhaps the second approver receives insufficient supporting information to perform a meaningful review.

Then the approval screen or procedure should be improved.

And yes, perhaps further examination ultimately identifies inappropriate transactions.

But that conclusion comes after investigation, not from the GCN signal itself.

This distinction matters because it changes the relationship between the business and Governance, Risk & Compliance.

GRC should not become the department that appears periodically with another exception list and asks operational management to explain itself.

GCN can make governance more constructive.

A divergence is identified.

The reason is understood.

A practical solution is actively pursued.

The solution is documented.

Responsibility is assigned.

The appropriate level of management authorises it.

And then comes the part traditional remediation processes can sometimes find difficult:

GCN continues observing the process to determine whether the solution actually changed Governance Reality.

That is where continuous monitoring becomes more than continuous control testing.

It becomes continuous improvement.

Because the real lesson from this case is not that the company needed a third approver, a fourth signature or another page in the Finance Manual.

The organisation already had a control.

The more interesting question is how GRC and GCN together can ensure that the control continues to work in substance, not merely in form.

11. Finding the Deviation Is Not the Objective

Suppose Governance Control Navigator identifies the pattern described in Part 2.

A particular finance role is associated with an unusual concentration of manual payments. The same initiator-approver combination occurs disproportionately often. Second approvals are unusually rapid and certain beneficiary patterns differ from those of comparable transactions.

Management now has a signal.

But it does not yet have a solution.

That distinction is fundamental.

A governance system that merely produces more exceptions, alerts and red flags can easily become another administrative burden. Finance receives a report. Compliance requests an explanation. Internal Audit adds an observation. Management writes an action plan. Someone updates a GRC system.

Six months later, everyone has complied with the process, but the underlying operational problem may still exist.

GCN should lead somewhere else.

The purpose of identifying governance divergence is to understand why it exists and what should be done about it.

Perhaps the explanation is surprisingly mundane.

The finance department has only a few employees with sufficient banking authority. One works part-time. Another regularly travels between locations. In practice, the same two experienced employees therefore authorise most exceptional payments for each other.

The four-eyes principle has not deliberately been circumvented.

The organisation has simply developed a practical solution to a staffing constraint.

That solution may have worked for years.

It may also have gradually weakened the independence that the control was designed to provide.

Traditional GRC correctly identifies the requirement:

two appropriately authorised people must participate.

GCN adds:

the way those people participate has become unusually concentrated.

Now management can address the real issue.

Perhaps another senior employee should receive appropriately limited payment authority. Perhaps approval responsibilities should rotate. Perhaps particular payment categories require a different approver. Perhaps supporting documentation needs to be more visible before the second authorisation can be given.

The appropriate solution will differ between organisations.

The governance principle should not:

A material divergence should lead to a practical solution that is actively pursued, documented and appropriately authorised.

This is an important distinction between governance observation and governance improvement.

Finding the problem is not the achievement.

Improving the organisation is.

Read more on Behavioural Governance on the website by Ethical Governance, an Australian research-led governnace firm.


12. Continuous Monitoring Should Create Continuous Improvement

Once a solution has been implemented, traditional remediation management can establish whether the agreed action has been completed.

New approver appointed.

Authorisation matrix updated.

Bank access configured.

Procedure amended.

Action closed.

All necessary.

But GCN can now ask the more interesting question:

Did it work?

Suppose approval responsibilities were broadened because one pair of employees had become excessively dependent on each other.

During the following months, GCN can observe whether approval concentration actually declines.

Does the original pair now account for 35% rather than 85% of exceptional payments?

Are approvals distributed more naturally across the authorised population?

Do review times become more comparable?

Are unusual payments receiving more visible challenge?

If so, management has evidence that the intervention changed Governance Reality.

If nothing changes, simply closing the remediation action would tell only part of the story.

This feedback loop is also important at the level of individual users.

Continuous monitoring should not be designed primarily as continuous surveillance.

Used intelligently, it can support continuous improvement in control execution.

Consider the employee providing the second approval.

That employee may never have realised that their behaviour differed from colleagues. They may simply have developed an efficient routine over many years.

Showing the individual that, for example, their approval times are consistently shorter or that they almost never return transactions can create useful professional awareness.

The message is not:

“We are watching you.”

It is:

“This is how the control operates in practice. Does that still correspond with what we expect from the control?”

That can change behaviour remarkably quickly.

The second approver starts looking more carefully at supporting documents.

Questions become slightly more frequent.

Unclear payments are returned.

The control becomes more effective without adding another approval layer.

Continuous monitoring has then produced something considerably more valuable than another compliance report.

It has produced continuous organisational learning.

And importantly, this does not require every employee to behave identically.

GCN should not attempt to standardise professional judgement.

Some employees work faster than others. Some teams legitimately have different transaction profiles. Some approval relationships are structurally more frequent.

The objective is to understand material divergence, establish whether it has a legitimate explanation and improve the process where appropriate.

That is navigation rather than policing.

Read more GRC and GCN cooperation cases in our blogs: JPMorgan and Weak Internal Controls: When Governance Design Is Not Enough or GRC versus Governance Control Navigator (GCN) – Why Perfect Controls Can Still Produce the Wrong Reality.


13. The Three Governance Realities™

The four-eyes case also provides a particularly simple illustration of the Three Governance Realities™.

Governance Design

The intended control is straightforward:

Significant payments require independent approval by two appropriately authorised individuals.

The organisation establishes an authorisation matrix, configures its banking system accordingly and separates the relevant User IDs.

Governance Design is sound.

Governance Execution

In operational reality, two employees participate.

One initiates the payment.

Another logs into the banking environment and approves it.

The electronic evidence confirms that the control has been executed.

Again, nothing is necessarily wrong.

Collective Governance Behaviour™

Now widen the perspective from individual transactions to behaviour over time.

The same employees repeatedly approve each other’s transactions.

Approval becomes increasingly routine.

Challenge becomes unusual.

Trust replaces part of the independent review originally envisaged by the control.

No single transaction creates this situation.

No policy necessarily changes.

No employee needs consciously to decide:

“From today onwards, I will no longer perform this control properly.”

The pattern emerges gradually from ordinary working behaviour.

This is precisely why the third governance reality matters.

The organisation can simultaneously demonstrate:

the control exists;

the control has been executed;

and yet:

the intended governance outcome may no longer be fully achieved.

That is the space in which GCN adds value.

Traditional GRC provides the architecture.

GCN connects that architecture with evidence of how the organisation actually behaves within it.

The difference is not theoretical.

It determines whether management knows only that the control was performed or also understands whether the control continues to serve its intended purpose.

Four-Eyes Principle GRC versus GCN, Governance Control Navigator Governance Intelligence Segregation of Duties dual authorisation
payment controls continuous monitoring governance divergence control effectiveness behavioural governance

Four-Eyes Principle Four-Eyes Principle Four-Eyes Principle Four-Eyes Principle Four-Eyes Principle Four-Eyes Principle Four-Eyes Principle Four-Eyes Principle


14. Don’t Add Another Pair of Eyes – Make the Existing Eyes Look

Cases involving long-running payment irregularities often produce a predictable governance response.

Increase approval requirements.

Lower authorisation limits.

Add another management review.

Introduce more exception reports.

Perform additional audits.

Require more documentation.

Some of those measures may be entirely appropriate.

But there is a danger.

Every governance problem appears to produce another control.

Over time, the organisation accumulates layers of approvals, reports and procedures. Employees become increasingly accustomed to clicking through them. Controls that were intended to create challenge gradually become administrative routines.

The solution to a four-eyes control that has lost part of its effectiveness is therefore not automatically a six-eyes control.

Before adding another pair of eyes, management should understand why the existing four were insufficient.

Was there insufficient staffing?

Was the second approver unable to see the underlying documentation?

Had approval become too routine?

Was the authorisation structure poorly aligned with actual responsibilities?

Had one experienced employee accumulated too much practical influence over the process?

Or was there, after further investigation, evidence of deliberate misconduct?

Those are very different problems.

They require very different solutions.

This is also why the distinction between GRC and GCN should not be framed as a competition.

Traditional Governance, Risk & Compliance remains essential.

GRC defines the four-eyes principle.

It establishes Segregation of Duties.

It determines authorisation limits.

It manages access rights.

It documents controls.

It enables Internal Audit to test whether controls have operated.

It records deficiencies and monitors remediation.

Governance Control Navigator adds another layer.

It continuously examines whether the actual operation of those controls remains aligned with their intended purpose.

Four-Eyes Principle

That creates a much more useful governance cycle:

Design the control.

Operate the control.

Observe the resulting behaviour.

Identify material divergence.

Understand the cause.

Develop a practical solution.

Document and appropriately authorise that solution.

Then determine whether Governance Reality actually improves.

That final step matters.

A governance issue should not disappear simply because someone has changed its status from Open to Closed in a GRC system.

The organisation should be able to see that the underlying behaviour has changed.

That is where continuous Governance Intelligence can transform remediation from an administrative process into an improvement process.

The fictionalised case in this article therefore should not leave us with the simplistic conclusion that employees cannot be trusted.

Nor should it lead to the conclusion that the four-eyes principle does not work.

Quite the opposite.

The four-eyes principle is a sensible and powerful control.

But even good controls operate through people.

People develop routines.

Teams become familiar with each other.

Experienced colleagues earn trust.

Shortcuts emerge because they make daily work easier.

Most of those developments are completely innocent.

Occasionally, however, the practical operation of the control gradually moves away from what its designers intended.

Traditional GRC gives management the framework needed to control that risk.

GCN adds the ability to observe that movement while it is occurring.

And that leads to the central lesson of this case:

The control exists. The control is executed. But that does not automatically mean that the intended governance outcome is still being achieved.

Better governance therefore does not always require more controls.

Sometimes it requires a better understanding of the controls already in place.

Or, put more simply:

Don’t automatically add another pair of eyes. First make sure the eyes you already have are actually looking.

 

Four-Eyes Principle