Separation of duties is a strategy for reducing risk to an organization inherent in any one person or system having too much authority. For example, in fraud prevention it is a common practice to require that transactions be initiated by one person, approved by another, and executed by a third. With respect to IT systems, a separation of duties policy might require that software be developed by a group independent from the system users.
With respect to fundamental IT security principles, separation of duties represents a form of administrative control.