Your glossary term was created and approved by the same person. That’s an audit finding. The four-eyes principle requires a second pair of eyes on every critical action — and it’s mandated across finance, pharma, and information security.
The four-eyes principle requires that any critical decision, transaction, or approval be reviewed and signed off by at least two authorized people — and bars the initiator from approving their own action. It maps directly onto MiFID II Art. 9(6), SOX Sections 302/404, FDA GMP (21 CFR 211.101, 211.103, 211.188), and ISO/IEC 27001:2022 Annex A 5.3 / ISO/IEC 27002:2022 clause 5.3 “Segregation of duties,” and is the standard control against self-approval, fraud, and single-point error in regulated workflows.
Last verified: 2026-04-17
The four-eyes principle (German: Vier-Augen-Prinzip) requires that a certain activity — a decision, transaction, or approval — must be reviewed and approved by at least two authorized people before it takes effect.
Also known as: dual control, maker-checker, two-person rule. The “maker” initiates an action; a separate “checker” independently reviews and approves or rejects it.
The concept is simple: four eyes see more than two. A single person can make mistakes, introduce bias, or act without oversight. A mandatory second reviewer catches errors, prevents fraud, and creates accountability.
The four-eyes principle is mandated — explicitly or through equivalent requirements — across every major compliance framework:
| Regulation | Requirement | Specific Reference |
|---|---|---|
| MiFID II | The “two persons effectively directing the business” rule, commonly called the four-eyes principle in ESMA guidance (MiFID II Directive 2014/65/EU Art. 9(6)). | Article 9(6) |
| SOX (Sarbanes-Oxley) | CEO and CFO must both certify financial statements. Internal controls require documented dual authorization for critical financial processes. | Sections 302, 404 |
| FDA GMP | Second-person verification required for weighing components, adding to batches, yield calculations, and labeling. Does not use the phrase “four-eyes” but codifies identical requirements. | 21 CFR 211.101(c)(d), 211.103, 211.188(b) |
| ISO/IEC 27001:2022 / 27002:2022 | Annex A 5.3 / ISO 27002 clause 5.3 “Segregation of duties” requires that conflicting duties and conflicting areas of responsibility be segregated; the corresponding ISO/IEC 27002:2022 implementation guidance discusses dual control as one means of meeting this requirement. | ISO/IEC 27002:2022 clause 5.3 |
| EBA Guidelines | Credit institutions require governance structures with dual oversight preventing single-person control over critical processes. | EBA/GL/2021/05 |
| Basel Committee | Separation of functions for committing the bank, paying funds, and accounting for assets. | Core Principles for Banking Supervision |
| EU AML Directive | Internal controls and independent review functions required (Directive (EU) 2015/849 Art. 8 internal policies, Art. 46 compliance function); dual control is the prevailing industry implementation for large-value transaction approvals and STR escalation. | Art. 8 (internal policies), Art. 46 (compliance function) |
Compliance Glossary enforces the four-eyes principle in code — not policy. The system technically prevents self-approval.
The four-eyes principle is only as strong as its audit trail. Each approval in Compliance Glossary records:
This creates the evidence chain auditors need. No reconstruction, no email threads, no “I think Sarah approved it.” Learn more about the complete audit trail in our compliance guide and how it maps to ALCOA+ data integrity principles.
These terms are related but distinct:
| Four-Eyes Principle | Segregation of Duties (SoD) | |
|---|---|---|
| Scope | A specific control at a single approval point | An organizational design framework across entire processes |
| Core idea | Two people must review the same action | Different stages of a process are handled by different people |
| Example | Person A defines a term, Person B approves it | Person A manages the glossary, Person B runs compliance scans, Person C handles audit exports |
| Relationship | One implementation of SoD | The overarching principle; four-eyes is a subset |
Compliance Glossary implements the four-eyes principle as the primary control. Full segregation of duties is supported through role-based access — you can configure who can create terms, who can approve, and who can run compliance scans.
Financial terminology (risk appetite, material transaction, insider information) drives regulatory reporting. MiFID II and SOX both require dual authorization. When your compliance team defines “material adverse change,” a second compliance officer must verify the definition matches regulatory intent before it governs reporting across the organization.
FDA GMP mandates second-person verification for batch records, component weighing, and labeling. The same logic applies to your controlled vocabulary — if “adverse event” is defined incorrectly, every CRF and safety report using that term inherits the error. See our FDA terminology management guide for the full 21 CFR Part 11 alignment.
ISO/IEC 27001:2022 Annex A 5.3 — “Segregation of duties” — with implementation guidance in ISO/IEC 27002:2022 clause 5.3, is the international-standard control behind dual-authorisation patterns for critical changes. Security policy terminology (incident, vulnerability, breach) must be defined consistently — and that definition needs independent verification. Our SOC 2 terminology template covers 40 Trust Services Criteria terms.
Pull request reviews are the four-eyes principle applied to code. The same principle applies to the documentation that governs that code — especially incident response procedures, change management policies, and security runbooks that reference controlled terminology.
The four-eyes principle (Vier-Augen-Prinzip) requires that a decision, transaction, or approval be reviewed and approved by at least two authorized people before it takes effect. It bars self-approval: whoever initiates an action cannot be the one who signs off on it. Also called dual control, maker-checker, or the two-person rule.
MiFID II Art. 9(6) requires at least two persons effectively directing the business of investment firms. SOX Sections 302 and 404 require dual certification and documented internal controls. FDA GMP (21 CFR 211.101(c)(d), 211.103, 211.188(b)) codifies second-person verification. ISO/IEC 27001:2022 Annex A 5.3 (and the implementation guidance in ISO/IEC 27002:2022 clause 5.3) is titled “Segregation of duties” and is the standards-based control behind dual-authorisation patterns. EU AML Directive (EU) 2015/849 Arts. 8 and 46 require internal policies and a compliance function.
Four-eyes is a specific control at one approval point: two people must review the same action. Segregation of duties is an organizational design framework that splits different stages of a process across different people. Four-eyes is one implementation of segregation of duties — see the comparison table above.
Compliance Glossary enforces four-eyes in code, not policy. If User A creates or edits a term and submits it for review, User A cannot approve it — the approve action is only available to a different authorized user. The check is server-side and cannot be bypassed through the UI. Every action is logged with user ID, timestamp, reason, and full diff, creating the evidence chain auditors need.
The four-eyes principle isn’t a policy suggestion — it’s a regulatory requirement. Enforce it in code, not in hope.
Evaluate in Confluence See Approval Workflow DocsCompliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence
ALCOA+ Documentation Principles — the data integrity framework behind every audit trail requirement
Compliance Guide — what auditors check and how we help, mapped to real regulatory standards
FDA Terminology Management — 43-term template for pharma & medtech, mapped to 21 CFR Part 11
SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams
Glossary App Comparison — how Compliance Glossary compares to Smart Terms, VECTORS, and native Confluence
Board Regulatory Disclosure (CEO) — four-eyes principle applied at the board level: dual sign-off on regulatory disclosures and material statements