Approval Workflow Control

Four-Eyes Principle in Documentation

Your glossary term was created and approved by the same person. That’s an audit finding. The four-eyes principle requires a second pair of eyes on every critical action — and it’s mandated across finance, pharma, and information security.

What Is the Four-Eyes Principle?

The four-eyes principle requires that any critical decision, transaction, or approval be reviewed and signed off by at least two authorized people — and bars the initiator from approving their own action. It maps directly onto MiFID II Art. 9(6), SOX Sections 302/404, FDA GMP (21 CFR 211.101, 211.103, 211.188), and ISO/IEC 27001:2022 Annex A 5.3 / ISO/IEC 27002:2022 clause 5.3 “Segregation of duties,” and is the standard control against self-approval, fraud, and single-point error in regulated workflows.

Last verified: 2026-04-17

The four-eyes principle (German: Vier-Augen-Prinzip) requires that a certain activity — a decision, transaction, or approval — must be reviewed and approved by at least two authorized people before it takes effect.

Also known as: dual control, maker-checker, two-person rule. The “maker” initiates an action; a separate “checker” independently reviews and approves or rejects it.

The concept is simple: four eyes see more than two. A single person can make mistakes, introduce bias, or act without oversight. A mandatory second reviewer catches errors, prevents fraud, and creates accountability.

Common audit finding: A team lead defines “material adverse change” in the company glossary and immediately marks it as approved. No one else reviewed the definition. Six months later, the auditor asks: “Who verified this definition was accurate? Where’s the evidence of independent review?” The answer is “nobody” — and that’s a control gap.

Which Regulations Require It?

The four-eyes principle is mandated — explicitly or through equivalent requirements — across every major compliance framework:

RegulationRequirementSpecific Reference
MiFID IIThe “two persons effectively directing the business” rule, commonly called the four-eyes principle in ESMA guidance (MiFID II Directive 2014/65/EU Art. 9(6)).Article 9(6)
SOX (Sarbanes-Oxley)CEO and CFO must both certify financial statements. Internal controls require documented dual authorization for critical financial processes.Sections 302, 404
FDA GMPSecond-person verification required for weighing components, adding to batches, yield calculations, and labeling. Does not use the phrase “four-eyes” but codifies identical requirements.21 CFR 211.101(c)(d), 211.103, 211.188(b)
ISO/IEC 27001:2022 / 27002:2022Annex A 5.3 / ISO 27002 clause 5.3 “Segregation of duties” requires that conflicting duties and conflicting areas of responsibility be segregated; the corresponding ISO/IEC 27002:2022 implementation guidance discusses dual control as one means of meeting this requirement.ISO/IEC 27002:2022 clause 5.3
EBA GuidelinesCredit institutions require governance structures with dual oversight preventing single-person control over critical processes.EBA/GL/2021/05
Basel CommitteeSeparation of functions for committing the bank, paying funds, and accounting for assets.Core Principles for Banking Supervision
EU AML DirectiveInternal controls and independent review functions required (Directive (EU) 2015/849 Art. 8 internal policies, Art. 46 compliance function); dual control is the prevailing industry implementation for large-value transaction approvals and STR escalation.Art. 8 (internal policies), Art. 46 (compliance function)

How It Works in Compliance Glossary

Compliance Glossary enforces the four-eyes principle in code — not policy. The system technically prevents self-approval.

Step 1Author creates or edits a term
Step 2Author submits for review
Step 3Different person reviews
Step 4Reviewer approves or rejects
Enforced by the system: If User A creates a term and submits it for approval, User A cannot approve it. The approve button is only available to a different authorized user. This is checked server-side — it cannot be bypassed through the UI.
What happens without enforcement: Spreadsheet-based glossaries, shared documents, and most glossary apps have no concept of author vs. reviewer. Anyone can create and “approve” a term in the same action. There is no evidence of independent review — and auditors will find that gap.

Every action is recorded

The four-eyes principle is only as strong as its audit trail. Each approval in Compliance Glossary records:

This creates the evidence chain auditors need. No reconstruction, no email threads, no “I think Sarah approved it.” Learn more about the complete audit trail in our compliance guide and how it maps to ALCOA+ data integrity principles.

Four-Eyes Principle vs. Segregation of Duties

These terms are related but distinct:

Four-Eyes PrincipleSegregation of Duties (SoD)
ScopeA specific control at a single approval pointAn organizational design framework across entire processes
Core ideaTwo people must review the same actionDifferent stages of a process are handled by different people
ExamplePerson A defines a term, Person B approves itPerson A manages the glossary, Person B runs compliance scans, Person C handles audit exports
RelationshipOne implementation of SoDThe overarching principle; four-eyes is a subset

Compliance Glossary implements the four-eyes principle as the primary control. Full segregation of duties is supported through role-based access — you can configure who can create terms, who can approve, and who can run compliance scans.

Industry Applications

Banking & Finance

Financial terminology (risk appetite, material transaction, insider information) drives regulatory reporting. MiFID II and SOX both require dual authorization. When your compliance team defines “material adverse change,” a second compliance officer must verify the definition matches regulatory intent before it governs reporting across the organization.

Pharmaceutical & Life Sciences

FDA GMP mandates second-person verification for batch records, component weighing, and labeling. The same logic applies to your controlled vocabulary — if “adverse event” is defined incorrectly, every CRF and safety report using that term inherits the error. See our FDA terminology management guide for the full 21 CFR Part 11 alignment.

Information Security

ISO/IEC 27001:2022 Annex A 5.3 — “Segregation of duties” — with implementation guidance in ISO/IEC 27002:2022 clause 5.3, is the international-standard control behind dual-authorisation patterns for critical changes. Security policy terminology (incident, vulnerability, breach) must be defined consistently — and that definition needs independent verification. Our SOC 2 terminology template covers 40 Trust Services Criteria terms.

Software & IT

Pull request reviews are the four-eyes principle applied to code. The same principle applies to the documentation that governs that code — especially incident response procedures, change management policies, and security runbooks that reference controlled terminology.

Frequently Asked Questions

What is the four-eyes principle?

The four-eyes principle (Vier-Augen-Prinzip) requires that a decision, transaction, or approval be reviewed and approved by at least two authorized people before it takes effect. It bars self-approval: whoever initiates an action cannot be the one who signs off on it. Also called dual control, maker-checker, or the two-person rule.

Which regulations reference the four-eyes principle?

MiFID II Art. 9(6) requires at least two persons effectively directing the business of investment firms. SOX Sections 302 and 404 require dual certification and documented internal controls. FDA GMP (21 CFR 211.101(c)(d), 211.103, 211.188(b)) codifies second-person verification. ISO/IEC 27001:2022 Annex A 5.3 (and the implementation guidance in ISO/IEC 27002:2022 clause 5.3) is titled “Segregation of duties” and is the standards-based control behind dual-authorisation patterns. EU AML Directive (EU) 2015/849 Arts. 8 and 46 require internal policies and a compliance function.

What is the difference between four-eyes principle and segregation of duties?

Four-eyes is a specific control at one approval point: two people must review the same action. Segregation of duties is an organizational design framework that splits different stages of a process across different people. Four-eyes is one implementation of segregation of duties — see the comparison table above.

How does Compliance Glossary enforce the four-eyes principle?

Compliance Glossary enforces four-eyes in code, not policy. If User A creates or edits a term and submits it for review, User A cannot approve it — the approve action is only available to a different authorized user. The check is server-side and cannot be bypassed through the UI. Every action is logged with user ID, timestamp, reason, and full diff, creating the evidence chain auditors need.

Stop Self-Approving Terminology

The four-eyes principle isn’t a policy suggestion — it’s a regulatory requirement. Enforce it in code, not in hope.

Evaluate in Confluence See Approval Workflow Docs

Related Resources

Compliance for Confluence — approved terms, page scanning, and audit evidence for regulated teams in Confluence

ALCOA+ Documentation Principles — the data integrity framework behind every audit trail requirement

Compliance Guide — what auditors check and how we help, mapped to real regulatory standards

FDA Terminology Management — 43-term template for pharma & medtech, mapped to 21 CFR Part 11

SOC 2 Terminology Management — 40 Trust Services Criteria terms for InfoSec & GRC teams

Glossary App Comparison — how Compliance Glossary compares to Smart Terms, VECTORS, and native Confluence

Board Regulatory Disclosure (CEO) — four-eyes principle applied at the board level: dual sign-off on regulatory disclosures and material statements