This might be what your looking for:

COBIT PO 4.4 and PO 4.10—Roles, Responsibilities, and Segregation of Duties

As part of an effective regulatory compliance program, COBIT Planning and Organization (PO) section 4.4 directs management to ensure that all personnel have clearly defined roles and responsibilities in relation
to an organization’s IT systems. Further, COBIT PO 4.10 specifies that an organization should define and implement clearly defined user roles and responsibilities that exclude the opportunity for an individual or
department to co-opt or subvert critical parts of the IT system including data access, data entry, system administration, and security processes.
Cheers