A high-risk transaction refers to transactions that have a high chance that they can lead to losses when a threat occurs and the impact of such loss would be huge.
A good example is when payroll raises approval without enough consideration of the company's revenue structure. This could lead to the company suffering losses.
Separation of duties is important. Below is an example of roles that should be separated:
System configuration and approvals
An IT engineer typically does the configurations and changes to IT devices such as firewalls and intrusion detection systems. However, the chief information security officer is in charge of approving the changes or disapproving them if they do not meet the company recommendations
System Access Permissions
An administrator has to add and edit permissions while a security analyst can only report and do a monitoring role on security incidents that escalate for action to be taken.
Learn more about security professionals here https://brainly.com/question/26260220
#SPJ4