Join our Newsletter — 33% off our NHI Course

Why do organisation-wide access reviews become less effective when they stay limited to ERP?

ERP-only reviews miss conflicts that emerge when users hold risky combinations of access across multiple platforms. A person may appear compliant in one system while still creating excessive privilege or SoD violations elsewhere. Broader reviews help security and GRC teams see the full access picture, especially in hybrid and SaaS environments where business processes span several applications.

Why This Matters for Security Teams

ERP-only access reviews create a narrow compliance view that can look clean while the real risk sits in adjacent SaaS, cloud, and workflow tools. Once access is distributed across finance, HR, ticketing, and integration platforms, separation-of-duties conflicts and privilege sprawl are no longer visible in one report. That is exactly why the OWASP Non-Human Identity Top 10 and NIST control guidance both push organisations toward broader identity visibility rather than point-in-time system checks.

NHIMG’s Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts, which is a good proxy for the wider problem: teams often cannot review what they cannot see. In practice, audit evidence becomes less meaningful when entitlement reviews stop at ERP boundaries, because the user’s effective access is defined by the full stack of business applications, not one ledger system. In practice, many security teams encounter toxic access combinations only after an audit exception, fraud review, or incident has already exposed the cross-system path.

How It Works in Practice

Effective access reviews need to be scoped around business processes, not individual platforms. A finance approver in ERP may also hold approval rights in procurement, admin access in a SaaS reimbursement tool, and a support role in a workflow engine. Each entitlement may be acceptable on its own, but together they create excess privilege or a segregation-of-duties conflict. This is why current guidance suggests cross-application identity correlation, especially where users authenticate through SSO and inherit permissions across multiple systems.

Security and GRC teams should build reviews from identity data, role data, and application entitlements into a single access graph. The practical sequence is:

  • inventory all connected systems, including SaaS and shadow IT with business impact;
  • normalise identities so one person is matched across HR, IAM, ERP, and downstream applications;
  • map roles to business functions, then test combinations for SoD conflicts;
  • review privileged and exception-based access separately from standard user access;
  • evidence removals, compensating controls, and approver rationale for audit.

This is consistent with NIST SP 800-53 Rev 5 Security and Privacy Controls, which expects access enforcement and least privilege to be managed as an enterprise control, not a single-application activity. NHIMG’s Key Challenges and Risks section also highlights how excessive privileges and weak visibility compound over time. These controls tend to break down when organisations rely on disconnected application owners, because no one sees the full entitlement chain that creates effective privilege.

Common Variations and Edge Cases

Tighter cross-system review often increases administrative effort, requiring organisations to balance stronger SoD assurance against the cost of data integration and entitlement mapping. That tradeoff becomes visible in mergers, shared service models, and heavily customised ERP landscapes where access paths are inconsistent and role definitions are messy.

Current guidance suggests treating ERP as one control plane, not the control plane. In some environments, ERP remains the primary financial system of record, so it should still anchor reviews. But standalone ERP certification is not sufficient when the same user can trigger purchases in a procurement suite, alter records in a cloud CRM, or approve exceptions in a case-management tool. The more distributed the workflow, the less meaningful an ERP-only review becomes.

There is no universal standard for exactly how many systems must be included in every access review. The practical test is whether a reviewer can see the full path from identity to business action. Where that path crosses multiple platforms, add those systems to the certification scope and document the risk if integration is incomplete. For teams building a more complete program, NHIMG’s Ultimate Guide to NHIs is a useful reference point for lifecycle visibility, and the broader OWASP Non-Human Identity Top 10 reinforces why access must be understood across the environment, not in isolation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-4 Cross-platform access reviews support least privilege and access enforcement.
OWASP Non-Human Identity Top 10 NHI-01 Visibility gaps and entitlement sprawl are core non-human and enterprise identity risks.
NIST AI RMF Risk management requires understanding how system interactions create enterprise-wide exposure.
CSA MAESTRO MAESTRO emphasizes end-to-end governance across connected systems and workflows.
NIST Zero Trust (SP 800-207) 3.1 Zero Trust requires continuous evaluation of identity and authorization across resources.

Extend certification scopes across systems so reviewers validate effective access, not just ERP entitlements.