Manual reviews create risk because they are point in time, inconsistent, and hard to evidence across a full financial year. Email approvals and spreadsheet dumps can miss conflicts, delay remediation, and leave weak documentation for the board’s annual statement. Automated controls reduce that exposure by capturing access changes, approvals, exceptions, and remediation actions as they happen.
Why manual reviews become a Provision 29 evidence problem
Manual segregation of duties checks and user access review can satisfy the intent of control oversight, but they often fail on traceability. Under Provision 29, the issue is not only whether a review happened, but whether the organisation can show that access was governed consistently across the year, exceptions were identified, and remediation was completed in a way the board can rely on. Spreadsheet-based or email-based reviews tend to fragment that evidence chain, especially when ownership changes or reviewers apply different thresholds.
That matters because compliance risk builds when the control is treated as a periodic task instead of a managed process. A review that is complete on paper can still leave unresolved conflicts, stale access, or missing approval records if the evidence is scattered across inboxes and local files. NIST’s broader control guidance on auditability and account governance remains useful here, especially NIST Cybersecurity Framework 2.0, because Provision 29 depends on demonstrable governance rather than informal assurance. In practice, many teams discover control gaps only when they try to assemble a year-end statement, not when the access review itself is carried out.
How the compliance failure usually develops in practice
Manual SoD and access review processes usually fail through a familiar sequence. First, the organisation defines a review cadence, often monthly, quarterly, or annually. Then evidence is collected from spreadsheets, ticket notes, or exported user lists. Reviewers mark exceptions by hand, but the process may not record why an exception was accepted, whether the conflicted access was actually removed, or whether the approver had enough context to judge the risk. That creates a gap between review activity and provable control operation.
The practical weakness is consistency. One manager may challenge a privileged role, while another may accept the same pattern because the business owner is unavailable or the spreadsheet is incomplete. If access is provisioned, changed, or removed outside the review cycle, the process can miss short-lived but material exposures. If the evidence pack is assembled after the fact, teams may be unable to show a clean trail from request to approval to remediation.
- Manual review records often capture opinion, but not the underlying access state at the time of review.
- Exception handling is frequently undocumented, which makes later assurance difficult.
- Remediation may be delayed because the review owner and the access owner are not the same person.
- Aggregating results across business units is hard when each team uses a different template or file structure.
That is why automated workflows reduce compliance exposure: they preserve timestamps, approvers, exceptions, and closure actions as part of the operational record, rather than reconstructing them later. For broader control design and evidence expectations, NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls both reinforce the value of repeatable control operation and audit-ready records. Where manual reviews cannot preserve that chain reliably, the guidance breaks down at scale and during board-level attestation.
Where manual review still works, and where it stops being defensible
Tighter review processes often improve oversight but increase administrative overhead, so organisations have to balance scrutiny against the risk of inconsistent execution. A manual model can still be defensible in smaller environments with limited privileged access, stable role design, and very clear ownership of approval and remediation. It becomes far less defensible when access is frequent, roles are overlapping, or the control must support a formal annual statement that depends on complete and reproducible evidence.
The main edge case is not whether a manual review exists, but whether it can be relied on to detect and prove the full population of conflicts. A well-run manual review may be adequate for low-volume exceptions, but it is fragile when the organisation depends on it for broad-scale SoD enforcement across many systems or business units. Another common misstep is treating a signed spreadsheet as equivalent to control completion. Guidance versus consensus is still emerging on how much manual evidence is sufficient for modern assurance expectations, but there is broad agreement that point-in-time reviews are weaker than controls that capture the event trail as work happens.
For this reason, the practical test is whether the review process can survive an audit without reconstruction. If the answer depends on chasing approvers, reconciling files, or explaining undocumented exceptions, the process is already carrying compliance risk that should be treated as material.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST IR 8596 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV.RM-03 — Risk Management Strategy | Provision 29 risk is a governance and assurance problem requiring consistent control oversight. |
| Recommendation — Align access review governance to a repeatable risk strategy and retain evidence of exceptions and remediation. | ||
| CIS Controls v8 | 6.3 — Access Control Management | Manual SoD and access review processes are direct account-governance controls. |
| Recommendation — Automate access review records and revoke conflicting access promptly when exceptions are found. | ||
| NIST SP 800-63 | 5.6 — Identity Proofing and Records | The question turns on trustworthy identity and access records for audit and assurance. |
| Recommendation — Maintain authoritative access records that can substantiate reviewer decisions and revocations. | ||
| ISO/IEC 42001:2023 | A.5 — AI System Policy and Governance | If automation or AI is used in review workflows, governance and accountability must still be explicit. |
| Recommendation — Document oversight, accountability, and exception handling before using automated review support. | ||
| NIST IR 8596 | IR-4 — Incident Handling | Unresolved access conflicts and weak evidence can surface as control incidents needing remediation. |
| Recommendation — Triage unresolved access conflicts as control incidents and track them to closure with evidence. | ||
Practitioner Guidance
What to prioritise: Focus first on the controls that create the strongest audit exposure: privileged access, conflicting duties, and any review step where remediation is manual and delayed. If those areas cannot be evidenced cleanly, the annual statement is more vulnerable than the underlying access model.
What to verify: Check whether each review can produce a complete chain of evidence without manual reconstruction, including who reviewed, what was reviewed, what exception was accepted, and when the conflict was removed. If any of those elements depend on email searches or local spreadsheets, the process is not yet robust enough for reliable assurance.
Common mistake: Treating a completed review as proof of compliance when the organisation cannot show timely remediation or consistent reviewer judgment. In practice, the weakest point is often not the review itself but the gap between identifying a conflict and proving that it was resolved.
Practitioner takeaway: Provision 29 risk is usually created less by the existence of manual review than by the inability to prove control operation continuously and consistently across the reporting period.
Related resources from NHI Mgmt Group
- Why do manual access administration and fragmented identity data create compliance risk in complex identity environments?
- Why do manual user access reviews create compliance risk?
- Why do manual ID card processes create risk for access control and compliance?
- Why does AI governance create less risk for regulated deployments than ad hoc review processes?