Teams often treat manual reviews as sufficient when they are actually prone to missed accounts, misreported permissions, and rubber-stamping. Spreadsheets and ad hoc tracking do not scale well as users, roles, and integrations increase. They also leave weak audit trails, which makes it harder to prove review history, justify decisions, and detect excessive access in time.
Why Manual Access Reviews Break Down in Complex ERP Environments
Manual certification tends to fail in ERP estates because access is rarely expressed as a simple user-to-role mapping. Large organisations accumulate layered roles, temporary assignments, delegated approvals, integration accounts, and business exceptions that are hard to interpret from a spreadsheet alone. That creates a governance gap: reviewers may approve what they cannot fully reconstruct, and audit teams may later find that the decision trail does not explain why access was accepted.
In complex ERP environments, the real problem is not just volume but context loss. A reviewer may see a job title or cost centre and miss inherited privileges, cross-module entitlements, or access created through connected applications. The result is often that review activity becomes evidence of completion rather than evidence of informed decision-making. For identity-heavy systems, that is especially dangerous because access can persist long after the business reason has changed, and manual tracking rarely keeps pace with role sprawl. The OWASP Non-Human Identity Top 10 is useful here because ERP review failures often intersect with machine and integration identities as well as human access. In practice, teams discover the mismatch between policy and actual privilege only after an audit exception, a failed recertification, or a downstream incident.
How Manual Reviews Are Supposed to Work, and Where They Usually Fail
A good access review process should answer three questions: who has access, why they have it, and whether that access still matches the current business need. In ERP systems, that sounds straightforward until the environment includes derived roles, shared service accounts, batch jobs, interface users, and cross-functional approvals. Reviewers then rely on exports, manager memory, and local knowledge, which means the process depends more on people than on controlled evidence.
The strongest practice is to separate entitlement data from interpretation. Teams should make the review population explicit, include role inheritance and indirect grants, and preserve the rationale for each approval or removal. Where access originates in workflows, account ownership and approval authority should be traceable end to end. That matters because ERP reviews often miss hidden privilege paths: a user may look ordinary at the top layer but still inherit sensitive financial, procurement, or master-data permissions underneath.
- Review the effective privilege set, not just the named role.
- Include non-human and interface accounts in the same governance cycle.
- Require an auditable reason for each exception, not just an approval tick.
- Reconcile terminated, transferred, and temporarily elevated access against actual system state.
The NHI Management Group’s Ultimate Guide to NHIs is relevant because ERP access reviews often break down exactly where human and machine identities intersect. These controls tend to break down when the environment uses many inherited roles and outside integrations because reviewers cannot reliably reconstruct the true access path from static exports alone.
Common ERP Edge Cases That Make “Passed Review” Misleading
Tighter review thresholds often increase operational load, requiring organisations to balance speed against certainty. That tradeoff becomes visible in ERP systems where not every access item should be judged the same way. A read-only report role is not equivalent to a posting role, and a human user is not equivalent to a scheduler or middleware account that can move transactions at scale.
Best practice is evolving toward risk-based review rather than equal treatment of every entitlement. Current guidance suggests focusing human attention on high-impact combinations such as finance posting, vendor master changes, payment runs, privileged admin functions, and access that crosses environments. Low-risk access can still be sampled, but high-risk access needs stricter evidence of business need and tighter ownership. For a useful NHI-specific lens on why this matters, the Ultimate Guide to NHIs — Key Challenges and Risks helps explain why visibility and rotation failures often persist even when review processes appear complete.
One more edge case is that manual reviews can look successful while leaving stale access in place for months. That happens when the review asks managers to validate names rather than entitlements, or when exceptions are approved without a required expiry date. The most reliable signal is not whether the review was completed on time, but whether it actually removed unneeded access and produced a defensible record of why the remaining access was retained.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Manual ERP reviews are an access control practice that must remove excess rights. |
| Recommendation — Enforce periodic access reviews and remove unnecessary ERP privileges promptly. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication, and Access Control | ERP recertification depends on accurate identity and access governance. |
| GV.RM — Risk Management Strategy | Risk-based review is needed for high-impact ERP entitlements and exceptions. | |
| Recommendation — Maintain authoritative access records and validate effective permissions during recertification. Prioritise high-risk ERP access for stricter review and exception handling. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory and Ownership | ERP reviews often miss service and integration accounts that need clear ownership. |
| NHI-03 — Least Privilege and Access Scope | Excessive inherited ERP access is the core review failure mode. | |
| Recommendation — Inventory every ERP non-human account and assign accountable ownership. Trim inherited ERP permissions to the minimum access needed for each role. | ||
Practitioner Guidance
What to prioritise: Treat indirect and inherited access as the first problem, not the last one. If the ERP review does not show effective permissions, ownership, and exception history in one place, the review is only partially trustworthy.
What to verify: Check whether reviewers can distinguish temporary access, delegated approval paths, shared accounts, and interface identities. If they cannot, the process is likely certifying a record extract rather than certifying actual privilege.
Decision rule: If an entitlement can initiate payments, alter vendor data, post financial entries, or drive automated transactions, require stronger evidence than managerial acknowledgement alone. Those items should be escalated for technical validation or removal when the business justification is unclear.
What practitioners underestimate: Audit defensibility depends on the quality of the entitlement model as much as on the approval log. A clean approval trail does not compensate for missing inherited access, stale role mapping, or disconnected service accounts.
Practitioner takeaway: Manual access reviews are only useful when the organisation can prove it reviewed the real privilege set, not just the visible one.
Related resources from NHI Mgmt Group
- What do teams get wrong about quarterly access reviews and manual joiner mover leaver processes?
- What do teams get wrong about manual user access reviews for shared file repositories?
- What do security teams get wrong about access reviews in hybrid ERP and cloud environments?
- What do teams get wrong about access reviews in regulated healthcare environments?