By NHI Mgmt Group Editorial TeamBased on Pathlock: “Internal Controls to Prevent Fraud | Checklist” (December 26, 2025)

TL;DR: Internal controls reduce fraud, limit misuse, and improve accountability by combining preventive, detective, and corrective measures across financial and operational processes, according to Pathlock. The same control logic now applies to NHI, human access, and delegated workflows, where standing privilege and weak review cycles turn convenience into exposure.


At a glance

What this is: This is a controls-first analysis of how preventive, detective, and corrective measures reduce fraud and improve accountability across business processes and identity governance.

Why it matters: It matters because IAM, IGA, and PAM teams face the same governance problem the article describes: without clear checks and independent review, access becomes a business control gap, not just a security one.

By the numbers:

  • A 2022 KPMG Fraud Outlook survey of 642 senior executives and board members in the Americas found that 71% had experienced internal or external fraud in the last 12 months.

Context

Internal controls are the policies, procedures, and system checks that keep access, approvals, and records aligned with business intent. In identity programmes, the same idea shows up as segregation of duties, independent review, and least privilege, because uncontrolled access is often just control failure in another form.

The article's core argument is that controls should not be viewed as administrative drag. They are the mechanism that reduces fraud exposure, improves accountability, and gives organisations a repeatable way to detect and correct misuse before it becomes a larger loss.


Key questions

Q: What breaks when no single person is allowed to own an entire transaction or access path?

A: When one person can initiate, approve, record, and reconcile the same process, fraud and misuse become much easier to hide. The control fails because there is no independent check on the action, so errors and abuse can move through normal workflow without challenge or timely detection.

Q: Why does weak access control increase the risk of unauthorized access and misuse?

A: Weak access control increases risk because broad permissions make it easier for stolen credentials, mistaken assignments, or insider misuse to reach sensitive systems. When authentication is weak and privileges are excessive, an attacker or unauthorized user can move further than intended. Tight role design and least privilege reduce the blast radius and make compromise harder to turn into material impact.

Q: How do organisations know whether internal controls are actually working?

A: They work when activity, approval, and reconciliation consistently line up. Look for fewer exceptions, faster detection of anomalies, clean audit trails, and control owners who can explain why an action was allowed. If access grants exist without business justification, or if reviews never change entitlements, the controls are present in name only.

Q: What should teams do when a control failure is found in an access or approval process?

A: They should correct the process, not just record the exception. That means fixing the approval chain, limiting who can perform conflicting duties, and confirming the same failure does not reappear in later reviews. Corrective action only works when it changes the operating model, not just the paperwork.


Technical breakdown

Why segregation of duties still matters for access governance

Segregation of duties works by ensuring no single person can initiate, approve, record, and reconcile the same transaction or access path. In identity terms, that principle prevents one role from both requesting and certifying the same privilege, which is how misuse hides inside normal operations. When the same actor can create, approve, and review access, the control environment depends on trust instead of evidence. That is why internal controls are not just financial safeguards. They are a governance mechanism that breaks concentration of power and makes abnormal behaviour easier to detect.

Practical implication: map every privileged workflow to the point where independent review must break the chain of control.

How preventive, detective, and corrective controls map to identity risk

Preventive controls stop bad access before it is granted, detective controls identify misuse after it happens, and corrective controls close the loop by fixing the process that failed. In IAM and NHI governance, that means entitlement design, monitoring, and lifecycle repair cannot be treated as separate disciplines. A weak preventive layer increases the load on detective controls, while weak corrective action lets the same failure recur. The article's structure mirrors a mature control model: stop what you can, detect what you miss, and correct the root cause so the issue does not repeat.

Practical implication: build access governance as a three-stage control loop rather than a single approval step.

Why continuous monitoring is the real test of control effectiveness

A control is only meaningful if it can reveal variance from expected behaviour. The article's examples of reconciliations, audits, and variance analysis show that controls are not static policies but operating checks against actual transactions. For identity teams, the equivalent is comparing access state, usage, and ownership over time. If a privileged account, service account, or delegated workflow is never independently reviewed, the organisation has a documentation problem, not a control. Effective governance depends on evidence that the control ran and that exceptions were investigated.

Practical implication: verify that access reviews, logs, and reconciliations produce actionable exceptions rather than routine sign-off.


Threat narrative

Attacker objective: The objective is to move money, alter records, or misuse assets while staying inside a workflow that lacks effective independent oversight.

  1. Entry occurs when excessive or unchecked access creates a path for fraudulent transactions, misuse, or unauthorised changes. The article's fictitious vendor scheme shows how access that does not match job responsibilities becomes the opening condition.
  2. Escalation follows when one person can create, approve, or reconcile the same process without independent review. That concentration of authority lets misuse blend into normal workflow and avoids immediate challenge.
  3. Impact appears as financial loss, inaccurate reporting, reputational harm, and weaker accountability across the process. Once the control gap is established, the same workflow can be reused until detection or audit interrupts it.
  • Zacks breach claim 2025: A hacker leaked 12 million Zacks accounts in 2025, claiming domain admin access in 2024; HIBP verified the data, Zacks has not confirmed.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Internal controls are the governance layer that turns identity from a permission problem into an accountability system. The article is written for finance and operations, but the underlying pattern applies equally to IAM, IGA, and PAM: access without review becomes an open path for misuse. In practice, controls are what make ownership, approval, and reconciliation auditable rather than assumed, and that is why identity programmes fail when control design is treated as optional.

Segregation of duties is the clearest bridge between financial controls and identity controls. The article shows that no one should receive, record, deposit, and reconcile the same funds. The identity equivalent is no single actor creating, approving, and certifying the same entitlement or delegated workflow. That is the same control logic across human access and NHI governance, and it remains the best test for whether privilege design is truly bounded.

Continuous monitoring matters because static approval does not prove control effectiveness. Reconciliations, audits, and variance analysis are only useful when they surface exceptions that someone must explain. That is the same standard identity teams should apply to privileged access, service accounts, and delegated workflows: if reviews never find anything unusual, the programme may be under-observing rather than well-controlled.

Control culture is the difference between policy and practice. The article is explicit that documentation without leadership and consistent enforcement is just paperwork. For identity security, that means access governance only works when managers, auditors, and system owners actually honour the process. A named concept here is control drift, the point at which written checks remain in place while real enforcement quietly weakens.

Fraud prevention and identity governance now share the same operating assumption: trust must be earned through evidence, not granted by convenience. The article's message is not that controls slow work down. It is that unchecked speed is what creates loss, whether the asset is cash, a record, or a privileged identity. Practitioners should treat every control exception as a governance signal, not an administrative annoyance.

From our research library:

What this signals

Control drift is the real risk signal: when written procedures still exist but independent review is skipped, organisations have a governance problem rather than a policy problem. Identity teams should watch for workflows where approval, execution, and reconciliation have quietly collapsed into the same role, because that is where misuse becomes routine.

The practical lesson is that internal controls only matter when they are designed to expose exceptions. For IAM, IGA, and PAM teams, that means reviewing whether access reviews, reconciliations, and corrective actions are producing evidence that someone actually checked the work and closed the loop.


For practitioners

  • Map critical workflows to segregation points Identify where the same person or role can request, approve, execute, and reconcile a transaction or access change. Break that chain so no single actor controls the full path end to end.
  • Separate access creation from access certification Ensure the person who grants privilege is not the same person who later certifies it. This applies to human accounts, service accounts, and delegated workflows where review independence is often weakest.
  • Require independent reconciliation of privileged activity Compare entitlement records, actual usage, and approval evidence on a fixed cadence. Investigate exceptions that show dormant access, unapproved privilege growth, or unresolved ownership.
  • Document and enforce corrective actions for control failures When a review finds a mismatch, close the gap with a process change, not just a one-time exception note. Track whether the same issue reappears in later reviews or audits.

Key takeaways

  • Internal controls are not paperwork when they prevent one person from controlling an entire process from start to finish.
  • The article shows that fraud risk rises when approvals, records, and reconciliation sit with the same role or team.
  • For identity programmes, the control lesson is to separate privilege creation, review, and reconciliation so misuse has an independent checkpoint.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about controlling who can do what and proving that access is governed.
Recommendation — Apply PR.AA-05 to separate access granting, review, and reconciliation across sensitive workflows.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeLeast privilege underpins the article's guidance on limiting access to only what a role needs.
Recommendation — Enforce AC-6 so users and systems cannot retain broader access than their duties require.
CIS Controls v8CIS-5 — Account ManagementThe article's access and oversight themes align with account lifecycle and responsibility control.
Recommendation — Use CIS-5 to review account ownership, role fit, and conflicting duties across business processes.
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIThe article's logic extends to non-human accounts when access exceeds operational need.
Recommendation — Audit NHI privileges for scope creep and revoke access that is broader than the workflow demands.

Key terms

  • Internal Controls: The broader set of mechanisms, rules, and procedures used to safeguard operations, support accountability, and detect or correct problems. In identity governance, they include approvals, monitoring, reconciliation, audits, and training, not just permission boundaries.
  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Preventive Controls: Preventive controls block or constrain risky actions before they are completed. In ERP environments, they can stop unauthorized transactions, enforce approval paths, or restrict configuration changes, making them more effective than detective-only controls when business processes move quickly.
  • Detective Control: A control that identifies problems after they occur or after a process has moved outside expected bounds. In identity governance, detective controls include logging, audit review, and reconciliation that reveal whether SoD is actually being enforced.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org