TL;DR: SOX compliance failures often come down to access control gaps, not accounting errors, and Protiviti’s 2024 report says 44% of organisations face the most audit challenges in IT access controls while 24% report a significant expansion in SOX scope. Spreadsheet-based reviews and manual evidence collection leave auditors with weak proof and delayed revocations.
At a glance
What this is: This is an analysis of SOX compliance through the lens of identity and access governance, showing that access reviews, segregation of duties, and audit evidence are the controls auditors test most closely.
Why it matters: It matters because SOX failures usually surface as identity governance failures, so IAM, IGA, PAM, and lifecycle teams need controls that produce defensible evidence, not just policy statements.
By the numbers:
- 44% identify IT access controls as the area with the most audit challenges and deficiencies.
- 24% of respondents report a significant expansion in SOX scope over the past year.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
- 17 minutes
👉 Read Oleria Security's analysis of SOX access controls and identity governance
Context
SOX compliance is fundamentally an identity governance problem because auditors are asking who had access, why they had it, and whether that access was still appropriate when the control was tested. In practice, the hardest part is not writing policy but proving that access reviews, segregation of duties, and deprovisioning actually happened.
The article frames a familiar enterprise pattern: spreadsheet-driven access certification, manual evidence gathering, and delayed revocation create audit risk even when teams believe the controls exist. That is typical in organisations where identity data is fragmented across ERP, financial systems, and cloud platforms.
For IAM and IGA teams, the issue is less about abstract compliance and more about whether controls can survive auditor scrutiny. If the programme cannot tie each access decision to a timestamped review, a reviewer, and an executed outcome, SOX becomes a documentation exercise instead of control assurance.
Key questions
Q: What breaks when SOX access evidence still lives in spreadsheets?
A: Spreadsheets break traceability. They make it harder to prove who reviewed access, when the review happened, what was approved, and whether remediation actually occurred. That creates more audit follow-up, more manual reconciliation, and more risk that the evidence trail will not stand up under scrutiny.
Q: Why do access controls matter so much for SOX compliance?
A: Because access is where financial control failures often start. If the wrong people can create accounts, approve transactions, or modify system settings, the accuracy of reporting becomes untrustworthy. Access controls therefore support both compliance and the integrity of the underlying financial process.
Q: How do organisations know if access certification is actually working?
A: Look for shrinking numbers of standing privileges, faster revocation after review decisions, and fewer orphaned or overprivileged accounts over time. If campaigns finish but access sprawl remains unchanged, the programme is producing documentation rather than governance. Working certification changes the entitlement baseline, not just the audit record.
Q: Who is accountable when SOX access controls fail?
A: Accountability sits with control owners, system owners, and executives who sign off on financial reporting controls. SOX expects clear ownership, documented assessments, and timely remediation when gaps appear. If ownership is vague, the program may pass a checklist but still fail an audit.
Technical breakdown
Why SOX 404 puts identity controls at the centre of audit evidence
Section 404 requires management to assess and auditors to attest to internal controls over financial reporting. That makes identity controls central because access rights determine whether the right person can initiate, approve, or alter financially material activity. Logical access, change management, and computer operations are the most common IT general controls examined, but access is the one that most often exposes whether the control environment is actually working. The technical test is not whether a control exists in policy. It is whether the organisation can show who had access, how it was granted, and whether the approval path still matched business need at the time of review.
Practical implication: Map every in-scope financial system to named access owners, review cadences, and evidence sources before auditors ask for them.
How access certification fails when reviewers lack decision context
Access certification is meant to confirm that entitlement still matches role, duty, and business need. In practice, the process fails when reviewers receive static lists without usage history, peer context, or risk indicators. That turns certification into rubber-stamping. Auditors look for evidence that the reviewer had enough context to make a defensible decision and that revocations were executed in the source system, not just noted on a spreadsheet. A certification process that cannot show reviewer identity, timestamp, rationale, and follow-through creates a gap between governance intent and operational reality.
Practical implication: Feed certification workflows with live entitlement data, last-login context, and revocation tracking rather than flat exports.
How segregation of duties becomes an identity problem across systems
Segregation of duties is the rule that no single identity should control conflicting steps in a financial process. Modern SoD failures usually emerge because access accumulates across ERP, finance, and cloud systems until a user can both initiate and approve transactions. This is not a one-time design issue. It is a lifecycle issue created by role change, inherited access, and exception drift. The control only works when SoD rules are continuously evaluated against current entitlements and exceptions are documented with business justification and compensating controls. Without that, the organisation discovers conflicts only when auditors or incidents expose them.
Practical implication: Continuously evaluate SoD conflicts across systems and tie exceptions to approved compensating controls before audit season.
Threat narrative
Attacker objective: The objective is not just unauthorised access but the ability to operate in financially material systems without detection, challenge, or defensible evidence.
- entry: The control failure begins when users, service accounts, or privileged identities retain access to financial systems after a role change or departure, or when access is granted through poorly governed manual workflows.
- escalation: Those stale or excessive entitlements allow the same identity to accumulate conflicting permissions across systems, creating SoD violations and weakening approval boundaries.
- impact: The result is unreconciled access, weak audit evidence, and potential material weakness disclosure when management cannot prove controls worked as intended.
Breaches seen in the wild
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
- Cisco DevHub NHI breach — IntelBroker exploited exposed Cisco credentials, API tokens and keys in DevHub.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
SOX is an identity governance regime disguised as a financial reporting law. The article is right to centre access reviews, segregation of duties, and audit trails because those controls determine whether the financial control environment can be proven. In practice, the identity layer is where management certification either becomes defensible or collapses into paperwork. For practitioners, SOX readiness starts with access truth, not audit narratives.
Manual access certification creates proof gaps even when the underlying review is sincere. A spreadsheet can record that a review happened, but it often cannot prove the reviewer had current context, that all in-scope identities were covered, or that revocations executed in the system of record. That makes the control vulnerable to challenge during Section 404 testing. The implication is that evidence quality, not review volume, is the real audit signal.
Segregation of duties is a lifecycle problem, not a static rule set. Users accumulate conflicting access as roles change, projects expand, and exceptions linger. That means SoD controls must be evaluated continuously across the identity lifecycle, including joiner-mover-leaver events and inherited access across systems. Practitioners should treat SoD drift as an ongoing governance condition, not a pre-audit cleanup task.
Access evidence becomes the control when systems are fragmented. Financial applications, ERP platforms, databases, and cloud services each produce different logs, retention periods, and approval artefacts. The governance gap is not the absence of policy, but the inability to assemble a trustworthy timeline of who approved what and when. The practical conclusion is that auditability must be designed into identity operations, not reconstructed under deadline.
Continuous control monitoring is the only defensible response to changing entitlements. The article’s strongest point is that annual certification is often too blunt for high-risk systems. When access changes throughout the year, annual assurance cannot keep pace with the exposure window. Practitioners should view continuous monitoring as the baseline for financially material identities, especially where privilege and approval rights can converge.
From our research:
- 44% identify IT access controls as the area with the most audit challenges and deficiencies, according to the 2024 ESG Report: Managing Non-Human Identities.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to the 2024 ESG Report: Managing Non-Human Identities.
- For lifecycle governance context, see NHI Lifecycle Management Guide for the provisioning, rotation, and offboarding discipline that audit teams increasingly expect to see.
What this signals
Access review quality is becoming a board-level evidence problem. As SOX scope expands and audit expectations harden, IAM teams need evidence pipelines that can survive challenge without manual reconstruction. The practical shift is toward continuously queryable identity data and away from end-of-quarter spreadsheet assembly.
Lifecycle control is the hidden dependency in SOX readiness. If joiner-mover-leaver events, role changes, and privileged access changes are not tied into the same governance workflow, certification will always lag reality. That is why programmes should treat NHI Lifecycle Management Guide principles as relevant even in a human identity context when access spans service accounts and application ownership.
Auditability now intersects directly with identity architecture. Teams that align access governance to NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls will be better positioned to demonstrate control effectiveness without over-reliance on manual evidence collection.
For practitioners
- Inventory all in-scope financial identities Build a current register of every user, privileged account, and service account with access to financial reporting systems, then reconcile it against HR, IAM, and application owners.
- Attach decision context to every access review Give reviewers last-login data, entitlement risk, peer-role comparisons, and business justification so they can make defensible decisions instead of approving flat lists.
- Track revocations through system execution Do not stop at approval. Verify that access removals, role changes, and privilege reductions were executed in the source system and timestamped for audit.
- Continuously monitor segregation of duties conflicts Evaluate SoD rules whenever access changes, not only before audit, and document exceptions with named approvers and compensating controls.
- Centralise audit evidence by control Store certifications, provisioning records, SoD exceptions, and change logs in a queryable repository so auditors can trace each control from decision to outcome.
Key takeaways
- SOX compliance is primarily an identity governance problem because access, approvals, and evidence determine whether financial controls can be proven.
- The biggest audit weakness is not the existence of access reviews but the quality of the proof behind them, especially when reviews are spreadsheet-driven.
- Continuous SoD monitoring, lifecycle-linked deprovisioning, and traceable evidence are the controls that turn SOX from an annual scramble into an operational discipline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | SOX access governance aligns with managing and reviewing entitlements. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege and access enforcement underpin SOX control effectiveness. |
| ISO/IEC 27001:2022 | A.5.15 | Access control governance is directly relevant to SOX evidence quality. |
| CIS Controls v8 | CIS-5 , Account Management | Account management controls map closely to certification and deprovisioning gaps. |
Use CIS-5 to inventory, review, and remove access across financial systems on a fixed cadence.
Key terms
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
- Audit Evidence: Audit evidence is the record set used to prove that access was authorised, limited, and revoked according to policy. For modern identity programmes, evidence must come from runtime logs, approval events, and lifecycle records rather than from manual spreadsheets assembled after the fact.
- Material weakness: A material weakness is the most severe category of internal control failure, indicating a reasonable possibility of a material misstatement or a serious breakdown in trust. For identity teams, the parallel is a control environment so weak that access evidence, approvals, or lifecycle operations can no longer be relied upon.
What's in the full article
Oleria Security's full post covers the operational detail this analysis intentionally leaves for the source:
- A practical SOX access certification checklist for financial systems, including the evidence fields auditors expect to see.
- A control-by-control mapping of access review, segregation of duties, and audit trail requirements to identity operations.
- A walkthrough of how IGA automation changes the evidence burden for joiner-mover-leaver and privileged access workflows.
- A ready-to-use remediation checklist for common access control deficiencies before audit season.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on August 14, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org