By NHI Mgmt Group Editorial TeamBased on C1.ai: “Five Ways to Streamline SOX Compliance with C1” (August 20, 2025)

TL;DR: C1.ai says SOX compliance breaks down when access reviews, evidence collection, and separation of duties still depend on manual spreadsheets and fragmented systems. The real issue is identity governance maturity: controls drift faster than teams can certify them.


At a glance

What this is: This is a SOX compliance post arguing that audit readiness depends on identity governance, not manual spreadsheet workflows.

Why it matters: It matters because IAM, IGA, and PAM teams are often the only functions able to centralise access evidence, enforce SoD, and keep SOX controls auditable across changing environments.

👉 Read C1.ai's post on streamlining SOX compliance with identity governance


Context

SOX compliance becomes an identity governance problem when teams can no longer answer a basic question quickly and accurately: who has access to what, and why. In practice, the difficulty is not the regulation itself but the control environment around user access, separation of duties, and evidence collection.

The article centres on a familiar governance failure mode. When access data is scattered across SaaS, cloud, and on-premise systems, manual review cycles become slow, error-prone, and hard to defend to auditors. That makes SOX less a documentation exercise than a continuous identity control problem.


Key questions

Q: What breaks when SOX access reviews are run with spreadsheets and emails?

A: Manual reviews often miss incomplete user lists, unclear entitlement names, slow reviewer decisions, and weak remediation tracking. Evidence becomes scattered across inboxes, tickets, and spreadsheets, which makes audits harder to defend. The bigger failure is control drift: rejected access may remain active, exceptions may never expire, and reviewers may not know the business context.

Q: Why does separation of duties become hard to prove in SOX programmes?

A: SoD becomes hard to prove when role and entitlement data is scattered across multiple systems and exceptions are tracked inconsistently. The control depends on seeing incompatible access combinations in one place. Without that view, teams can describe the policy, but they cannot demonstrate that it is continuously enforced.

Q: How do you know if SOX control evidence is actually working?

A: Evidence is working when an auditor can reconstruct a change from start to finish without relying on informal explanation. That means the organisation can show the reason for the change, the approver, the implementation date, and the affected system or entitlement. Missing any of those pieces usually means the control is weaker than it appears.

Q: What should identity teams do when audit evidence is spread across systems?

A: Build a single evidence chain for review approvals, remediation actions, and ownership records. That allows auditors to trace each control decision back to the identity event that triggered it, instead of forcing the organisation to reassemble the story after the fact.


Technical breakdown

Why manual SOX access reviews fail at scale

SOX access reviews depend on a complete and current picture of who can access financial systems, application controls, and privileged functions. Manual processes break because reviewers work from spreadsheets, screenshots, and exported lists that are already stale by the time the review closes. The problem is not only labour cost. It is that the control outcome depends on humans reconciling fragmented identity data after access changes have already occurred. In fast-changing estates, the review becomes evidence of effort rather than evidence of control.

Practical implication: replace spreadsheet-based recertification with a governed access-review workflow that can pull current entitlement data from source systems.

How separation of duties becomes a governance signal

Separation of duties, or SoD, is the control that prevents one identity from combining incompatible permissions, such as request, approve, and pay. In SOX environments, SoD is only as strong as the inventory of roles and entitlements behind it. Once role assignment data lives across multiple systems, SoD violations can hide in role drift, temporary exceptions, and inherited access. That makes SoD a governance signal as much as a control requirement: if the organisation cannot continuously see and explain conflicting access, it cannot prove the control is operating.

Practical implication: maintain a live SoD matrix across applications, roles, and exceptions so conflicts are visible before audit testing begins.

Why centralised evidence matters for audit defensibility

SOX audits require evidence that controls are designed and operating effectively, not just that a team claims they are. Centralised evidence matters because auditors need time-stamped, consistent records of review completion, remediation, approval, and control ownership. When evidence sits in emails, screenshots, and ad hoc spreadsheets, the organisation spends time reconstructing the control story instead of proving it. The technical issue is traceability: without a single evidence chain, the organisation cannot reliably show that access decisions, SoD checks, and remediation actions were linked.

Practical implication: store access-review artefacts, approvals, and remediation records in a system of record that preserves timestamps and ownership.


Threat narrative

Attacker objective: The attacker objective is to exploit weak access governance to reach financial workflows or manipulate controls without timely detection.

  1. Entry begins with access sprawl after mergers, system growth, or decentralised provisioning, which makes financial-system privileges hard to inventory accurately.
  2. Credential or entitlement abuse follows when overbroad access, conflicting roles, or unreviewed accounts persist across business-critical systems.
  3. Impact appears as weaker internal controls, audit delays, and a higher chance that segregation-of-duties violations or material control gaps go undetected.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

SOX has become an identity governance discipline because the control surface is the account and entitlement estate. Manual evidence collection does not fail mainly because it is slow. It fails because it cannot keep pace with role churn, system sprawl, and review fatigue across the identity lifecycle. Practitioners should treat access governance as the control plane for SOX, not a back-office reporting task.

Separation of duties is only enforceable when identity data is normalised across systems. If SaaS, cloud, and on-premise entitlements are managed in different places, SoD is reduced to a point-in-time claim that cannot survive remediation pressure or auditor scrutiny. The governance lesson is that control precision depends on identity visibility, not on how carefully the spreadsheet is maintained.

Automated evidence is not a convenience layer, it is the difference between defensible control and reconstructed control. Timestamped review records, approval chains, and remediation histories create the audit trail that manual processes cannot sustain at scale. For SOX programmes, the decisive question is whether identity evidence is generated as controls operate or assembled after the fact.

Identity control drift: This is the condition where access, roles, and exceptions change faster than review and certification cycles can absorb them. In SOX environments, drift turns least privilege and SoD into aspirations rather than enforceable states. Practitioners should measure how quickly identity changes outpace certification, because that gap defines audit exposure.

What this signals

Identity control drift: SOX programmes fail when access changes outpace the cadence of review and certification. The practical test is whether the organisation can detect and resolve entitlement changes before they become an audit exception.

When identity and evidence data are fragmented, the organisation is forced to reconstruct control performance instead of operating it. That shifts SOX from continuous governance to intermittent reporting, which is exactly where auditors find weakness.


For practitioners

  • Centralise access review inputs Pull entitlement data from SaaS, cloud, and on-premise sources into one governed review workflow so reviewers are working from current access state, not exported snapshots.
  • Maintain a live SoD matrix Map incompatible duties across applications and privileged roles, then track exceptions in the same system that records remediation and approval.
  • Time-stamp every audit artefact Preserve review completion, approval, and remediation records with immutable timestamps so the audit trail survives handoffs and quarter-end pressure.
  • Track access drift between review cycles Measure how many roles, entitlements, and exceptions changed after the last certification so you can see where governance is falling behind.

Key takeaways

  • SOX compliance is really an identity governance problem because access review quality, SoD enforcement, and evidence traceability determine whether controls can be defended.
  • Manual spreadsheets and fragmented systems create drift between actual access and what reviewers can certify, which weakens audit readiness.
  • The strongest response is to centralise entitlement visibility, preserve immutable evidence, and treat identity change as a continuous control signal.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSOX access governance depends on limiting and reviewing access to financial controls.
Recommendation — Apply AC-6 to enforce least privilege and challenge standing access during SOX reviews.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about entitlement visibility and access governance.
Recommendation — Use PR.AA-05 to maintain current entitlement inventories and review access against SoD rules.
CIS Controls v8CIS-5 — Account ManagementSOX review and remediation depend on account lifecycle control and ownership clarity.
Recommendation — Use CIS-5 to track account ownership, remove stale access, and document remediation.
ISO/IEC 27001:2022A.5.15 — Access controlSOX compliance relies on formalised access control governance and evidence.
Recommendation — Implement A.5.15 to define and enforce access approval, review, and exception handling.

Key terms

  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Access Recertification: Access recertification is the periodic review of user or account permissions to confirm that access is still justified. It is useful, but it is not enough on its own because it reacts after entitlements already exist, which is why lifecycle governance must reduce the volume of exceptions before review time.
  • Identity Governance: Identity governance is the set of controls that defines who approves access, who owns it, how it is reviewed, and when it is removed. In practice, it turns identity management from a deployment task into a durable control system that can withstand audits, organisational change, and operational growth.
  • Audit Evidence: Audit evidence is the record set used to prove that access was authorised, limited, and revoked according to policy. For modern identity programmes, evidence must come from runtime logs, approval events, and lifecycle records rather than from manual spreadsheets assembled after the fact.

What's in the full article

C1.ai's full blog covers the operational detail this post intentionally leaves for the source:

  • Walkthrough of automated evidence collection across connected systems
  • How review campaigns can be structured for business-critical access certification
  • Examples of continuous monitoring dashboards for SOX control oversight
  • Practical collaboration flow between system owners, compliance teams, and auditors

👉 The full C1.ai article covers automated evidence collection, access review workflows, and continuous monitoring details.

Deepen your knowledge

NHI governance, identity lifecycle management, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org