TL;DR: Repeated access reviews do not reduce segregation of duties risk when the same conflicts return quarter after quarter; SafePaaS argues the real gap is risk closure, not review frequency. The broader lesson is that governance must prevent conflicts before provisioning, route exceptions to owners, and track remediation so risk actually changes over time.
NHIMG editorial — based on content published by SafePaaS: Automated access governance is the missing risk-closure layer
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed and 26% suspected.
Questions worth separating out
Q: How should security teams detect segregation of duties conflicts that matter in practice?
A: They should correlate assigned entitlements with actual activity across systems, not just rely on role definitions.
Q: Why do access reviews often fail to reduce real risk?
A: Access reviews often fail when they produce evidence without changing the underlying entitlement state.
Q: What should organisations measure instead of review completion rates?
A: They should measure unowned access, standing privilege, and the time between entitlement change and governance action.
Practitioner guidance
- Shift high-risk SoD checks left Evaluate proposed access against conflict rules before provisioning, especially for journal posting, payment release, vendor maintenance, and bank-data changes.
- Review entitlements, not just roles Show reviewers the effective privileges, sensitive access, and business context underneath each role so they can make a defensible decision.
- Create a closed-loop exception workflow Route every conflict to an accountable owner with a due date, mitigation option, and final disposition of prevented, removed, mitigated, or accepted.
What's in the full article
SafePaaS's full analysis covers the operational detail this post intentionally leaves for the source:
- A deeper breakdown of how policy-based access control evaluates SoD and sensitive-access rules before provisioning.
- A fuller description of remediation states, owner routing, and evidence retention across request, approval, and closure.
- Coverage of how access governance connects with application-change and transaction monitoring across ERP processes.
- Implementation detail on coverage gaps across SaaS, legacy, and locally administered applications.
👉 Read SafePaaS's analysis of automated access governance and risk closure →
Access reviews keep missing risk closure: what changes for IAM teams?
Explore further
Risk closure, not review frequency, is the real governance metric. Completing more certifications does not matter if the same segregation of duties conflicts reappear unchanged. The discipline has to measure whether exposure is prevented, removed, mitigated, or formally accepted, because only those outcomes change the risk state.
A few things that frame the scale:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
- Enterprises that have experienced a compromised NHI averaged 2.7 separate incidents in the past 12 months, which shows how quickly one governance failure becomes multiple exposures.
A question worth separating out:
Q: Why do non-human identities complicate privileged access governance?
A: Non-human identities complicate privileged access because they often act faster, more frequently, and at greater scale than humans. They may also rely on long-lived secrets, broad scopes, or automation paths that are hard to trace after the fact. Governance must therefore cover lifecycle, scope, and evidence, not just authentication.
👉 Read our full editorial: Automated access governance is the missing risk-closure layer