Financial institutions should run regular, role-aware access reviews that verify each user still needs their current permissions, especially where teller platforms support granular access and staff roles change often. The review should cover dormant accounts, excessive access, and sensitive financial functions. Strong governance means combining timely recertification, revocation of stale access, and auditable evidence so compliance checks are defensible and security gaps do not accumulate.
Why role-aware reviews matter more than simple recertification
When teller platforms expose granular permissions, the real control question is not whether a user has access, but whether each permission still matches the user’s current duties. Frequent role changes make static approvals unreliable, because access that was appropriate last month may now create unnecessary exposure. That is why review design has to be tied to job function, entitlement scope, and business context rather than a generic name check.
In practice, the review should treat a teller, supervisor, relief staff member, and operations user as different access profiles even if they share the same application. Granular permissions make overprovisioning easier to miss, especially when teams rely on inherited access or temporary exception paths that were never fully removed. A strong process spots where a legitimate role move has left behind stale entitlements, dormant accounts, or access to sensitive financial functions that no longer has a clear business owner.
That approach is supported by NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives and NHI Lifecycle Management Guide, both of which emphasise auditability, recertification, and removal of stale access as part of governance discipline.
How to structure access reviews around changing teller roles
The most effective model is a role-aware review matrix that maps each entitlement to a business function, approval owner, and review cadence. That lets reviewers confirm not only whether the person is still employed, but whether the permission is still justified for the current desk, branch, shift pattern, or escalation path. Where access is highly granular, reviewers should sample for combinations that create hidden capability, not just look at single permissions in isolation.
- Review all privileged or sensitive teller functions separately from baseline transaction access.
- Flag dormant accounts, temporary access that has outlived its date, and users whose role change has not triggered entitlement cleanup.
- Require a business owner to justify each retained permission in plain operational terms.
- Revoke access immediately when the user’s current role no longer requires it, then document the decision.
- Keep evidence of who approved, who reviewed, what changed, and when the review completed.
For institutions that need a broader governance reference, OWASP Non-Human Identity Top 10 is useful for its emphasis on overprivilege, lifecycle discipline, and credential hygiene, while CIS Controls v8 reinforces account management, access control, and audit logging as operational safeguards.
Risk and Threat Considerations
Granular teller permissions can create a false sense of precision: the access model looks controlled, but accumulated exceptions, delayed recertification, and role churn can leave users with more authority than they need. That becomes a security and compliance problem when sensitive financial actions remain available to staff who have moved roles, changed branches, or are no longer actively performing the same duties.
Failure mechanism: Role changes do not reliably trigger entitlement cleanup, so old permissions remain active, dormant accounts stay usable, and sensitive functions accumulate outside current business need.
Impact: Excess access increases the chance of unauthorized transactions, weakens segregation of duties, and leaves the institution with poor audit defensibility if a control review cannot explain why the access was still present.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, CIS Controls v8 and NIST CSF 2.0 set the technical controls, and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Lifecycle and Ownership | Role changes and stale teller permissions are a lifecycle governance problem. |
| Recommendation — Tie each entitlement to an owner and recertify or revoke it when the role changes. | ||
| CIS Controls v8 | 5 — Account Management | User access reviews directly depend on knowing which accounts and permissions remain justified. |
| 6 — Access Control Management | Granular teller permissions require least-privilege control and timely revocation. | |
| 8 — Audit Log Management | Defensible access reviews need evidence of who reviewed, approved, and changed access. | |
| Recommendation — Review accounts regularly and remove access that no longer matches business need. Enforce least privilege and revoke stale permissions after role changes. Retain audit evidence for every recertification and revocation decision. | ||
| NIST CSF 2.0 | PR.AA — Identity Management, Authentication and Access Control | Role-aware reviews are part of maintaining current access authorization. |
| GV.RM — Risk Management Strategy | Frequent role changes require a risk-based review cadence and escalation path. | |
| Recommendation — Align access reviews to current duties and remove unused authorization promptly. Set review frequency based on entitlement sensitivity and role-change velocity. | ||
| PCI DSS v4.0 | 7 — Restrict Access by Business Need to Know | Financial institutions must limit access to what each user needs for the job. |
| 8 — Identify Users and Authenticate Access to System Components | Access review evidence is stronger when identities and account usage are clearly attributable. | |
| Recommendation — Limit teller access to business need and remove permissions that exceed current duties. Verify account ownership and remove shared or stale access paths during reviews. | ||
Practitioner Guidance
What to prioritise: Put the highest review priority on permissions that can move money, override controls, approve exceptions, or expose customer or account data. Those are the entitlements where stale access becomes a material control failure rather than an administrative issue.
What to verify: Do not trust a recertification unless the reviewer can state the current role, the specific permission needed, and the business reason it must stay active. If the justification sounds like “may need it occasionally,” treat it as an exception that deserves tighter approval and shorter review intervals.
Practitioner takeaway: The control objective is not to review everything equally, but to make sure each retained teller permission can survive a role-change challenge, a business-owner challenge, and an audit challenge at the same time.
Related resources from NHI Mgmt Group
- How should security teams run user access reviews when a file platform has frequent role changes and granular folder permissions?
- Why do manual user access reviews break down in SaaS environments with frequent role changes?
- Why do HR platforms with frequent hiring and role changes create more access governance risk?
- How should security teams run user access reviews in environments with frequent staffing and vendor changes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org