Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should organisations reduce fraud risk when one…
Governance, Ownership & Risk

How should organisations reduce fraud risk when one employee can influence multiple finance controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 27, 2026 Domain: Governance, Ownership & Risk

Organisations should separate initiation, approval, and reconciliation tasks so no single person can control an entire payment or journal workflow. Pair that with periodic access reviews, exception monitoring, and enforced sign-off on high-risk transactions. The goal is not just to assign roles, but to create friction where abuse would otherwise be easy to hide.

Why This Matters for Security Teams

When one employee can initiate, approve, and reconcile finance activity, the issue is not only fraud exposure. It is also a control design failure that lets errors and abuse blend into normal operations. Strong segregation of duties reduces the chance that a single compromise, coercion event, or insider action can move money unnoticed. NIST’s NIST Cybersecurity Framework 2.0 frames this as a governance and access-control problem, not just a finance workflow issue.

NHIMG research shows how often weak identity governance becomes real loss: in the Ultimate Guide to NHIs, 97% of NHIs carry excessive privileges and only 5.7% of organisations have full visibility into their service accounts. That pattern matters here because finance controls are often wrapped around human roles, while the actual execution layer is spread across shared accounts, scripts, approvals, and ERP integrations. In practice, many security teams discover control concentration only after a suspicious payment, journal entry, or vendor change has already been posted.

How It Works in Practice

The practical answer is to design finance workflows so that no single identity can complete a transaction end to end. That means separating the person who creates or initiates the action from the person who approves it, and separating both from the person or system that reconciles the result. Where automation is involved, the same principle applies to service accounts, API keys, and workflow bots. The goal is not just RBAC on paper, but enforceable control over who can do what, when, and with what evidence.

Current guidance from NIST SP 800-53 Rev. 5 treats this as a combination of least privilege, access enforcement, and auditability. In finance environments, that typically translates into:

  • dual approval for payments, vendor master changes, and journal entries above a threshold
  • periodic review of users who can touch multiple steps in the same workflow
  • exception monitoring for out-of-hours, urgent, or manual overrides
  • strong logging that ties each action to a distinct identity and business justification
  • revocation of standing access where temporary task-based access would be sufficient

For organisations managing digital credentials at scale, NHIMG’s Top 10 NHI Issues is useful because the same abuse pattern appears in machine-to-machine finance integrations: over-privileged identities, weak rotation, and poor offboarding make control overlap harder to detect. The operational standard is to pair workflow separation with periodic recertification and evidence-backed approval chains, not rely on title-based trust. These controls tend to break down when emergency payment processes, inherited ERP permissions, or shared admin accounts let one operator override the normal path without triggering a review.

Common Variations and Edge Cases

Tighter segregation often increases processing time and exception handling, so organisations must balance fraud resistance against business continuity. That tradeoff becomes most visible in smaller finance teams, acquired entities, and regional operations where headcount is limited and one person may wear multiple hats. Best practice is evolving, but current guidance suggests compensating controls should be explicit rather than informal.

For example, a small team may allow the same employee to prepare and post entries only if a separate manager reviews evidence after the fact and exception reports are checked daily. In higher-risk environments, the safer pattern is more restrictive: temporary access, just-in-time approval rights, and automated detection of self-approval or same-day workflow completion. The Ultimate Guide to NHIs — Why NHI Security Matters Now is relevant here because excessive privilege and weak lifecycle controls are the same structural weaknesses that let fraud controls collapse quietly over time. Organisations should also treat shared inboxes, delegated authority, and delegated ERP roles as control surfaces, not convenience features. In practice, fraud risk rises fastest where one person can both create an exception and supply the evidence that the exception was justified.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-4Limits who can initiate, approve, and reconcile the same finance process.
NIST SP 800-53 Rev 5AC-5Directly addresses separation of duties in transactional controls.
OWASP Non-Human Identity Top 10NHI-03Excessive machine privileges can bypass finance workflow segregation.
CSA MAESTROGOV-2Governance must cover approval chains and autonomous workflow actions.

Reduce standing access for service accounts and automate revocation after task completion.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org