Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What fails when organisations trust employees more than…
Governance, Ownership & Risk

What fails when organisations trust employees more than access controls?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Fraud control fails when the same person can create, conceal, or reconcile activity without challenge. Trust is not a control, so organisations need segregation of duties, access reviews, and entitlement checks that make abuse harder to sustain inside business systems.

When trust replaces control, where does the failure show up first?

The first failure is usually in the transaction path, not the policy document. When one employee can initiate, approve, adjust, and reconcile the same activity, the organisation loses the independent challenge that catches error and misconduct. That makes abuse easier to hide inside normal business operations, especially where approvals and exceptions are treated as routine.

Trust-based operating models often work in small teams, but they stop scaling as soon as financial postings, master-data changes, refunds, journal entries, or entitlement changes can be completed by the same person end to end. The core problem is not intent, it is unchallenged capability. Once a user can both create and validate activity, the control environment starts relying on honesty rather than evidence.

Good control design separates initiation, approval, execution, and review so no single user can complete a sensitive workflow without exposure to a second line of sight. In practice that means the organisation should make it impossible, or at least visibly difficult, for one person to both produce the record and certify it as correct.

Which controls actually stop this kind of insider abuse?

The most effective controls are segregation of duties, access reviews, and entitlement checks, because they break the path from opportunity to concealment. These controls matter most in systems where the business process itself creates value or records value, such as ERP, payments, procurement, expense management, and customer refunds.

Segregation of duties is not just a finance concept. It is a practical design rule that limits how much authority any one account should have over a business outcome. IAM and IGA Basics is useful here because it ties access governance to separation of duties, entitlement review, and the difference between granting access and governing it over time.

Entitlement checks work best when they are tied to real business tasks, not job titles alone. If a user has access that lets them post, approve, and reverse the same transaction type, the risk is not theoretical, it is a direct control weakness. Reviews should therefore look for toxic combinations, dormant permissions, and broad roles that quietly accumulate authority.

Authorisation design also matters because coarse roles often create hidden overreach. The Authorisation Models Guide helps distinguish role-based access from finer-grained policy approaches when teams need to prevent one user from covering the full control path.

Why does this become a fraud problem instead of just a governance problem?

It becomes a fraud problem because the same access that enables operations can also enable concealment. If a person can create a payment, edit the supporting record, and reconcile the exception, then fraud, error, and manipulation can all look like legitimate work unless another control interrupts the sequence.

That is why strong environments design for challenge, not assumed goodwill. Privileged users, shared team accounts, and broad back-office access are especially risky when the business system lacks immutable audit trails or independent review. Privileged Access Management Guide is relevant because privileged access amplifies the same failure mode, especially where standing access can bypass normal checks.

Fraud control also depends on visibility into who changed what, when, and under whose authority. When access reviews are stale or entitlements are never recertified, organisations often discover too late that the control exception was not temporary at all, but a permanent workaround that became normalised.

Risk and Threat Considerations

When organisations trust employees more than access controls, the risk is not only deliberate theft. The same weakness also enables error to persist, concealment to go unnoticed, and privileged users to bypass the checks that would normally expose abnormal behaviour.

Failure mechanism: A user with excessive or unreviewed access can create, modify, approve, and reconcile the same business event, which removes independent challenge and makes both fraud and accidental misuse harder to detect.

Impact: Financial loss, misstated records, weak audit evidence, and delayed detection are all more likely when the control environment depends on goodwill instead of enforced separation and periodic entitlement verification.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-5 — Separation of DutiesDirectly addresses preventing one user from controlling incompatible steps in a process.
AC-6 — Least PrivilegeLimits users to the minimum access needed, reducing abuse and concealment opportunities.
AC-2 — Account ManagementCovers access provisioning, review, and revocation needed to keep entitlements from drifting.
Recommendation — Enforce incompatible duties so no single user can create, approve, and reconcile the same transaction. Restrict entitlements to the minimum required for each business role and workflow. Review and revoke accounts and entitlements that no longer match the user's duties.
CIS Controls v8CIS-6 — Access Control ManagementSupports managing and reviewing access rights to prevent over-privileged users.
Recommendation — Continuously review and remove excessive access that enables single-user abuse.
ISO/IEC 27001:2022A.5.15 — Access controlRequires controlling access rights so sensitive business actions are not broadly exposed.
Recommendation — Define and enforce access rules that separate sensitive business actions.

Practitioner Guidance

What to prioritise: Start with the highest-value workflows where one person can influence both the transaction and its review, especially payments, refunds, journal entries, vendor setup, and entitlement changes. Those are the places where trust without control creates the fastest path to loss.

What to verify: Check whether access reviews actually test for toxic combinations, not just whether a manager clicked approve. If the review process cannot show who can create, alter, and clear a sensitive action, it is too weak to rely on.

Common mistake: Treating segregation of duties as a policy statement rather than a system property. A written rule does little if the application, role model, or override process still lets one person complete the full chain.

Practitioner takeaway: The right test is not whether employees are trusted, but whether the system still catches them when trust is misplaced, because resilient control design assumes that intent and integrity are not sufficient safeguards.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org