When ERP access reviews are not automated, reviews tend to lag behind real user changes, especially in environments with frequent role moves and system integrations. That delay allows dormant accounts and excess privileges to persist. The result is higher exposure to unauthorized access, more manual effort for administrators, and weaker evidence during compliance audits.
Why ERP Access Reviews Become a Governance Problem When They Are Manual
ERP environments change faster than periodic spreadsheets and email sign-offs can keep up. When access reviews are manual, role moves, temporary project access, shared functional accounts, and integration-driven permissions often remain in place long after they should have been revalidated. That creates a gap between the current business need and the actual access model, which is where excess privilege accumulates.
The main issue is not just administrative burden. ERP systems frequently sit behind finance, procurement, HR, and operations workflows, so stale entitlements can affect segregation of duties, transaction integrity, and auditability at the same time. Manual reviews also tend to produce weak evidence because approvers may not be reviewing current context, only static exported lists. NHI Management Group research shows that 97% of NHIs carry excessive privileges, which is a useful reminder that review delay and privilege creep are rarely theoretical.
In practice, many organisations discover the weakness only after a role change, audit request, or access incident reveals that the review process was tracking the schedule, not the actual state of access.
How Automated Reviews Change the Control Model
Automation changes access review from a periodic administrative task into a continuous control with better timing, traceability, and exception handling. In an ERP setting, that usually means pulling identity and entitlement data directly from the system of record, comparing it against approved roles or business ownership, and flagging mismatches for review while the data is still current. It also means making revocation part of the workflow instead of leaving follow-up actions to inbox reminders.
That matters because ERP access is rarely static. People change functions, contractors leave, service integrations expand, and emergency access is often granted under pressure. A good automated review process can separate human users from technical or integration accounts, highlight dormant access, and force approvers to make a decision on each exception rather than accepting a bulk certification. The strongest programs also preserve evidence of who approved what, when the data was pulled, and what changed after the review closed.
For teams assessing control depth, the NHI Management Group Ultimate Guide to NHIs is useful because ERP environments increasingly rely on service accounts, API keys, and other machine identities that do not behave like ordinary user accounts. OWASP’s Non-Human Identity Top 10 also helps teams think about why static access review habits miss machine-led access paths and long-lived credentials.
Automation is most effective when it is tied to authoritative identity data, current role mappings, and revocation workflows that can actually act on the findings. It breaks down when ERP roles are poorly modelled, ownership is unclear, or integrations create access that the business has never formally assigned.
Where Manual Reviews Fail First, and What Good Practice Looks Like
Tighter review cadence often increases process overhead, so organisations have to balance reviewer effort against control quality. The common failure is not that teams fail to perform reviews at all; it is that they certify access without checking whether the entitlement still matches the user’s current job, contract status, or system dependency.
- Reviews of shared accounts are often the weakest point because ownership is ambiguous and nobody wants to remove access that might keep a process running.
- ERP integrations can hide access paths that do not appear in standard user reports, so technical accounts need separate treatment from end-user access.
- Manual sign-off can create false confidence if reviewers are approving stale exports rather than live entitlement data.
Current guidance suggests treating access review quality as an evidence problem, not just a compliance calendar problem. If the review cannot show current scope, reviewer accountability, and timely follow-up on exceptions, then the control is only partially working. NIST’s SP 800-53 Rev 5 Security and Privacy Controls remains relevant here because it emphasises access control, auditability, and review discipline, even though the practical implementation details vary by ERP platform.
For longer-term improvement, many teams benefit from aligning reviews with the full lifecycle of accounts and entitlements rather than treating certification as a one-time event. The NHI Management Group NHI Lifecycle Management Guide is especially helpful when ERP access includes service identities, because the operational question becomes not just who approved access, but whether the identity should still exist at all.
Practitioner takeaway: automation is valuable when it shortens the gap between entitlement drift and corrective action; without that, reviews become documentation of delay rather than control of access.
Risk and Threat Considerations
Manual ERP access reviews create a material exposure window for privilege creep, dormant accounts, and untracked integration access. In systems that support finance or operational workflows, that exposure can translate into unauthorised transactions, segregation-of-duties failures, and weak audit defensibility.
Failure mechanism: stale entitlements persist because reviewers are working from outdated snapshots, approvals are delayed, or owners do not have enough context to spot excessive access. That same gap can be abused by insiders, compromised accounts, or unattended technical identities that retain access beyond their intended purpose.
Impact: organisations can lose control over who can initiate, approve, or alter ERP transactions, and they may be unable to prove timely review or revocation during an audit or incident investigation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | ERP reviews are about enforcing and verifying access decisions. |
| Recommendation — Review and remove unnecessary ERP access on a repeatable schedule. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions Management | Automated reviews support timely permission validation and removal. |
| GV.RM-05 — Risk Management Strategy | Manual review lag creates governance and assurance risk in ERP access. | |
| RS.AN-1 — Incident Analysis | Poor reviews often surface only after suspicious access or audit findings. | |
| Recommendation — Validate ERP permissions continuously and revoke excess access quickly. Treat stale ERP access as a governed risk requiring accountable remediation. Use access review findings to investigate and triage abnormal ERP access. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Stale ERP accounts can be abused as valid access paths after review delay. |
| Recommendation — Hunt for unused but still-valid ERP accounts and remove them promptly. | ||
| OWASP Non-Human Identity Top 10 | NHI-03 — Secrets and Credential Lifecycle | ERP integrations often depend on machine identities that need review and rotation. |
| Recommendation — Inventory and rotate ERP machine credentials before they outlive their purpose. | ||
Practitioner Guidance
What to prioritise: Focus first on ERP accounts with broad transactional power, dormant access, and any identity tied to integrations or automation. Those are the places where review lag has the highest operational and audit consequence.
What to verify: Confirm that the review pulls live entitlement data, not a stale export, and that each exception has a named owner and a recorded disposition. If a reviewer cannot explain why access still exists, the control should default toward removal or escalation.
Common mistake: Treating certification completion as proof of control. A completed review is only useful if it results in timely remediation, especially for accounts that can bypass normal business approval paths.
Practitioner takeaway: The real test is whether the review process can keep pace with role change and integration growth; if it cannot, the organisation is certifying risk instead of reducing it.
Related resources from NHI Mgmt Group
- What happens when Azure AD access reviews are not automated?
- What happens when access reviews are not automated for sensitive document repositories?
- What happens when access requests are handled case by case instead of through automated policy?
- What happens when AWS IAM Identity Center access reviews are done manually instead of through automation?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 9, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org