They should redesign the access path so the secure option is also the usable one. That usually means reducing repeated prompts, extending modern controls to legacy systems where possible, and replacing manual vendor access handling with governed lifecycle steps. If operations only work through exceptions, the compliance programme is already leaking value.
When Compliance Controls Slow Frontline Work
The practical answer is to redesign the control so the secure path is the fastest usable path, not a parallel hurdle. If workers have to bypass the process to do ordinary tasks, the programme has already created exception debt, shadow access, and avoidable delay. The fix is usually to simplify the access journey, remove duplicate approvals, and make governed access the default.
That often means modern controls need to follow the operational reality, not sit beside it. Legacy systems, vendor workflows, and shift-based operations are where friction usually appears first, so agencies should treat usability as part of control design rather than as a nice-to-have.
What Usually Causes the Slowdown
Most slowdowns come from control layering, not from a single bad policy. Frontline teams may face repeated logins, manual ticket handling, re-authentication at awkward intervals, or approval chains that do not match the way work actually happens. The result is not just inconvenience; it is workarounds, shared access, and informal exceptions that weaken accountability.
There is also a common mismatch between control scope and system maturity. A modern security standard applied to a legacy application can be technically sound but operationally brittle, especially when the application cannot support federation, granular roles, or clean lifecycle automation. In those cases, the control design should be adapted rather than enforced as a copy-and-paste overlay.
When agencies depend on external vendors, slowdowns often come from manual onboarding, ad hoc credential handling, and unclear expiry rules. Those are access-governance problems as much as operational ones, because they leave too much discretion in the hands of people who are simply trying to keep work moving.
How Agencies Should Rebalance Security and Usability
Start by identifying which control step adds security value and which step only adds delay. If the same person has to prove their identity multiple times in the same task flow, collapse the redundant checks. If access is approved once but revalidated on every handoff, move to governed lifecycle steps so the control is enforced through policy, not repeated human effort.
Then extend modern controls to the highest-friction systems first. Where possible, use single sign-on, role-based access, just-in-time elevation, and lifecycle automation so frontline staff do not have to choose between speed and compliance. For legacy systems that cannot support those patterns natively, wrap them with compensating controls that are consistent, monitored, and time-bound rather than ad hoc.
The key design principle is usable security guidance from the NCSC: the more a control forces routine work into exception handling, the more likely it is to be bypassed. Agencies should also align control simplification with CIS Controls v8, especially where account management, access control, and audit logging need to work together rather than compete with operations.
For vendors and third parties, replace manual access handling with governed workflows that define who can approve, how long access lasts, and how it is revoked. That is the difference between a controlled exception and a standing operational dependency. It also makes auditing possible without forcing staff to maintain workarounds in spreadsheets or email chains.
When the Control Is the Problem, Not the Work
Agencies should treat repeated exceptions as evidence that the control design is misaligned with the service model. If frontline staff are routinely asking for overrides, the underlying rule may be too blunt, the system may be too old, or the access pattern may not reflect the actual job role. At that point, the right response is redesign, not more reminders.
This is where broader control frameworks help. NIST SP 800-53 Rev. 5 reinforces that access, identification, authentication, and auditability should be coordinated. ISO/IEC 27001:2022 likewise expects controls to be part of a working management system, which means they have to be operable in the environment they govern. Where cloud and supplier access are involved, the CSA Cloud Controls Matrix is useful for mapping how access, governance, and vendor obligations should fit together.
If the control only functions when people stop doing the work, it is the wrong control. The better test is whether the secure path can be completed at operational speed without losing traceability, expiry, or approval discipline.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Frontline access friction often stems from weak or manual account handling. |
| Recommendation — Standardise account lifecycle and access workflows so routine work does not depend on exceptions. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | The question is about making access controls workable without losing governance. |
| Recommendation — Automate account provisioning, review, and revocation to reduce manual access bottlenecks. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The issue is balancing secure access with practical operability in the ISMS. |
| Recommendation — Design access controls that remain enforceable in day-to-day operations. | ||
| CSA Cloud Controls Matrix | IAM — Identity & Access Management | The problem involves operational identity and access controls across users and vendors. |
| Recommendation — Align access governance, authentication, and lifecycle steps to reduce operational friction. | ||
Practitioner Guidance
What to prioritise: Fix the highest-friction access path first, usually the one used most often by frontline teams. That is where small improvements in authentication, approval flow, or lifecycle automation create the biggest reduction in exceptions.
What to verify: Confirm that every streamlined path still preserves ownership, expiry, and revocation. A faster process is only an improvement if it reduces manual burden without creating standing access or untracked vendor credentials.
Common mistake: Treating user resistance as a training issue when the real issue is control design. If the secure process is materially harder than the unsafe workaround, people will keep choosing the workaround.
Practitioner takeaway: The objective is not to make every control more restrictive, it is to make the compliant path operationally natural so that exceptions become rare, visible, and justified.
Related resources from NHI Mgmt Group
- Who should be accountable when privacy controls slow down marketing operations?
- Why do traditional security controls often slow down business operations?
- What happens when compliance controls slow the business down without a documented workaround?
- How should security teams govern non-human identities for compliance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org