Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when SoD conflicts and…
Governance, Ownership & Risk

What should organisations do when SoD conflicts and stale access both appear in the same programme?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Treat the problems separately but govern them together. Fix the provisioning logic so conflicting access is blocked, then clean the existing population through access reviews and removal workflows. A combined model closes both the creation path and the drift path, which is the only durable way to reduce audit findings and operational risk.

How SoD Conflicts and Stale Access Should Be Managed Together

SoD conflicts and stale access are related, but they are not the same control problem. A conflict is a rule violation in how access is granted; stale access is an entitlement lifecycle problem. Organisations should treat them as separate findings, then manage them through one governance loop so design flaws, exception handling, and cleanup all feed back into the same programme.

The practical distinction matters because each issue fails for a different reason. SoD defects usually originate upstream in role design, provisioning logic, or exception paths, while stale access accumulates downstream through delayed removal, orphaned accounts, and weak recertification. If you only review access without fixing the rules, the same bad grants will return. If you only fix the rules without cleaning the population, the audit trail still shows residual exposure.

In that sense, the real programme objective is not simply to find violations, but to close both the creation path and the drift path. That means aligning business rules, entitlement models, and removal workflows so new access cannot recreate a known conflict and old access cannot persist after it has stopped being justified.

What the Combined Control Model Should Cover

The combined model needs two operating lanes. The first lane blocks conflicting access at the point of request or assignment, using clear rules for incompatible roles, functions, or elevated combinations. The second lane removes legacy exposure by reviewing existing entitlements, confirming business need, and revoking what no longer belongs. Both lanes must be visible in the same programme dashboard so one issue does not mask the other.

This is where access governance becomes more effective than isolated remediation. A good model can distinguish between a toxic combination that should never be granted and a dormant entitlement that should have been removed months ago. That distinction matters for ownership, because the fix for a role design issue is usually different from the fix for delayed deprovisioning or weak review cadence.

When the control model is mature, the organisation can answer three questions at once: what should never coexist, what still exists, and what must be removed or redesigned. That is also why the Segregation of Duties (SoD) Guide is relevant as a reference point for conflict rules, mitigation patterns, and broader access governance design.

Why Audit Findings Persist Unless You Fix Both Sides

Audit findings persist when organisations treat SoD as a one-time provisioning check and stale access as a periodic cleanup task. The result is a gap between policy and reality: conflicting access can continue to be granted through exceptions, while old access remains active because no one owns removal, revalidation, or escalation. One issue creates new exposure; the other preserves old exposure.

That is also why control evidence should show both preventive and corrective activity. Preventive evidence demonstrates that conflicting combinations are blocked or routed for approval. Corrective evidence shows that aged, unused, or no-longer-authorised access is being removed on schedule. Without both, you may improve one metric while leaving the enterprise still exposed to the other.

Programme owners should expect the two issue types to have different closure rates and different remediation effort. SoD conflicts often require rule changes, exception governance, or role redesign. Stale access often requires inventory cleanup, recertification, and removal automation. Conflating them makes it harder to assign the right owner and can create the false impression that a single control activity has solved the whole problem.

Risk and Threat Considerations

SoD conflicts and stale access create different but compounding exposure. Conflicting access can enable fraudulent or unauthorised action if a single identity can both request and approve, create and pay, or build and deploy. Stale access increases blast radius because accounts that should have been removed remain available for abuse, especially when users change roles, leave the organisation, or accumulate excess entitlements over time.

Failure mechanism: Weak provisioning rules allow toxic combinations to be granted, while delayed removal and poor recertification let obsolete entitlements persist long after they should have been revoked.

Impact: The organisation retains both active policy violations and dormant access paths, increasing fraud risk, insider risk, audit findings, and the chance that a compromised or abandoned account can still perform harmful actions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementSoD conflicts and stale access both depend on account and entitlement governance.
Recommendation — Strengthen account management to prevent conflicting access and remove stale entitlements promptly.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccount lifecycle control addresses both provisioning logic and stale-access removal.
AC-5 — Separation of DutiesSoD conflicts are directly about preventing incompatible access combinations.
Recommendation — Apply AC-2 to govern account provisioning, review, and timely disabling. Use AC-5 to block conflicting duties and require compensating controls for exceptions.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control governance covers both preventing conflicts and removing obsolete access.
A.5.18 — Access rightsAccess rights review and removal are central to clearing stale access.
Recommendation — Define access-control rules that prevent toxic combinations and support revocation workflows. Review access rights regularly and revoke entitlements that no longer have business need.

Practitioner Guidance

What to prioritise: Separate the remediation backlog into design fixes and population fixes. If the entitlement model itself permits a toxic combination, fix the rule first so the issue cannot reappear through the next provisioning event.

What to verify: Confirm that removal workflows actually revoke access everywhere the entitlement exists, including inherited roles, indirect memberships, and system or application-specific permissions. A review that only documents approval is not enough if the entitlement remains active.

Decision rule: If the issue is a conflicting grant, treat it as a control design or exception-management problem; if the issue is an aged entitlement with no current business need, treat it as a lifecycle and recertification problem. Do both in the same programme, but do not use the same remediation logic for each.

Practitioner takeaway: The durable fix is to govern SoD conflicts and stale access together while remediating them separately, because one is prevented at assignment time and the other is removed through lifecycle control.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org