Because they are the controls that expose whether business access matches business intent. Access reviews identify who still has access, while segregation-of-duties analysis reveals where a single role or user can create conflicting actions. Together they convert risk from an abstract concern into an entitlement problem that can be corrected.
Why access reviews and SoD analysis belong in ERM
ERM programmes often fail when they stop at policy language and do not test whether access still reflects current business duties. Access reviews answer a simple but critical question: who can still do what? Segregation-of-duties analysis asks whether one person or role can complete a sensitive process alone, which is where hidden control failure and fraud opportunity usually begin.
That makes the two controls complementary. Reviews are retrospective, confirming whether access remains justified; SoD analysis is structural, showing whether the role design itself creates conflict. Together they turn enterprise risk into a concrete entitlement and workflow question, which is easier to measure, remediate, and audit than broad assertions about “least privilege” or “strong governance”.
They also help ERM teams move from exception handling to control design. If the same conflicts reappear in multiple access reviews, the issue is usually not the reviewer, it is the underlying role model, approval path, or business process. In that case the right fix is not more review effort alone, but redesign of roles, approvals, or compensating controls.
How they expose drift, conflict, and control breakdown
Access reviews are effective because entitlement drift is normal in real organisations. People change jobs, projects end, vendors rotate, and temporary access quietly becomes permanent. A review surfaces dormant, inherited, or excessive access before it becomes an incident, and it gives business owners a formal chance to confirm whether access still matches current intent.
SoD analysis targets a different failure mode: incompatible capabilities that create abuse paths even when each entitlement looks reasonable on its own. A user who can both create and approve payments, provision and certify access, or request and release a controlled action has a built-in control gap. The problem is not just excess access, it is the combination of access rights.
For ERM, that distinction matters because it changes the remediation path. A review may remove a stale permission, while SoD analysis may require redesigning the process, splitting duties, adding independent approval, or applying compensating monitoring where separation is not practical. Both controls are therefore about assurance, but they answer different operational questions.
What good ERM practice looks like
Strong programmes treat access reviews and SoD analysis as continuous control signals rather than periodic paperwork. Reviews should focus on meaningful entitlements, ownership, and business context, not just on bulk certification. SoD analysis should be tied to real business processes, role templates, and exception handling so that conflicts are found where work is actually performed.
NHIMG’s IAM and IGA Basics is a useful starting point for how access governance, entitlement management, and access review fit together. From there, a dedicated Access Reviews and Certification Guide helps teams design reviews that actually remove access instead of merely collecting sign-off. For conflict analysis, the Segregation of Duties (SoD) Guide shows how to define toxic combinations and manage mitigations without losing operational control.
Risk and Threat Considerations
When these controls are weak, the result is usually not a single dramatic failure but accumulated exposure: role creep, orphaned access, hidden conflicts, and unreviewed exceptions. That creates a larger attack surface for fraud, privilege abuse, insider misuse, and post-compromise lateral movement because one compromised or malicious account can do more than the business intended.
Failure mechanism: Access is approved once, then left in place after job changes or process changes; separately, SoD conflicts are tolerated because each entitlement is reviewed in isolation rather than as a combined workflow. The business ends up with permissions that are individually defensible but collectively unsafe.
Impact: ERM loses control visibility over who can initiate, approve, and conceal sensitive actions, which increases the chance of fraud, policy breach, audit findings, and delayed detection of misuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Access reviews and SoD analysis depend on controlling account ownership and entitlement hygiene. |
| Recommendation — Review account assignments regularly and remove unnecessary or conflicting access. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | ERM access reviews rely on regular account and entitlement review, approval, and revocation. |
| AC-5 — Separation of Duties | SoD analysis directly maps to preventing one identity from performing conflicting actions. | |
| Recommendation — Implement periodic account review and disable access no longer supported by business need. Separate conflicting duties or apply documented compensating controls where separation is impossible. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | ERM access reviews operationalise access control governance across users and roles. |
| A.5.18 — Access rights | Periodic review and removal of excess access is central to the question. | |
| A.8.2 — Privileged access rights | SoD failures are often most damaging in privileged roles and administrative paths. | |
| Recommendation — Define and enforce access control rules that reflect business need and current role ownership. Review access rights at defined intervals and revoke access that is no longer justified. Restrict privileged access and require stronger review for administrative entitlements. | ||
| SOC 2 (AICPA) | CC6.2 — Change Management and Access Control | Access review and SoD evidence supports control design and operation over logical access. |
| Recommendation — Maintain evidence that access is authorised, reviewed, and removed when no longer needed. | ||
Practitioner Guidance
What to prioritise: Start with high-risk business processes, not with low-value access lists. Payment, procurement, vendor onboarding, journal entry, privileged administration, and access administration usually deserve first pass because SoD conflicts there create the highest downside.
What to verify: For each review cycle, confirm that the reviewer has actual business ownership, that entitlements are grouped by meaningful function, and that exceptions are time-bound with a named compensating control. If a reviewer cannot explain why the access is needed, the review is not adding assurance.
Common mistake: Treating access reviews as a compliance event and SoD as a static policy exercise. ERM value appears when the controls are used to change entitlements, redesign roles, or force an explicit risk acceptance decision.
Practitioner takeaway: The real objective is not to “check the box” on entitlement governance, it is to prove that no single role can quietly accumulate enough access to bypass the business process itself.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org