Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Why do manual segregation of duties and user…
Governance, Ownership & Risk

Why do manual segregation of duties and user access review processes create compliance risk under Provision 29?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 6, 2026 Domain: Governance, Ownership & Risk

Manual reviews create risk because they are point in time, inconsistent, and hard to evidence across a full financial year. Email approvals and spreadsheet dumps can miss conflicts, delay remediation, and leave weak documentation for the board’s annual statement. Automated controls reduce that exposure by capturing access changes, approvals, exceptions, and remediation actions as they happen.

Why manual reviews become a Provision 29 evidence problem

Manual segregation of duties checks and user access review can satisfy the intent of control oversight, but they often fail on traceability. Under Provision 29, the issue is not only whether a review happened, but whether the organisation can show that access was governed consistently across the year, exceptions were identified, and remediation was completed in a way the board can rely on. Spreadsheet-based or email-based reviews tend to fragment that evidence chain, especially when ownership changes or reviewers apply different thresholds.

That matters because compliance risk builds when the control is treated as a periodic task instead of a managed process. A review that is complete on paper can still leave unresolved conflicts, stale access, or missing approval records if the evidence is scattered across inboxes and local files. NIST’s broader control guidance on auditability and account governance remains useful here, especially NIST Cybersecurity Framework 2.0, because Provision 29 depends on demonstrable governance rather than informal assurance. In practice, many teams discover control gaps only when they try to assemble a year-end statement, not when the access review itself is carried out.

How the compliance failure usually develops in practice

Manual SoD and access review processes usually fail through a familiar sequence. First, the organisation defines a review cadence, often monthly, quarterly, or annually. Then evidence is collected from spreadsheets, ticket notes, or exported user lists. Reviewers mark exceptions by hand, but the process may not record why an exception was accepted, whether the conflicted access was actually removed, or whether the approver had enough context to judge the risk. That creates a gap between review activity and provable control operation.

The practical weakness is consistency. One manager may challenge a privileged role, while another may accept the same pattern because the business owner is unavailable or the spreadsheet is incomplete. If access is provisioned, changed, or removed outside the review cycle, the process can miss short-lived but material exposures. If the evidence pack is assembled after the fact, teams may be unable to show a clean trail from request to approval to remediation.

  • Manual review records often capture opinion, but not the underlying access state at the time of review.
  • Exception handling is frequently undocumented, which makes later assurance difficult.
  • Remediation may be delayed because the review owner and the access owner are not the same person.
  • Aggregating results across business units is hard when each team uses a different template or file structure.

That is why automated workflows reduce compliance exposure: they preserve timestamps, approvers, exceptions, and closure actions as part of the operational record, rather than reconstructing them later. For broader control design and evidence expectations, NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls both reinforce the value of repeatable control operation and audit-ready records. Where manual reviews cannot preserve that chain reliably, the guidance breaks down at scale and during board-level attestation.

Where manual review still works, and where it stops being defensible

Tighter review processes often improve oversight but increase administrative overhead, so organisations have to balance scrutiny against the risk of inconsistent execution. A manual model can still be defensible in smaller environments with limited privileged access, stable role design, and very clear ownership of approval and remediation. It becomes far less defensible when access is frequent, roles are overlapping, or the control must support a formal annual statement that depends on complete and reproducible evidence.

The main edge case is not whether a manual review exists, but whether it can be relied on to detect and prove the full population of conflicts. A well-run manual review may be adequate for low-volume exceptions, but it is fragile when the organisation depends on it for broad-scale SoD enforcement across many systems or business units. Another common misstep is treating a signed spreadsheet as equivalent to control completion. Guidance versus consensus is still emerging on how much manual evidence is sufficient for modern assurance expectations, but there is broad agreement that point-in-time reviews are weaker than controls that capture the event trail as work happens.

For this reason, the practical test is whether the review process can survive an audit without reconstruction. If the answer depends on chasing approvers, reconciling files, or explaining undocumented exceptions, the process is already carrying compliance risk that should be treated as material.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST IR 8596 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-03 — Risk Management StrategyProvision 29 risk is a governance and assurance problem requiring consistent control oversight.
Recommendation — Align access review governance to a repeatable risk strategy and retain evidence of exceptions and remediation.
CIS Controls v86.3 — Access Control ManagementManual SoD and access review processes are direct account-governance controls.
Recommendation — Automate access review records and revoke conflicting access promptly when exceptions are found.
NIST SP 800-635.6 — Identity Proofing and RecordsThe question turns on trustworthy identity and access records for audit and assurance.
Recommendation — Maintain authoritative access records that can substantiate reviewer decisions and revocations.
ISO/IEC 42001:2023A.5 — AI System Policy and GovernanceIf automation or AI is used in review workflows, governance and accountability must still be explicit.
Recommendation — Document oversight, accountability, and exception handling before using automated review support.
NIST IR 8596IR-4 — Incident HandlingUnresolved access conflicts and weak evidence can surface as control incidents needing remediation.
Recommendation — Triage unresolved access conflicts as control incidents and track them to closure with evidence.

Practitioner Guidance

What to prioritise: Focus first on the controls that create the strongest audit exposure: privileged access, conflicting duties, and any review step where remediation is manual and delayed. If those areas cannot be evidenced cleanly, the annual statement is more vulnerable than the underlying access model.

What to verify: Check whether each review can produce a complete chain of evidence without manual reconstruction, including who reviewed, what was reviewed, what exception was accepted, and when the conflict was removed. If any of those elements depend on email searches or local spreadsheets, the process is not yet robust enough for reliable assurance.

Common mistake: Treating a completed review as proof of compliance when the organisation cannot show timely remediation or consistent reviewer judgment. In practice, the weakest point is often not the review itself but the gap between identifying a conflict and proving that it was resolved.

Practitioner takeaway: Provision 29 risk is usually created less by the existence of manual review than by the inability to prove control operation continuously and consistently across the reporting period.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 6, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org