Operational risks are frequently driven by human error, processing failures, or malicious internal actors. Managing people risk requires strong identity management controls and clear segregation of duties.
Key Identity Access Governance Defenses
- The Principle of Least Privilege: Employees receive only the system access permissions necessary to perform their specific job functions, preventing unauthorized internal access to sensitive data or financial keys.
- Segregation of Duties (SoD): High-risk business workflows must be divided among multiple employees. For example, the individual who sets up a new vendor profile in the accounting system must not be authorized to approve payments to that same vendor, preventing internal fraud.
- Mandatory Consecutive Leave Controls: High-risk employees (such as traders or wire transfer originators) must take consecutive days of annual leave each year. During this window, their system access is completely deactivated, allowing independent teams to review their account logs and identify any hidden anomalies or unauthorized activities.
Â