Back to Glossary

Entry · Business

Access Control

Access control is the set of decisions and checks that determines who can enter a place, view information or perform an action in a system. It includes identity checks, permissions, approvals and the removal of rights. The aim is to give people the access their work needs while limiting mistakes and misuse.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

A new finance hire needs to view invoices but not approve bank transfers. An access-control process gives the hire the first right and withholds the second.

Without that distinction, one login can become a route to error or fraud. Two ideas sit at the centre.

Authentication asks whether a person is who they claim to be, while authorisation asks what that person may do after signing in. Strong passwords or multifactor authentication (a second proof of identity, such as a phone prompt) do not solve a permission problem if every signed-in user can change payment details.

The principle of least privilege gives each person only the rights needed for an assigned job. A payroll clerk may need to prepare a payment file without being able to release it.

Segregation of duties extends the idea, so that the person who creates a supplier's bank record is not the one who approves its first payment. Access control applies well beyond software, covering office doors, stockrooms, shared files, bank accounts and cloud applications.

Named accounts beat shared logins, because a shared front-desk password makes an audit trail ambiguous and may stay active after a worker leaves. Service accounts and automated integrations are easy to overlook, so they need an owner, a limited scope and credentials that are rotated.

People change roles, so the process must handle joiners, movers and leavers. A new hire receives approved access, a mover loses old rights as well as gaining new ones, and a leaver loses access across all connected systems.

Temporary permissions, such as an outside accountant's access during a filing period, should carry an expiry date. A regular access review compares current users and rights with current jobs, and the frequency should reflect risk and system change.

Logs of sign-ins and permission changes help investigations, but a log cannot prove who used a shared or compromised account. For an owner, access control is a living list of who can do what, why and until when.

In practice

Real-world examples.

1

Example

A finance worker in a manufacturing firm can prepare a supplier payment, but a separate authorised manager must release it, so no single person controls the whole transaction. A small firm without enough staff for this split can add an independent review of payments instead.

2

Example

A retailer's employee moves from the warehouse to the accounts team and loses stock-adjustment rights at the same time as receiving access to the ledger. The change request records both the rights added and the rights removed.

3

Example

A marketing agency gives a freelance designer time-limited access to one project folder for six weeks instead of opening the entire shared drive. When the six weeks end, the access lapses automatically and no manual clean-up is needed.

Formula

Calculation

Access review completion = accounts reviewed / accounts in scope x 100 Worked example: a company has 200 accounts in scope and its reviewers examine 190 of them, so completion is 190 / 200 x 100 = 95%. This does not prove quality. If the reviewers find 12 rights that are no longer justified, those 12 must actually be removed and checked in the live system, otherwise a high completion figure still leaves the risk in place.

Case study

Seen in the real world.

This entirely fictional example follows Oasis Clinics, an invented group with several sites. An internal review found that a former receptionist still had a working login to the scheduling system. There was no evidence of a data leak, but the stale account was a clear risk.

Oasis tied offboarding to a named checklist, assigned an owner for each clinic system and verified revocation after each departure. The illustrative case shows a control improvement and does not claim that every leaver account leads to a breach.

A later check found that every departure in the following year was closed within one working day. Clinic managers also began to treat access requests as a normal part of hiring and not as an afterthought.

Watch out

Common mistakes.

  • Giving every signed-in employee administrator rights because it is quicker than defining roles.
  • Adding new permissions after a role change without removing the old ones, so rights quietly accumulate.
  • Counting a completed review as proof of safety while unjustified access remains active.

Questions

People also ask.

What is access control?

It is the set of rules and checks that decide who can reach a resource and which actions they may take.

What is least privilege?

It means giving each person or system only the rights needed for an authorised task, and nothing more.

How often should access be reviewed?

At a cadence suited to the risk, the pace of change and any contractual or legal duties, so a quarterly review may suit some systems but is not a universal standard. High-risk systems such as payments often justify a shorter cycle.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%

Related

Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.