What it means
A new finance hire needs to view invoices but not approve bank transfers. An access-control process gives the hire the first right and withholds the second.
Without that distinction, one login can become a route to error or fraud. Two ideas sit at the centre.
Authentication asks whether a person is who they claim to be, while authorisation asks what that person may do after signing in. Strong passwords or multifactor authentication (a second proof of identity, such as a phone prompt) do not solve a permission problem if every signed-in user can change payment details.
The principle of least privilege gives each person only the rights needed for an assigned job. A payroll clerk may need to prepare a payment file without being able to release it.
Segregation of duties extends the idea, so that the person who creates a supplier's bank record is not the one who approves its first payment. Access control applies well beyond software, covering office doors, stockrooms, shared files, bank accounts and cloud applications.
Named accounts beat shared logins, because a shared front-desk password makes an audit trail ambiguous and may stay active after a worker leaves. Service accounts and automated integrations are easy to overlook, so they need an owner, a limited scope and credentials that are rotated.
People change roles, so the process must handle joiners, movers and leavers. A new hire receives approved access, a mover loses old rights as well as gaining new ones, and a leaver loses access across all connected systems.
Temporary permissions, such as an outside accountant's access during a filing period, should carry an expiry date. A regular access review compares current users and rights with current jobs, and the frequency should reflect risk and system change.
Logs of sign-ins and permission changes help investigations, but a log cannot prove who used a shared or compromised account. For an owner, access control is a living list of who can do what, why and until when.
In practice
Real-world examples.
Example
A finance worker in a manufacturing firm can prepare a supplier payment, but a separate authorised manager must release it, so no single person controls the whole transaction. A small firm without enough staff for this split can add an independent review of payments instead.
Example
A retailer's employee moves from the warehouse to the accounts team and loses stock-adjustment rights at the same time as receiving access to the ledger. The change request records both the rights added and the rights removed.
Example
A marketing agency gives a freelance designer time-limited access to one project folder for six weeks instead of opening the entire shared drive. When the six weeks end, the access lapses automatically and no manual clean-up is needed.
Formula
Calculation
Access review completion = accounts reviewed / accounts in scope x 100
Worked example: a company has 200 accounts in scope and its reviewers examine 190 of them, so completion is 190 / 200 x 100 = 95%.
This does not prove quality. If the reviewers find 12 rights that are no longer justified, those 12 must actually be removed and checked in the live system, otherwise a high completion figure still leaves the risk in place.Case study
Seen in the real world.
This entirely fictional example follows Oasis Clinics, an invented group with several sites. An internal review found that a former receptionist still had a working login to the scheduling system. There was no evidence of a data leak, but the stale account was a clear risk.
Oasis tied offboarding to a named checklist, assigned an owner for each clinic system and verified revocation after each departure. The illustrative case shows a control improvement and does not claim that every leaver account leads to a breach.
A later check found that every departure in the following year was closed within one working day. Clinic managers also began to treat access requests as a normal part of hiring and not as an afterthought.
Watch out
Common mistakes.
- Giving every signed-in employee administrator rights because it is quicker than defining roles.
- Adding new permissions after a role change without removing the old ones, so rights quietly accumulate.
- Counting a completed review as proof of safety while unjustified access remains active.
Questions
People also ask.
What is access control?
It is the set of rules and checks that decide who can reach a resource and which actions they may take.
What is least privilege?
It means giving each person or system only the rights needed for an authorised task, and nothing more.
How often should access be reviewed?
At a cadence suited to the risk, the pace of change and any contractual or legal duties, so a quarterly review may suit some systems but is not a universal standard. High-risk systems such as payments often justify a shorter cycle.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
