Fraud Risk along the Employee Lifecycle – The Fraud Risk of Internal Role Changes
This article is the third deep dive in the Fraud Risk along the Employee Lifecycle article series.
The umbrella article introduced the Employee Lifecycle as a practical lens for identifying HR Fraud Risk across hiring, onboarding, role changes, incentives, access rights and offboarding.
The first deep dive, Identity Risk Starts in HR, focused on the earliest control-relevant question:
Who is this person?
The second deep dive, Onboarding Turns Identity into Access, examined the next question:
What is this person now allowed to do?
This third deep dive focuses on what happens when the answer changes.
Employees move. Roles change. Managers change. Projects start and end. Temporary responsibilities become permanent. Teams are reorganised. People are promoted, transferred, seconded, reassigned or asked to “help out” in another process.
From a people-management perspective, this is normal organisational life.
From a Fraud Risk perspective, it creates a critical question:
Do access rights, approval authority and control responsibilities still match the person’s current role?
Very often, the answer is not fully clear.
This is where Control Drift begins.
Internal Movement as a Control Event
Internal movement is often treated as a career, HR or organisational event. A person receives a new title. A new manager is assigned. A new cost centre appears. A new project role is added. A new team structure is communicated.
But from a control perspective, an internal role change is more than a change in the organisational chart.
It is a control event.
| Role change may affect | Control relevance |
|---|---|
| System access | Which applications, data, platforms and workflows the person can use |
| Approval authority | Which transactions, limits, exceptions or releases the person can approve |
| Segregation of Duties | Whether old and new permissions create toxic combinations |
| Reporting lines | Which manager, workflow or escalation path controls the person |
| Control ownership | Which reviews, reconciliations, approvals or monitoring activities the person performs |
| Data visibility | Which personal, financial, commercial or operational data the person can see |
| Budget or cost centre influence | Which spending, allocation or performance structures the person can influence |
The risk is not only that new access is granted incorrectly.
The larger risk is that old access, old authority and old control responsibilities remain in place after the person has moved.
Why Internal Role Changes Are Fraud-Relevant
Fraud Risk is often associated with deliberate circumvention: someone hacks a system, falsifies a document, manipulates an approval or bypasses a control.
But many access-related fraud risks are less dramatic.
They arise when legitimate rights become excessive, outdated or insufficiently reviewed over time.
This makes internal role changes particularly important.
A person who moves internally may accumulate access rights across several roles. A finance employee who once worked in accounts payable may still have vendor-related permissions after moving into a controlling role. A procurement employee may retain access to supplier master data after moving into contract management. A former payroll specialist may keep visibility into payroll data after joining HR operations.
In each case, the access may have a legitimate history.
But it no longer has a legitimate current purpose.
Fraud risk does not always require illegal access. Sometimes it only requires valid access that has become inappropriate.
Access Accumulation and Authority Drift
Control Drift often appears in two connected forms: access accumulation and authority drift.
| Drift pattern | What happens | Fraud-relevant effect |
|---|---|---|
| Access accumulation | New access is added during a role change, but obsolete access is not removed. | The person can act across more systems, processes or data areas than the current role requires. |
| Authority drift | Approval rights, signing authority, release permissions or workflow roles remain active after the role has changed. | The person may still approve, release, override or influence transactions they should no longer control. |
| Control ownership drift | A person stops owning a process operationally but still appears as control owner, reviewer or escalation point. | Controls may be performed by the wrong person or not performed at all. |
| Data visibility drift | A person retains access to data from a previous function, project or management role. | Confidential, payroll, customer, supplier or financial data may remain visible without current need. |
Access accumulation often happens for practical reasons. The new role requires additional systems. The manager wants a smooth transition. The employee is still helping the old team. Nobody is fully sure which permissions are still needed. Removing access feels more risky than leaving it in place.
Authority drift can be even more difficult to detect because it may look legitimate in the system. The workflow accepts the approval. The approval matrix still includes the person. The Audit Trail shows a named and active user.
But the underlying control question is different:
Should this person still have had this authority?
If the answer is no, the approval trail may document a control weakness rather than a valid control.
Dynamic Segregation of Duties
Segregation of Duties is often tested at a point in time. But employee roles are not static.
A person may not have had a conflict at onboarding. The conflict may emerge later, when new responsibilities are added and old access remains active.
| Internal movement | Possible Segregation of Duties issue |
|---|---|
| Accounts payable employee moves into a payment approval role | Invoice entry access remains active while payment approval authority is added |
| Procurement employee gains supplier approval authority | Vendor master data rights remain active |
| Payroll specialist moves into HR management | Payroll change access or payroll data visibility remains active |
| System administrator moves into access governance | Privileged operational access remains active |
| Project controller receives budget approval rights | Transaction entry or cost allocation rights remain active |
| Warehouse manager moves into finance operations | Inventory adjustment permissions remain active |
Each permission may have a reasonable history.
The combination creates the problem.
This is why Segregation of Duties should not only be checked at onboarding. It should also be checked during internal role changes, promotions, temporary assignments and reorganisations.
Temporary Access That Becomes Permanent
Many Control Drift problems start with temporary access.
Temporary access is often granted for legitimate reasons: a colleague is absent, a project deadline is urgent, a system migration requires support, a new process is being stabilised, a manager needs someone to cover approvals or an employee is asked to support another team during a transition.
The problem is not temporary access as such.
The problem is temporary access without closure.
Temporary access without an expiry date is not temporary access. It is unmanaged access.
An access right that was granted for two weeks may remain active for two years. An emergency permission may never be reviewed. A project role may survive the project. A substitute approval may continue after the substitute arrangement has ended.
This creates a control reality that no longer reflects the original organisational reason for granting access.
Reorganisations, Manager Changes and Project Roles
Some internal movements are formal and visible. Others are embedded in organisational change, reporting-line updates, project work or informal assignments.
| Movement context | Typical control risk |
|---|---|
| Reorganisation | System roles, access groups, approval workflows and cost centre responsibilities still reflect the old structure. |
| Manager change | Workflow approvals, access requests, expense reviews, time approvals or escalations still follow the old reporting line. |
| Project role | Temporary project access, master data rights or implementation permissions remain active after the project ends. |
| Informal process ownership | A person becomes the practical decision-maker without formal role, control ownership or review structure being updated. |
| Post-merger integration | HR Master Data, Identity and Access Management, Finance workflows and approval matrices may not align across inherited systems. |
Manager changes are particularly important because the manager field is often more than informational. It can drive workflows, approvals, escalation paths, access requests, expense reviews, time approvals and performance-related decisions.
A manager change is therefore not only an HR update.
It can be a control update.
Which controls rely on the manager field as organisational truth?
If the answer is unclear, the manager change may create hidden Control Drift.
The Joiner-Mover-Leaver Gap
Many organisations have a Joiner-Mover-Leaver process.
The joiner part is often relatively structured. The leaver part is usually recognised as important. The mover part is frequently weaker.
This is understandable. Joiners are visible because they need activation. Leavers are visible because they need deactivation. Movers are more difficult because they remain inside the organisation.
The person is still employed. The account stays active. The device remains assigned. The email address remains unchanged.
The risk is therefore less obvious.
Movers can be more complex than joiners or leavers because they require both addition and removal.
| Mover question | Why it matters |
|---|---|
| What new access is required? | The person may need capability for the new role. |
| What old access must be removed? | The person may retain capability from the previous role. |
| What authority must change? | Approval rights may no longer match the current responsibility. |
| What Segregation of Duties conflicts are created? | Old and new permissions may create toxic combinations. |
| What temporary access should expire? | Project, substitute or emergency access may remain active. |
| What workflows depend on the old role? | Approvals, escalations and control ownership may still follow outdated structures. |
Risk Pattern Matrix
The MOVE phase can create different forms of Control Drift. The following matrix summarises common patterns.
| Movement pattern | Typical Control Drift | Fraud-relevant consequence |
|---|---|---|
| Promotion | New approval rights are added while old process access remains active. | Segregation of Duties conflict, excessive authority or Override of Approval Limits. |
| Lateral transfer | Old department access remains active after the person joins a new function. | Cross-process visibility, Access Rights Abuse or Data Manipulation. |
| Temporary assignment | Temporary access has no expiry date or is not reviewed after the assignment ends. | Unmanaged long-term access. |
| Manager change | Workflow approvals and access requests still follow the old reporting line. | Invalid approval path or weak accountability. |
| Project role | Project permissions survive project closure. | Residual access before formal offboarding. |
| Reorganisation | HR Master Data, IAM roles, workflows and approval matrices no longer align. | Control reality diverges from organisational structure. |
| System migration | Old permissions are transferred, duplicated or mapped too broadly. | Privileged Access, excessive access or auditability issues. |
| Process ownership change | Former process owners retain master data, approval or review rights. | Weak control ownership and unclear accountability. |
Red Flags
Control Drift often appears as small inconsistencies rather than obvious failures. The following Red Flags are especially relevant after internal moves, promotions, temporary assignments and reorganisations.
Access Red Flags
- old access remains active after internal transfer
- new access is granted without removing obsolete access
- users have access rights across incompatible process steps
- business owners cannot explain why a user still has specific access
- role templates are updated, but existing users are not remediated
- high-risk permissions survive reorganisations
Authority Red Flags
- approval authority remains active after role change
- employees approve transactions for a team they no longer manage
- authority matrices do not match system permissions
- workflow approvals follow outdated reporting lines
- substitute approvals continue after the substitute arrangement has ended
- approval limits do not match the current role
Temporary and Project Access Red Flags
- temporary access has no expiry date
- project access remains active after project completion
- external or temporary roles remain active after assignment end
- emergency permissions are not visible in access reviews
- project roles are not reflected in Joiner-Mover-Leaver controls
- temporary process ownership becomes permanent by default
Data and Alignment Red Flags
- manager fields differ between HR, Identity and Access Management and Finance systems
- cost centre ownership does not match workflow approval paths
- Segregation of Duties conflicts appear only after role changes
- access reviews confirm access based on habit rather than current role
- HR Master Data and system permissions describe different organisational realities
- high-risk roles have not been reassessed after organisational change
None of these Red Flags proves fraud.
But each of them should trigger a control question.
Control Questions
A practical Fraud Risk Assessment can examine internal role changes as control events.
Role change trigger
The first question is whether the organisation recognises the movement as control-relevant.
- Which events trigger a mover control?
- Are promotions, lateral transfers, secondments, project assignments and manager changes included?
- Are temporary assignments captured?
- Are reorganisations treated as mass mover events?
- Who owns the mover process?
Access removal
A mover process is incomplete if it only adds new rights.
- Which access rights should be removed when a person changes role?
- Is old access removed before or at the same time as new access is added?
- Are access removals confirmed by system owners?
- Are obsolete permissions detected automatically?
- Are Privileged Access rights reviewed separately?
Authority and approvals
Authority should follow the current role, not the historical role.
- Does approval authority change when the role changes?
- Are workflow roles updated when manager, cost centre or organisational unit changes?
- Are signing rights and delegation rules reviewed?
- Are approval limits aligned with the current role?
- Are substitute approvals time-limited?
Segregation of Duties
Segregation of Duties should be dynamic, not only an onboarding check.
- Are Segregation of Duties checks performed after internal role changes?
- Do checks consider accumulated access across old and new roles?
- Are conflicts remediated or formally risk accepted?
- Are compensating controls defined?
- Are repeated conflicts analysed as role design problems?
HR Master Data and system alignment
Control Drift often appears when systems rely on different versions of organisational truth.
- Which systems rely on HR Master Data for role, manager, cost centre or employment status?
- Are HR, Identity and Access Management, Finance, Procurement and workflow systems reconciled after role changes?
- Can a person have one role in HR and a different access profile in IAM?
- Are manager changes reflected in approval workflows?
- Are organisational changes reflected in access groups?
Temporary and project access
Temporary capability should have a controlled end.
- Does every temporary role have an end date?
- Are project roles reviewed when the project ends?
- Who confirms that temporary access has been removed?
- Are emergency permissions visible in access reviews?
- Are project-related permissions included in Segregation of Duties checks?
Practical Control Measures
Control Drift cannot be managed only through periodic access reviews. It requires controls at the moment of movement.
| Control measure | Purpose |
|---|---|
| Treat role changes as control events | Trigger review of access, authority, Segregation of Duties and control ownership. |
| Define mover controls explicitly | Ensure the mover process removes obsolete rights, not only adds new rights. |
| Remove before adding where possible | Reduce the period in which a person holds both old and new capabilities. |
| Review accumulated access | Assess what the person can do across systems and processes. |
| Link role changes to Segregation of Duties checks | Detect conflicts created by the combination of old and new permissions. |
| Time-limit temporary roles | Prevent temporary access from becoming unmanaged access. |
| Reconcile HR, IAM and workflow data | Keep organisational truth aligned with control reality. |
| Review authority separately from access | Ensure that system access does not automatically imply approval authority. |
| Include projects and informal assignments | Capture hidden access accumulation outside formal HR role changes. |
| Preserve the Audit Trail | Allow later reconstruction of access, authority and exception decisions. |
For sensitive roles, Least Privilege should be applied not only at onboarding, but also at every significant movement. A person may still need access to view information, but no longer require the authority to approve, release or change it.
This is particularly important in Finance, Procurement, Payroll, HR Master Data, Master Data Management, system administration and other High-Risk Process Exposure areas.
NIST Identity and Access Management is relevant in this context because the concept of “right access” depends on role, context, current need and organisational purpose. NIST SP 800-53 is also useful as a reference point for access control, least privilege, separation of duties and audit-related control concepts.
Forensic Relevance
When a fraud case involves Access Rights Abuse, Control Override, Data Manipulation, Vendor Fraud, Payroll Fraud, Expense Reimbursement Fraud or Procurement Fraud, the investigation often begins with the action.
Who changed the data?
Who approved the transaction?
Who released the payment?
Who accessed the system?
Who had the credential?
Those questions are necessary.
But the Employee Lifecycle Fraud Risk Lens adds a different question:
Was this access still appropriate for the person’s current role?
| Evidence area | What it can show |
|---|---|
| HR role change records | When the organisational role changed and who approved it |
| Promotion or transfer documentation | Whether the role change was formal, temporary or exceptional |
| Manager change history | Whether approval paths followed current or outdated reporting lines |
| Cost centre change logs | Whether financial responsibility changed together with the role |
| IAM provisioning and deprovisioning logs | Which access rights were added, retained or removed |
| Role template history | Whether access profiles changed over time and whether existing users were remediated |
| Approval authority matrices | Whether authority matched the current role |
| Workflow configuration history | Whether approvals followed current or outdated organisational structures |
| Segregation of Duties check results | Whether old and new permissions created conflicts |
| Access review records | Whether continued access was actively validated or merely confirmed by habit |
| Project role assignments | Whether temporary or informal roles created additional capability |
| Exception registers | Whether temporary access, substitute approvals or emergency permissions were closed |
| Audit logs | Which actions were performed and whether the user acted with formally valid access |
This is especially important when the user acted through formally valid access.
The system may show that the user had permission. The workflow may show that the approval was accepted. The Audit Trail may show a named active employee.
But the forensic issue may be upstream:
The person should no longer have had that permission.
Why This Matters
Control Drift is dangerous because it rarely looks like a single control failure.
It looks like normal organisational change.
A promotion. A transfer. A temporary assignment. A restructuring. A project role. A manager update. A workaround during a busy period.
But over time, these changes can create excessive access, outdated authority, weak Segregation of Duties and unclear control ownership.
This matters because many fraud risks do not require illegal access.
They require valid access that has become inappropriate.
The person does not need to break into the system. The system already lets them in. The workflow does not reject the approval. The approval path still accepts it. The Audit Trail does not show an outsider. It shows an insider with rights that should have been reviewed.
That is why the MOVE phase is central to the Employee Lifecycle Fraud Risk Lens.
Conclusion
Fraud risk does not always start when access is first granted.
Sometimes it starts when access outlives the role that justified it.
The first deep dive in this series focused on identity.
The second focused on onboarding and capability creation.
This third deep dive focused on internal role changes and Control Drift.
Internal moves, promotions, temporary assignments and reorganisations are not only HR events.
They are control events.
Each role change can alter what a person should access, approve, influence or control.
If the organisation adds new access without removing old access, updates job titles without updating authority, or changes reporting lines without updating workflows, control reality begins to drift away from organisational truth.
The Employee Lifecycle Fraud Risk Lens helps make this visible.
Before asking whether a transaction was technically authorised, organisations should also ask:
Did the person still have a legitimate reason to hold the access, authority or control capability used?
Further Perspectives
This article is part of the Fraud Risk along the Employee Lifecycle series.
The umbrella article introduced the Employee Lifecycle as a practical lens for identifying Fraud Risk across hiring, onboarding, role changes, incentives, access rights and offboarding.
The first deep dive examined Identity Risk.
The second deep dive focused on onboarding, role assignment and access creation.
This third deep dive examined the MOVE phase: internal role changes, access accumulation and Control Drift.
The next article will examine how incentives, targets and performance pressure can become Red Flags for Fraud Risk.
Related Terms
- Internal Controls
- Fraud Risk Assessment
- Fraud Prevention
- Access Rights Abuse
- Segregation of Duties
- Control Override
- Management Override of Controls
- Override of Approval Limits
- Red Flags
- Audit Trail
- Data Manipulation
- Vendor Fraud
- Payroll Fraud
- Expense Reimbursement Fraud
- Procurement Fraud
- HR Master Data
- Identity and Access Management
- Access Rights
- Privileged Access
- Role-Based Access Control
- Least Privilege
- Approval Authority
- Joiner-Mover-Leaver
- Data Integrity
- High-Risk Process Exposure
- Employee Lifecycle Fraud Risk Lens
- Employee Lifecycle
- HR Fraud Risk
- Control Drift
