Privileged access to payment and customer tables accumulates through incidents, contractors, and “temporary” support roles. Attestation campaigns that only collect ticks leave the same people in place.

Ask for evidence of removals in the last two review cycles. If none exist, the control is performative.

Sample break-glass accounts and export permissions separately — those paths often bypass the same review queue used for day-to-day roles.

Pair technical sampling with a clear owner for each high-risk system. Governance is a rhythm of decisions, not a folder of screenshots.