In every grown system sits an „H. Schmidt“ who is allowed to do everything. Not by intent, but because roles only grow and never shrink. The only question is whether you know him.
I have seen this again and again across two working lives, on the operator side as in the freelance years. There are two patterns. When a system or a company is built up new, a lot of responsibility initially lies in few hands. It is about speed, not governance. Everyone gets in everywhere, roles are handed out quickly and unbureaucratically, everyone may do everything.
In the running system it is more subtle. Where external regulations draw no line, roles naturally accumulate on employees, hanging off positions they once held years ago. Internal roles are often granted permanently, external ones time-limited, say to a year. At least for the critical access, though, you would have to check internally too, on a regular basis, what is still needed. This is not an IT topic. It is technical hygiene, and it is a governance risk.
What happened when we touched it
In one case the cleanup was triggered by an audit from the parent company. Because we had backing from top management, there was no open resistance. But there was, once again, far too few resources for clean tests, and very long negotiations during implementation. Without change management and without enough deep knowledge to judge the business units‘ assurances, it would not have been doable. „We still need all of this“ is what you often hear, and it is rarely true.
What the board really has to do
Does the board have to know who is allowed to do everything in its system? As a one-off report that is the wrong question, and apart from the CIO it is not the body’s job to know it in detail. The board makes the decision that makes a rule set and a monitoring possible in the first place. Within it, it is checked as deeply as possible where critical rights sit, and confirmed regularly whether they are still needed. Only when this standard process fails, because there is no check or no confirmation, should escalation happen step by step.
The board question is therefore not „who is allowed to do everything?“ as a one-off report. The question is: is there a process that continuously checks and confirms critical rights? If it is missing, the next „H. Schmidt“ is already growing in your system.