top of page
Search

The Overlooked Importance of Joiners, Movers and Leavers Controls in Governance

  • ageal8
  • Aug 5
  • 3 min read

Managing access to sensitive information is a critical part of organisational security. Yet many organisations struggle with a basic governance issue that often goes unnoticed: controlling what happens when employees join, move within, or leave the organisation. These Joiners, Movers and Leavers (JML) processes are essential to maintaining strong security and compliance, but they frequently lack clear ownership and consistent execution.


Eye-level view of HR manager and IT administrator reviewing onboarding and access permissions on a shared screen
HR manager and IT administrator collaborating on access controls

Why Joiners, Movers and Leavers Controls Matter


Organisations invest heavily in cyber security tools, policies, and staff training. They implement multi-factor authentication, deploy firewalls, and conduct regular audits. Despite these efforts, poor JML controls can quietly undermine these investments. When access rights are not properly managed, the risk of data breaches, insider threats, and regulatory non-compliance increases significantly.


For example, a new employee might be granted excessive access "just in case," exposing sensitive data unnecessarily. Similarly, when staff change roles, they may retain permissions that no longer apply to their new responsibilities. Departing employees who remain active in systems for days or weeks create a window of vulnerability that attackers can exploit.


These issues are especially critical in sectors like education, legal, finance, and public services, where data sensitivity and regulatory requirements are high. Poor JML controls can lead to audit failures, regulatory fines, and damage to reputation.


Common Challenges in Managing JML Processes


Many organisations treat onboarding and offboarding as administrative tasks rather than key governance controls. This mindset leads to several common problems:


  • Unclear accountability: JML processes often involve HR, IT, security, and operational teams, but no single group takes full responsibility.

  • Excessive access for new starters: Granting broad permissions "just in case" creates unnecessary risk.

  • Role changes without access updates: Employees keep old permissions that no longer fit their job.

  • Delayed deactivation of leavers: Accounts remain active long after employees leave.

  • Shared accounts with unclear ownership: These accounts are difficult to monitor and audit.

  • Lack of evidence for access reviews: Organisations struggle to prove that access rights are regularly checked.

  • Informal or missing approval processes: Access changes happen without proper authorisation.

  • Infrequent user access reviews: Reviews are often skipped or done too rarely to be effective.


These challenges stem from a lack of process discipline and assurance rather than technology limitations.


How to Improve JML Controls


Improving JML controls requires clear ownership, defined processes, and regular assurance activities. Here are practical steps organisations can take:


Assign Clear Ownership


Designate a single team or individual responsible for managing JML processes end-to-end. This could be a joint role between HR and IT but must have clear accountability.


Define and Document Processes


Create detailed workflows for onboarding, role changes, and offboarding. Include steps for access requests, approvals, provisioning, and deactivation.


Implement Role-Based Access Control (RBAC)


Use RBAC to assign permissions based on job roles rather than individuals. This reduces the risk of excessive access and simplifies updates when roles change.


Automate Where Possible


Leverage identity and access management (IAM) tools to automate provisioning and deprovisioning. Automation reduces errors and speeds up access changes.


Conduct Regular Access Reviews


Schedule periodic reviews of user access rights with managers and system owners. Document the review outcomes and actions taken.


Enforce Formal Approval Processes


Require documented approval for all access changes. This ensures accountability and provides an audit trail.


Monitor and Audit JML Activities


Use logs and reports to track onboarding, role changes, and offboarding activities. Regular audits help identify gaps and enforce compliance.


Real-World Example


A mid-sized public sector organisation faced repeated audit findings related to user access controls. New employees were given broad system access without proper approvals, and departing staff accounts were not promptly disabled. After assigning a dedicated JML coordinator and implementing automated workflows, the organisation reduced access-related incidents by 70% within six months. Regular access reviews became standard practice, improving compliance and reducing risk.


The Leadership Role in JML Governance


Strong leadership commitment is essential to embed JML controls into organisational culture. Leaders must recognise that JML processes are not just administrative tasks but critical governance controls that protect the organisation’s assets and reputation.


By prioritising clear ownership, process discipline, and assurance, leaders can close a common security gap that often hides in plain sight.



Effective Joiners, Movers and Leavers controls are foundational to good governance and security. Organisations that address this often-overlooked area reduce risk, improve compliance, and protect sensitive information. The next step is to review your own JML processes, assign clear responsibility, and ensure regular, documented access reviews. Taking these actions will strengthen your organisation’s overall security posture and governance framework.



 
 
 

Comments


bottom of page