Failure to segregate duties
Users are able to exceed their authority
Backups are not tested regularly
Processes are not aligned with regulatory requirements