IAM Access Analyzer should be enabled at the organization level

Description

IAM Access Analyzer should be enabled at the organization level rather than only at the individual account level. An organization-level analyzer provides centralized visibility into resource access across all member accounts, enabling a delegated administrator account to monitor and manage access findings from a single location. Account-level analyzers alone do not provide this cross-account visibility.

Remediation

Enable IAM Access Analyzer at the organization level from the management account or a delegated administrator account. For guidance, refer to Enabling IAM Access Analyzer.