CISO · Compliance Manager
Your identity side is probably mature. The gap is not unauthorised access. It is an authorised person acting without a rule.
Identity management is in place. Privileges are defined, access is reviewed, privileged accounts are monitored.
Then a manager asks for some data. An authorised person runs a permitted query, puts the result in a file and sends it. No rule is broken.
Who took which data for what stated reason, which fields went out in the clear, and where the file ended up are nowhere recorded together.
Reading production data is treated as seriously as changing it: request, reason, approval and delivery live in a single record.
Which field is masked stops being a person's decision and becomes the rule's decision. If a field goes out in the clear, that approval is recorded separately.
Evidence is not gathered afterwards. The delivery produces the record, and that record can be verified from outside the system that keeps it.