What are the risks related to the PP232 rule related to Create and Maintain PO vs Approve AP Invoices?

While it is not customary for a user to have access to both of these activities, we see little risk in this, but have added because some audit firms have this in their library.