What are the risks related to the SA037 rule related to Administer Users?

This is the form where users are established, passwords are reset and roles are granted.  Access to this form could allow various issues such as: 1.A user to grant a role that is not approved.  2.Setting up fictitious user account or generic account.  3.Resetting password of generic account or user account with broad privileges.   4.Change the employee to whom the account is linked to gain additional privileges such as approval limits or buyer authority.