What are the risks related to the SA039 rule related to Administer Users vs Administer Roles?

Change to security via new roles or change to existing roles and provisioning to an existing or new user which could result in inappropriate or unauthorized access to data or business processes.