(Free capability) It is recommended to review all your roles, to ensure that only the minimum required privileges are granted, to limit the scope of the threat in case of a compromise (blast radius)
(paid capability)
It is recommended to clean up unused roles, access keys, and permissions that are not being used as it reduces the impact in case of a compromise.
There are multiple solutions from our partners that assist with the task of cleaning up unused and unintended access, these solutions are called Cloud Infrastructure Entitlement Management (CIEM), such as Sonrai, Ermetic (tenable), Palo Alto Prisma, Wiz, etc. these capabilities are in some cases integrated into Cloud-Native Application Protection Platform (CNAPP) platforms.
IAM Access analyzer can help you identify these risks
https://aws.amazon.com/iam/access-analyzer/pricing
IAM Access Analyzer external access analyzer is provided at no additional charge.