Root account should not have access keys. If at all you have that, then the keys should be rotated periodically.
Medium
Security
CBP, SOC2, CIS, PCIDSS, NIST, ISO27001, HIPAA