If you created a group in AWS with the rights that Audit Trail needs to run in the AWS environment, but you also attached those rights separately (maybe one user in the group with a slightly higher set of rights to run the Configuration tools) this will confuse AWS.  This is an approach we do not recommend, because in this set-up, group rights take precedence over the individually attached rights. 

We recommend you create a unique user, just for the purposes of setting up and configuring Audit Trail on the AWS environment. This user should be give many rights including 'BasicIAMRoleManagement' and should not be part of any group you may have set up.