Separated service accounts for different Data Centres / The Cloud

I was chatting with someone at a SWUG about SVC accounts and best practices, I know its nearly a year but the wheels turn slowly in the public sector.

Basically we have a single SVC account that is monitoring all our Windows devices (WMI), is used for installing the Agent, basically doing everything windows based (except IPAM)
This account has several problems in my mind:
1. It is basically too powerful
2. If there is a problem in "the cloud" or one of our remote DCs and the SVC account gets locked, it kills monitoring for everything, obfuscating the issue.

Management and Security team want written documentation about best practices before allowing any new SVC accounts be created. However my googlefu is failing me.
Can anyone point me to some nice best practice documentation about splitting up the SVC accounts?