I observed that the IAM role to create a new AWS user would require the addition a policy as specified in steps 11 - 21 in this doc
I feel these two tasks should also be added to the Working with multiple AWS accounts section where the switch role is explained rather than when after it has been implemented to avoid confusing the of reader