For keys that matter, good practice is that no one has direct access to the key. E.g. you have a process where there are ways to sign stuff with that key, and there are ways to gain access to that key if extraordinary circumstances arise, but in normal operation you should be able to make sure that you can revoke the ability to sign stuff from anyone, which requires you to be certain that they never ever had a chance to see, copy or write down private key material.
Yup, but even in cases where the expense of a proper HSM isn't warranted, you can set up a software solution/process that works in a similar manner to a HSM, just with less tamper-resistance.