Join our Newsletter — 33% off our NHI Course

What are the signs that manual Concur access reviews are failing?

Common warning signs include missed accounts, outdated permission records, inconsistent reviewer decisions, and reviews that feel like routine sign-off rather than real scrutiny. If audit evidence is hard to produce, if role changes are not reflected quickly, or if excessive access keeps reappearing, the process is not giving reliable governance or compliance assurance.

What manual access review failure looks like in practice

Manual Concur access reviews fail when the review outcome no longer reflects the real access state. The clearest signs are missed accounts, stale permission data, inconsistent approvals, and a process that produces signatures without meaningful challenge. When reviewers cannot tell who has access, why they have it, or whether the entitlement still matches job duties, the review has become administrative rather than controlling.

A second warning sign is drift between the system and the review packet. If role changes, terminations, transfers, or temporary access are not reflected quickly, the review will keep validating obsolete access. That is especially problematic when excess access keeps reappearing after cleanup, because it shows the underlying access model or ownership process is not being corrected, only periodically documented.

Why the process stops providing real assurance

Manual reviews usually fail for one of three reasons: the source data is incomplete, the reviewer lacks enough context to make a sound decision, or the decision is not tied to timely remediation. In Concur, this often shows up as broad role lists, inherited permissions, or unclear owner accountability, which makes it easy for reviewers to click through without identifying unnecessary access.

The governance problem is not just missed exceptions, it is weak evidence of control operation. If the organisation cannot show who reviewed what, what changed as a result, and how quickly follow-up happened, the review does not provide durable compliance or audit confidence. A process can look complete on paper and still fail to reduce excess access in the real environment.

Useful reference points for this kind of control failure are NHIMG’s lifecycle processes for managing identities and regulatory and audit perspectives, because both emphasise reviewability, ownership, and traceable remediation. For the broader control model, the CIS Controls v8 and PCI DSS v4.0 both reinforce least-privilege review and access governance expectations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while PCI DSS v4.0 define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management Manual access reviews assess whether accounts still need access and retain least privilege.
8 — Audit Log Management Review failure is visible when evidence of decisions and remediation cannot be produced.
Recommendation — Review and remove unnecessary access using a disciplined account management process. Retain review and remediation evidence so access decisions are auditable.
PCI DSS v4.0 7 — Restrict Access by Business Need to Know Concur reviews should validate that access remains justified by business need.
8 — Identify Users and Authenticate Access Periodic review depends on accurate account ownership and traceable access records.
Recommendation — Revalidate access against business need and revoke excessive entitlements promptly. Ensure account records are accurate enough to support access recertification.
NIST CSF 2.0 PR.AA — Identity Management, Authentication, and Access Control Access reviews are part of maintaining controlled, current authorization decisions.
GV.RM — Risk Management Strategy Failed reviews create governance and compliance assurance gaps that must be managed.
Recommendation — Keep access rights current and revoke entitlements that are no longer justified. Treat recurring review defects as a governance risk requiring executive oversight.

Practitioner Guidance

What to verify: Check whether every review cycle starts from a complete entitlement inventory, not a stale export. If the reviewer packet omits dormant accounts, delegated access, or recently changed roles, the process is already failing before the first approval is signed.

Decision rule: If reviewers cannot explain why a user needs a given entitlement, treat that access as unverified rather than approved. If the same excessive access returns after cleanup, fix the upstream role model, ownership, or provisioning path instead of relying on another identical review cycle.

Evidence to retain: Keep the reviewer identity, the exact entitlements reviewed, exception decisions, remediation timestamps, and proof that removals actually executed. The Ultimate Guide to NHIs is a useful benchmark for the level of visibility and lifecycle discipline that access governance needs to be credible.

Practitioner takeaway: A manual review is only effective if it changes access outcomes, not just attestation counts, so focus on completeness, decision quality, and remediation speed rather than the number of approvals collected.