Join our Newsletter — 33% off our NHI Course

What are the signs that manual SFTP access reviews are failing?

Manual reviews are failing when teams rely on spreadsheets, miss accounts, cannot explain who has access to which files, or produce weak audit evidence. Other warning signs include slow review cycles, inconsistent approvals, and rubber stamping without checking whether permissions are still justified. Those conditions usually mean the review process is too error prone to support security or compliance.

What failing manual SFTP reviews usually look like in practice

The first signal is operational drift: the review no longer produces a reliable picture of who can reach SFTP endpoints, what files they can touch, and whether those permissions still match the business need. When a team has to reconcile spreadsheets by hand, chase owners for context, or interpret inconsistent approval notes, the process is already losing integrity.

Another sign is that the review output cannot be defended. If the reviewer cannot explain why an account remains active, whether a transfer path is still required, or what evidence supports the decision, the process is functioning as a ritual rather than a control.

A useful reference point for this control problem is Ultimate Guide to NHIs, which ties visibility, ownership, lifecycle, and access governance together in one operating model.

Manual review failure also shows up when approval quality drops below the level needed for audit or remediation. That usually means the team is not validating actual access against current usage, is missing dormant or shared accounts, or is accepting approvals without checking whether the underlying entitlement still exists for a reason.

Where the process breaks down technically and organisationally

Manual SFTP review failure is rarely a single error. It is usually a combination of poor inventory quality, weak ownership, and slow human validation. If account lists are incomplete, if file-level entitlements are not visible, or if reviewers depend on informal knowledge of who “should” have access, the review cannot catch excessive access reliably.

Slow cycles are another hard indicator. By the time a spreadsheet is circulated, checked, returned, and consolidated, the access landscape may already have changed. That gap matters because SFTP access often persists longer than expected, especially where service accounts, shared credentials, or outsourced workflows are involved.

For teams that need a deeper lifecycle view, Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is useful because it maps review work to provisioning, rotation, offboarding, and recertification.

Weak evidence is another failure mode. If the only record is a signed spreadsheet with no link to current entitlements, logs, or owner confirmation, the control is difficult to trust. That is especially important where auditors need to see not just that a review occurred, but that access was actually evaluated and corrected when needed.

One statistic that reinforces the visibility problem is that only 5.7% of organisations have full visibility into their service accounts, which shows how often access reviews are forced to operate with incomplete data.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8, NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Secrets and Credential Management SFTP reviews fail when access remains tied to unmanaged credentials and stale permissions.
NHI-03 — Lifecycle and Ownership Manual reviews depend on knowing who owns each account and why it still exists.
NHI-08 — Visibility and Discovery The question centers on missed accounts, incomplete inventories, and weak access visibility.
Recommendation — Inventory and rotate SFTP credentials, then revoke any access path without a current owner. Assign each SFTP account a named owner and recertify it on a fixed lifecycle cadence. Continuously discover SFTP accounts and reconcile them against the authoritative inventory.
CIS Controls v8 6 — Access Control Management Manual SFTP reviews are an access-control validation problem that must confirm least privilege.
5 — Account Management Missed accounts and stale access indicate account management controls are not operating effectively.
Recommendation — Review SFTP entitlements regularly and remove access that is no longer business justified. Maintain complete account inventories and disable SFTP accounts that lack active ownership.
NIST CSF 2.0 PR.AC — Access Control The issue is whether access is still justified, known, and enforceable for SFTP users.
GV.RM — Risk Management Strategy Weak manual reviews create governance risk because the organisation cannot evidence control effectiveness.
Recommendation — Enforce least-privilege access and recertify SFTP permissions against current business need. Define review quality criteria so failed SFTP recertifications trigger remediation, not rubber stamping.
NIST SP 800-63 IAL — Identity Assurance Level Review quality depends on confidence that the account and owner identity are correctly established.
AAL — Authenticator Assurance Level Stale SFTP access often persists because authenticators are weakly governed or reused.
Recommendation — Require strong identity proofing for account owners before approving access exceptions. Use stronger authenticators and rotate access material when SFTP access is recertified.
NIST Zero Trust (SP 800-207) PS — Policy Enforcement Manual review failures often mean policy decisions are not being enforced at access time.
Recommendation — Tie SFTP authorization to policy enforcement so stale access is blocked, not merely noted.

Practitioner Guidance

What to prioritise: Treat missing inventory and unclear ownership as the primary failure, not the approval workflow itself. If the team cannot reconcile the accounts and file paths first, the review result is not trustworthy regardless of how many sign-offs it collects.

What to verify: Confirm that each reviewed SFTP account maps to a named owner, a current business purpose, and a current set of file or directory entitlements. If any one of those three is missing, the review should be treated as incomplete rather than approved.

Common mistake: Do not confuse volume of reviewed accounts with control quality. A fast spreadsheet exercise can look efficient while still missing dormant access, shared credentials, or stale permissions that matter most.

Practitioner takeaway: Manual SFTP reviews fail when they cannot keep pace with entitlement change, cannot prove the basis for approval, and cannot produce evidence that would stand up to audit or remediation.