When access reviews fall behind, permissions drift away from the user’s actual role. That can leave former employees, transferred staff, or rarely used accounts with access that should have been removed. Over time, the organisation faces a higher risk of unauthorized access, weaker governance, and audit findings tied to inadequate access control and review discipline.
What changes when access reviews slip in core banking
In a core banking environment, stale reviews do more than create paperwork debt. They weaken the control that confirms access still matches job function, operating unit, and customer or product responsibilities. That matters because core platforms often concentrate high-value transactions, master data, and sensitive operational functions in one place, so an outdated attestation can leave excessive access in a system where it is especially consequential.
When review cadence slips, the control no longer reliably catches orphaned entitlements, role creep, and accounts that should have been downgraded after a transfer or process change. The practical result is a larger gap between what the user should be allowed to do and what the system still permits.
For a broader access-governance view, NHIMG’s Lifecycle Processes for Managing NHIs section is useful because the same lifecycle discipline applies when entitlements, ownership, and recertification fall behind.
Why stale recertification creates audit and control failures
Access reviews are not just a periodic administrative checkpoint. They are the evidence that the organisation can justify each permission as current, approved, and traceable. When they are overdue, auditors may treat the entire access-control process as weakened, not merely delayed, because the institution can no longer show that removals, reductions, and exceptions were handled in time.
That is especially important in regulated banking systems because access decisions are expected to be demonstrable, repeatable, and tied to business need. If reviewers are working from outdated org charts or incomplete application inventories, they can sign off on access that no longer has a valid operational basis. The failure is therefore both control design and control execution.
NHIMG’s Regulatory and Audit Perspectives section provides a helpful parallel on why access evidence must be current, not merely documented.
Where the operational risk shows up first
The first signs are usually entitlement drift, unused privileged accounts that remain active, and exception approvals that never get revisited. In a core banking stack, that can affect payment posting, account maintenance, reconciliation support, and other functions where access is broad enough to alter records or view sensitive customer data.
One useful benchmark is NHIMG’s finding that 97% of NHIs carry excessive privileges, which reinforces how quickly permissions can outgrow their intended purpose when governance does not keep pace. Even though that statistic comes from the NHI space, the operational lesson is the same: if review discipline slips, excess access tends to accumulate rather than correct itself.
Over time, the control weakness also undermines segregation of duties. A user who has changed teams may retain a path into functions that should now be split across different roles, creating avoidable fraud, error, or misuse exposure.
Risk and Threat Considerations
Stale access reviews create a direct exposure path because old approvals can leave former employees, transferred staff, contractors, or dormant accounts with live permissions long after the business justification has disappeared. In a core banking system, that widens the blast radius of both accidental misuse and malicious account abuse.
Failure mechanism: The review process stops acting as a timely removal and downgrade control, so orphaned entitlements, role creep, and privileged exceptions survive past the point where they should have been revoked.
Impact: The organisation faces higher unauthorized-access risk, weaker segregation of duties, and audit findings that can trigger remediation work, management scrutiny, and possible regulatory concern if the gap is persistent or systemic.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack surface, CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, and ISO/IEC 42001:2023 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Current access reviews enforce least privilege and remove stale access. |
| Recommendation — Review and revoke dormant or excessive access on a fixed cadence. | ||
| NIST CSF 2.0 | PR.AC-4 — Access Permissions and Authorizations | The subject is current authorization state and timely access review. |
| GV.RM-01 — Risk Management Strategy | Outdated reviews increase governance and audit risk in a regulated core system. | |
| Recommendation — Continuously verify authorizations and correct drift from approved access. Treat stale access recertification as an operational risk requiring tracked remediation. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Inventory, Ownership, and Lifecycle | Stale reviews are a lifecycle and ownership failure that leaves access uncleared. |
| NHI-03 — Overprivilege and Least Privilege | Old reviews commonly preserve excessive permissions beyond current need. | |
| NHI-09 — Access Governance and Review | The exact issue is failing to keep access reviews current. | |
| Recommendation — Maintain ownership and recertification for every account, entitlement, and exception. Remove permissions that are no longer justified by the current role or workflow. Run timely recertification and escalate overdue access decisions for immediate cleanup. | ||
| NIST SP 800-63 | IAL2 — Identity Assurance Level 2 | Current access decisions depend on reliable identity and entitlement governance. |
| AAL2 — Authenticator Assurance Level 2 | Review lag can leave active access tied to still-valid authenticators. | |
| Recommendation — Use verified identity records and re-assurance when access decisions rely on role changes. Require stronger reauthentication or step-up checks for sensitive banking actions. | ||
| ISO/IEC 42001:2023 | 5.3 — Roles, Responsibilities and Authorities | Access review ownership and accountability must be clear for current decisions. |
| Recommendation — Assign explicit accountable owners for access recertification and exception closure. | ||
Practitioner Guidance
What to prioritise: Treat overdue reviews in core banking as control failures, not administrative backlog. Prioritise accounts with privileged access, posting authority, customer-data visibility, and any entitlement that crosses business units or environments.
What to verify: Confirm that each reviewer is assessing live role maps, current line ownership, and current system inventories. If the review process depends on stale spreadsheets or generic role names, it will keep certifying access that no longer fits the job.
Decision rule: If the access cannot be clearly tied to current business need, current manager approval, and current system ownership, remove or restrict it first, then investigate whether the access was ever still required.
Practitioner takeaway: In core banking, the value of access reviews is not the review event itself, it is the timely removal of access that has outlived its justification.
Related resources from NHI Mgmt Group
- Why do manual user access reviews create higher risk for credit unions with core banking systems?
- How should credit unions automate user access reviews in core banking environments to reduce fraud risk and compliance gaps?
- How should security teams automate access reviews for core banking platforms with granular role-based permissions?
- What happens when user access reviews are not automated for a system like Symitar?