Use broad reviews when the organisation needs periodic coverage across a large population and the control objective requires wide assurance. Use narrower campaigns when the risk is concentrated in privileged roles, sensitive entitlements, inactive identities, or contractor access. The strongest approach is often a combination: broad periodic review plus targeted, higher-frequency reviews for higher-risk access.
When broad access reviews make more sense than narrow campaigns
Broad reviews are the better choice when the control objective is population-wide assurance, not just cleanup of a known hot spot. They help confirm that baseline access governance is operating across the full estate, especially where the organisation needs a periodic reset of ownership, entitlement accuracy, and certification discipline.
They are also useful when the access model is relatively stable, the review population is large, and the main question is whether the organisation can still account for who has what access. In that setting, breadth gives you coverage and comparability, while targeted campaigns are reserved for the higher-risk slices that need deeper scrutiny.
When narrower risk-based campaigns should take priority
Narrow campaigns are more efficient when risk is concentrated and the review can be focused on a clearly defined group, entitlement set, or business process. That is usually the case for privileged roles, sensitive systems, contractor access, temporary access, dormant accounts, or access paths with higher blast radius if misused.
This approach is strongest when the organisation already has a broad baseline review in place and now wants to raise the frequency or depth for the riskiest access. It reduces reviewer fatigue, improves decision quality, and makes it easier to investigate exceptions, because the campaign is tied to a specific exposure rather than a general compliance sweep.
For teams managing identity lifecycle and recertification at scale, the review model itself should match the control purpose. NHIMG’s IAM and IGA Basics is a useful reference for aligning access reviews with entitlement governance, while the NHI Lifecycle Management Guide helps when the review population includes service, workload, or other non-human access that must be recertified and retired cleanly.
How to choose the right mix without turning reviews into theatre
The practical decision is usually not broad versus narrow, but broad plus narrow, with each serving a different assurance goal. Use a broad cycle to prove coverage, then overlay narrower campaigns where the organisation sees privilege concentration, sensitive entitlements, inactive access, or external-party exposure. That gives you both completeness and precision.
Timing matters as much as scope. A broad review that runs too infrequently becomes a checkbox exercise, while a narrow review that is too frequent can waste reviewer attention on low-impact access. The best programmes use risk tiering to decide cadence, then keep the review method consistent enough that exceptions, removals, and reroutes can be measured over time.
Where organisations want a deeper governance lens, NHIMG’s Regulatory and Audit Perspectives section is helpful for understanding how access review evidence supports governance and auditability, especially when access decisions must be defensible across human and machine populations.
Risk and Threat Considerations
Broad reviews can miss concentrated exposure if they are treated as the only control, while narrow campaigns can miss drift elsewhere if they are treated as a substitute for baseline coverage. The risk is not just review fatigue, it is control blind spots, where excessive privilege, stale access, or weak ownership persists outside the campaign boundaries.
Failure mechanism: Organisations either review too much low-risk access and miss the important exceptions, or they focus narrowly on known risk pockets and lose visibility across the rest of the population. In both cases, entitlement creep, orphaned access, and unreviewed privilege can accumulate between campaigns.
Impact: The result is weaker assurance, higher likelihood of inappropriate access remaining active, and greater effort to prove that access decisions were actually reviewed. In regulated or audit-sensitive environments, that also creates evidence gaps when the organisation must show that review coverage matched the risk model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Broad and targeted access reviews are core account governance safeguards. |
| Recommendation — Review account access regularly and prioritize high-risk accounts for tighter recertification. | ||
| NIST CSF 2.0 | PR.AA-05 — Identity Management, Authentication, and Access Control | The question is about how access is reviewed and governed across populations. |
| Recommendation — Match review cadence to access risk and ensure high-risk privileges are recertified more often. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews are part of governing account existence, access, and periodic validation. |
| Recommendation — Establish periodic account review and target additional scrutiny to privileged or sensitive access. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights review and adjustment directly support the question's governance decision. |
| Recommendation — Review access rights on a set cadence and tighten review depth for higher-risk access. | ||
| SOC 2 (AICPA) | CC6.2 — Change management of logical and physical access | The subject concerns how access approvals and reviews are performed and evidenced. |
| Recommendation — Document access reviews and use risk-based follow-up for sensitive or privileged access. | ||
Practitioner Guidance
What to prioritise: Start with a broad periodic review if the organisation lacks reliable baseline coverage, then add narrower campaigns only where the access risk is clearly elevated. If you already have broad coverage, use the narrow campaigns to focus reviewer time on the entitlements most likely to produce real exposure.
What to verify: Make sure the review population is defined by business ownership and access risk, not by directory shape or convenience. If reviewers cannot explain why a group is in a campaign, the campaign is probably too broad or too vague to drive good decisions.
Practitioner takeaway: Broad reviews establish assurance, but narrow campaigns create precision; mature programmes use broad coverage for baseline control and targeted reviews for the access that can actually hurt them.
Related resources from NHI Mgmt Group
- How should organisations run access reviews so they reduce risk instead of just meeting audit requirements?
- How should organisations reduce GDPR breach risk when they still rely on password-based access and broad internal permissions?
- How can organisations reduce the risk of stale API keys and machine tokens?
- How should organisations run ISO 27001 user access reviews without creating audit noise?