Inoperative account review is the periodic assessment of accounts with no recent customer transactions to determine whether they remain legitimate, need re verification, or should be escalated for further action. This control helps banks detect stale records, reduce fraud exposure, and keep dormant balances governed.
What Inoperative Account Review Is For
Inoperative account review is not just a housekeeping exercise. It is the control that distinguishes an account that is merely inactive from one that is still legitimate, still owned, and still safe to leave in place.
In banking environments, the review helps separate dormant but valid customer relationships from records that should be re-verified, restricted, or escalated. That matters because inactivity can hide stale entitlement, forgotten access paths, and accounts that no longer match current customer risk.
How Inoperative Account Review Works
The review is periodic, which means the institution defines a cadence and then checks accounts against objective signals such as recent transaction history, status changes, customer contactability, or other business rules. The point is to avoid treating “unused” as a final state without evidence.
Depending on the outcome, an account may be confirmed as still legitimate, marked for customer re-verification, placed under additional scrutiny, or routed for closure or other follow-up. The control is therefore both a classification step and an escalation trigger.
Why It Matters in Banking Controls
Inoperative accounts create governance problems when they are left untouched for long periods. They can become stale records, complicate customer master data, and weaken confidence that account status still reflects reality.
The control also supports fraud reduction and balance governance. A dormant account may still be attractive to an insider or external attacker if it remains on the books without active review, especially when normal customer activity has stopped but the record, relationship, or balance still exists.
For institutions that run broader access and certification programs, inoperative account review fits the same discipline as access reviews and certification: establish what should still exist, validate it against current evidence, and close the loop when it does not.
Common Failure Modes and Operational Signals
The biggest failure mode is rubber-stamping. If reviewers rely only on age or a static status flag, dormant accounts can remain open even when the underlying relationship has changed or the account should have been escalated for action.
Another common issue is poor data quality. If transaction history, ownership records, or contact details are incomplete, the review may produce false comfort, miss a stale account, or delay escalation. In that sense, the control is only as strong as the records that feed it.
Because the subject is essentially about review, certification, and dormant-account governance, the same control logic appears in broader security control sets such as CIS Controls v8 and in formal access governance expectations around periodic review and least privilege.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Inoperative account review depends on reviewing and cleaning up unused accounts and access paths. |
| Recommendation — Review dormant accounts regularly and remove or escalate records that no longer have a valid business purpose. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | This term is a periodic account review and disposition control for accounts that may no longer be warranted. |
| Recommendation — Set account-review intervals and disable, close, or revalidate accounts that no longer meet business need. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Inoperative account review validates whether account identities remain legitimate and appropriately governed. |
| Recommendation — Maintain an authoritative account inventory and periodically verify that each account still has an approved owner and purpose. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud IAM governance includes recurring review of inactive or stale accounts and permissions. |
| Recommendation — Use recurring account reviews to remove stale cloud access and keep dormant records under governance. | ||