Join our Newsletter — 33% off our NHI Course

What is the difference between a review that records approval and a review that actually reduces risk?

An approval-only review captures a decision, while a risk-reducing review changes the entitlement state and leaves an auditable trail. If the workflow does not validate that access was removed at the source, the organisation has evidence of review but not evidence of control.

Approval-only review versus risk-reducing review

An approval-only review answers “who signed off?” A risk-reducing review answers “what changed?” The difference is operational, not semantic: one produces evidence of a decision, the other produces evidence that access, privilege, or another entitlement condition was actually corrected at the source.

That distinction matters because a review can be complete on paper while the underlying exposure remains unchanged. If the workflow records approval without verifying revocation, removal, or privilege reduction, the organisation may have audit evidence of oversight but still carry the same downstream access risk.

What evidence each review type should leave behind

An approval-only review should leave a traceable decision record, such as who reviewed, what scope was covered, when the decision was made, and whether an exception was accepted. It is useful for accountability, but it does not by itself prove that the entitlement state changed.

A risk-reducing review should leave evidence that the control moved the environment toward lower exposure. That usually means a before-and-after state: the account, role, token, privilege set, or access path was removed, reduced, expired, or revalidated in a way that can be independently checked.

For sensitive access, the strongest evidence is not the approval note, but the system record showing the entitlement was removed or constrained and the change was applied in the authoritative source. A review that only closes a ticket can still leave standing access in place if the underlying system was not updated.

How to tell whether a review changed the risk state

The practical test is simple: if the review were deleted, would the environment still look safer? If the answer is no, the review probably documented governance rather than reduced risk. A real control outcome should be observable in the entitlement store, IAM platform, PAM system, or application authorisation layer.

That is why workflows need to validate source-of-truth changes, not just human acknowledgment. The review should confirm the access was removed where it originates, then verify that the dependent systems no longer honour the old entitlement. Without that loop, review activity can create a false sense of control.

For recurring reviews, the useful metric is closure quality, not closure volume. High review completion with low remediation or no state change is a warning sign that the process is becoming administrative rather than preventive.

Risk and Threat Considerations

Approval-only reviews can hide persistent exposure when excessive access, stale access, or privilege creep is accepted instead of fixed. The risk is not just weak governance, it is continued attack surface: a reviewed entitlement can still be abused if it remains active after the review.

Failure mechanism: The workflow captures sign-off, but does not validate revocation, deprovisioning, or privilege reduction at the source system, so the same access continues to exist after the review closes.

Impact: Organisations may believe they have reduced exposure when they have only documented approval, which increases the chance of undetected misuse, audit failure, and avoidable blast radius if the account or privilege is later abused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-12 — Audit Record Generation Review outcomes need auditable records to prove what decision and change occurred.
AC-2 — Account Management The question turns on whether access state is actually changed at the source.
Recommendation — Record review decisions and resulting entitlement changes in audit logs. Update or disable accounts and entitlements in the authoritative system, not just the workflow.
ISO/IEC 27001:2022 A.5.15 — Access control The distinction hinges on controlling and reducing access, not merely approving it.
A.5.16 — Identity management Reviews must verify the identity-to-entitlement relationship has changed after approval.
Recommendation — Ensure review processes drive actual access restriction or removal in the access control process. Verify that identity records and linked entitlements are updated when reviews require removal.
CIS Controls v8 CIS-5 — Account Management Account reviews are only risk-reducing when they change account state and privileges.
Recommendation — Remove, disable, or right-size accounts instead of stopping at approval records.

Practitioner Guidance

What to verify: Treat the source system as the authority. Confirm that the reviewed entitlement was actually removed, expired, or reduced in the system that grants access, not just acknowledged in the review ticket.

What good looks like: The review outcome should show a clear chain from decision to executed change, with timestamps, actor, and the resulting entitlement state. If you cannot prove the state changed, you do not yet have a risk-reducing review.

Common mistake: Teams often measure review completion rates and miss remediation effectiveness. A completed review is only useful when it reliably produces a smaller access footprint or a consciously accepted exception.

Practitioner takeaway: Design reviews so the control outcome is a changed entitlement state, not a recorded opinion, because only the former reduces risk in a way you can defend later.