The organisation keeps finding evidence without fixing control drift. Access can expand, privileged accounts can linger, and exceptions can pile up between review cycles, so the compliance record looks healthy while the actual identity state grows riskier. Continuous governance is what keeps policy, access, and accountability aligned.
Why periodic review turns governance into a snapshot
Periodic audit treatment creates a time gap between what was last checked and what is now true. Identity control is dynamic: roles change, contractors leave, service access accumulates, and exceptions age. When governance only “fires” at review time, the organisation measures compliance at a point in time but loses day-to-day control over entitlement drift, access reviews, and accountability.
The practical break is that policy becomes retrospective. By the time evidence is gathered, the access model may already have moved on, so the audit trail can look clean while the live access state is no longer aligned with approved intent. That is why continuous governance is not just a nicer operating model, it is the mechanism that keeps review, remediation, and ownership in the same control loop.
What actually degrades between audit cycles
When governance is episodic, the failure modes are predictable. Privilege tends to creep upward through movers, temporary exceptions, inherited roles, and inactive accounts that were never cleaned up. If teams rely on annual or quarterly review alone, they often miss the moment when a grant should have been removed, a role should have been recertified, or an exception should have expired.
Continuous governance also matters because identity risk is cumulative. A single overdue review is manageable, but dozens of small delays create a backlog of stale entitlements, orphaned accounts, and approvals that no longer reflect business need. Access Reviews and Certification Guide is useful here because the control problem is not review volume alone, it is whether review leads to actual removal and follow-through.
In practice, the drift becomes most visible in privileged paths, shared accounts, and high-impact systems where access changes faster than audit cadence. A periodic model can still collect evidence of review activity, but it cannot by itself guarantee that the identity state stayed bounded in the weeks between reviews.
Why compliance optics and control reality diverge
Periodic GRC encourages a documentary view of governance, where the main objective becomes showing that reviews happened. continuous identity governance instead measures whether decisions were current, exceptions were controlled, and changes were reflected quickly enough to prevent excessive access from persisting. Those are different outcomes, and the second one is the one that reduces exposure.
The strongest signal of this divergence is when exception lists grow while the audit pack stays stable. That means the organisation is collecting evidence of control activity without shrinking the underlying risk surface. Regulatory and audit perspectives matter here because they reinforce a simple point, auditability is not the same as active governance.
Periodic review can also distort accountability. If ownership is only checked at review time, no one is clearly responsible for the live state in between cycles, so remediation slows and exceptions become normalised. The result is a control environment that appears healthy in reports but is less reliable in operation.
Risk and Threat Considerations
When governance is periodic rather than continuous, identity drift becomes a security exposure, not just a housekeeping issue. Access that outlives its business need increases the chance of unauthorized use, privilege escalation, and lateral movement, especially when stale privileges or shared credentials remain active long after the original justification has disappeared.
Failure mechanism: Review cadence is slower than entitlement change, so excess access, lingering privileged accounts, and unexpired exceptions survive long enough to be abused or to accumulate into a larger control gap.
Impact: The organisation can pass a governance check while still carrying exploitable access paths, which raises breach potential, weakens segregation of duties, and makes incident investigation harder because the live access state is no longer trustworthy.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Periodic review breaks account lifecycle control and timely revocation. |
| AC-6 — Least Privilege | Continuous governance is needed to keep effective privilege from creeping upward over time. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Audit evidence is only useful when review drives corrective action on the live identity state. | |
| Recommendation — Automate account review and revocation so excess access is removed between audit cycles. Continuously validate and tighten privileges to maintain least privilege in live systems. Correlate audit findings with remediation workflows so evidence leads to access change. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question concerns keeping access decisions current rather than periodic only. |
| A.5.18 — Access rights | Stale rights and delayed removal are the core failure when governance is episodic. | |
| Recommendation — Operate access control as a continuous process, not a periodic compliance checkpoint. Review and revoke access rights promptly when business need changes. | ||
Practitioner Guidance
What to prioritise: Treat access removal and exception expiry as the primary governance outcomes, not the review event itself. If a control only proves that someone looked, it is not enough for high-risk entitlements or privileged access.
What to verify: Confirm that every review has an attached remediation path, an owner, and a due date. The useful question is whether the process can show that overdue entitlements were actually removed, not just marked for later follow-up.
Practitioner takeaway: Continuous governance is the difference between knowing the state of access and actually controlling it; if remediation does not happen as fast as entitlement change, the organisation is only documenting drift.
Related resources from NHI Mgmt Group
- What breaks when identity governance is treated as admin work instead of security work?
- What breaks when compliance is treated as a periodic exercise instead of a live control model?
- What breaks when data governance relies on periodic scans instead of continuous visibility?
- What breaks when organisations treat identity compliance as a one-time legal exercise instead of an ongoing governance function?