Periodic review breaks because access, integrations, and credentials continue to change between assessments. A vendor can remain approved on paper while its permissions expand, tokens persist, or offboarding stalls. That creates a live exposure window that procurement-style oversight cannot see, so governance has to move to continuous entitlement and posture monitoring.
Why periodic vendor review misses the thing that actually changes
A periodic review treats third-party cyber risk like a static questionnaire, but the risk surface is moving continuously. Access expands, integrations change, and credentials age in place between review cycles. The result is a false sense of approval, where the vendor looks compliant on the spreadsheet while its real access path has already drifted.
That gap matters because the thing being managed is not just the vendor relationship, it is the live set of permissions, tokens, and trust links that can be used right now. When those elements change outside the review window, the control stops describing reality.
What becomes invisible between assessments
Periodic review hides three kinds of drift: entitlement drift, where permissions are quietly expanded; credential drift, where tokens and keys outlive the approval that issued them; and offboarding drift, where access remains active after the business reason has ended. Each of those can exist without any change to the procurement record.
The practical failure is that risk owners may still see a current vendor status, even though the actual exposure has changed. A supplier can move from low-risk to high-risk simply by gaining a new API path, a broader data scope, or a long-lived token that was never rotated.
That is why continuous visibility into third-party access is more useful than a periodic pass/fail review. The control question is no longer “Was the vendor approved?” but “What can this vendor reach today, and what changed since yesterday?” For a deeper treatment of governance, least privilege, and third-party offboarding, see Third-Party, B2B and Contractor Access Guide and IAM and IGA Basics.
Why the exposure window is the real failure mode
Periodic governance creates an exposure window between the last review and the next one. During that window, a vendor’s permissions can grow, a secret can leak, or a subcontractor can retain access after offboarding. Attackers do not need the approval process to be wrong, they only need the live access state to drift beyond what the review captured.
This is the same pattern seen in token theft and third-party access incidents, where a legitimate integration becomes the path of compromise. The lesson is not that vendor reviews are useless, but that they are too slow to be the primary control for active access relationships. Continuous monitoring of entitlements, token age, and deprovisioning status closes that gap far better than a calendar-driven review.
For a threat pattern view of how third-party access and stolen tokens turn into real compromise, Salesloft OAuth token breach, Slack GitHub breach 2022, and GitHub OAuth token breach 2022 are useful reference points.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Periodic vendor risk fails when tokens and credentials outlive review cycles. |
| AC-2 — Account Management | Third-party access becomes risky when accounts remain active or expand unnoticed between assessments. | |
| AC-6 — Least Privilege | The core issue is entitlement drift, where vendor access grows beyond the approved need. | |
| Recommendation — Rotate and revoke third-party authenticators on a lifecycle basis, not only at review time. Continuously provision, review, and disable third-party accounts as access changes. Limit third-party entitlements to the minimum access required and recheck for privilege creep. | ||
| CIS Controls v8 | CIS-5 — Account Management | Continuous monitoring of third-party accounts is needed when access outlives periodic reviews. |
| Recommendation — Inventory and disable stale third-party accounts and credentials without waiting for the next review. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier access risk persists between periodic assessments and needs ongoing governance. |
| Recommendation — Manage supplier security obligations as an ongoing relationship with live access checks. | ||
Practitioner Guidance
What to prioritise: Track the third-party access path, not just the contract or vendor rating. The highest-value signals are privileged entitlements, dormant or long-lived tokens, and incomplete offboarding, because those are the conditions that make a “reviewed” vendor still dangerous.
What to verify: Before trusting a third-party approval, verify who can authenticate, what they can reach, and whether the access still matches the business purpose. If your evidence only shows the last review date, you do not yet have evidence of current risk posture.
What good looks like: Access changes trigger monitoring, review, and revocation decisions continuously, with stale credentials and expanded privileges surfaced as exceptions rather than discovered after the next quarterly cycle. That is the operational difference between vendor management and access governance.
Practitioner takeaway: Periodic review is a governance checkpoint, but it cannot be the control that keeps third-party access safe. The control has to follow the live entitlement state, or the organisation will keep approving yesterday’s risk while today’s access remains active.
Related resources from NHI Mgmt Group
- How should organisations expand third-party risk management beyond periodic vendor reviews in complex ecosystems?
- How should GRC teams automate vendor tiering in third-party risk management without relying on manual review?
- What is the difference between third-party risk management and a one-time vendor review?
- Who should be accountable for vendor selection and risk review in a third-party IT vendor management program?