Yes, when the goal is meaningful governance rather than simple compliance. Reviews tied to onboarding, role change, or exit preserve context and reduce repetition. Fixed cycles still have a place for oversight, but they should not be the only trigger for certification.
Why lifecycle-triggered access reviews work better
Access reviews tied to onboarding, role change, and exit are usually stronger than calendar-only campaigns because they line up with an actual entitlement change. That gives reviewers a concrete reason to reassess access, rather than asking them to re-approve the same set on a fixed date. The result is better context, less rubber-stamping, and fewer stale permissions surviving unchanged.
This approach also fits how access risk accumulates. A mover event often changes job function, application scope, or business owner, while a leaver event should trigger immediate removal or transfer of access before the old relationship lingers. For lifecycle-sensitive programs, NHIMG’s IAM and IGA Basics and Joiner-Mover-Leaver (JML) Guide both reinforce that certification is most useful when it follows a real identity event, not just a timer.
Fixed cycles still matter when you need periodic oversight across populations that do not move often or where event data is incomplete. But as a governance model, a cycle on its own often becomes a reporting rhythm instead of a control. Event-driven review is the better default because it ties the decision to a change in entitlement context, which is what actually determines whether access is still justified.
When fixed cycles still add value
Fixed cycles remain useful as a backstop, especially where review triggers are not reliable, systems are disconnected, or some access paths do not produce clean lifecycle events. They are also helpful for catching slow drift, inherited access, and exceptions that no business event will surface on its own. In practice, the strongest programs use lifecycle events as the primary trigger and fixed cycles as a compensating control.
That balance matters because some access does not map neatly to a human HR event. Shared service accounts, long-lived integrations, and inherited access in older applications can persist without a clear onboard-move-offboard moment. For that reason, the review model should distinguish between event-driven certification for active relationships and scheduled recertification for residual exposure that needs periodic inspection. NHIMG’s Access Reviews and Certification Guide and IGA Buyer’s Guide both support that mixed operating model.
In other words, the question is not event-driven versus periodic in the abstract. It is which trigger best preserves context for the entitlement being reviewed, and which fallback prevents blind spots when no meaningful lifecycle event exists.
How to design reviews that actually remove access
The practical test is whether the trigger creates a review that can lead to a real action. If a review arrives after the change has already been implemented, reviewers can validate only current need, not historical entitlement. If it arrives too early, the business context is still unstable. The best trigger is the point where the new role, new manager, or exit decision is already authoritative enough to support a clean access decision.
Review design should also separate standard renewal from exception handling. Access that changes because of a role move should be reviewed in the same workflow that records the new role, while access that remains outside normal policy should be flagged for explicit justification or removal. NHIMG’s Role Mining and Role Design Guide is relevant here because weak role models create noisy reviews, and noisy reviews are one of the fastest paths to certification fatigue.
Where access is high-risk or broadly privileged, lifecycle timing should be paired with stronger ownership and segregation checks. Otherwise, a well-timed review can still miss the fact that the entitlement should never have been granted broadly in the first place. The operational goal is not more review traffic, but better decisions per review.
Risk and Threat Considerations
When reviews are tied only to a calendar, stale access can persist between cycles and reviewers are more likely to approve what they have seen before. That creates exposure through privilege creep, orphaned access after job change or exit, and weak accountability when no one can easily explain why access was still present.
Failure mechanism: The review happens without a triggering change in role, ownership, or business need, so the reviewer lacks context and defaults to approval or deferral. Over time, that turns certification into a checkbox process rather than a removal control.
Impact: Excess access stays live longer than necessary, increasing the blast radius of compromise, insider misuse, and audit findings tied to ineffective governance.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Lifecycle-driven access reviews support account recertification and removal decisions. |
| AC-6 — Least Privilege | Event-triggered reviews help reduce excessive entitlements after role changes or exits. | |
| AU-6 — Audit Review, Analysis, and Reporting | Review outcomes and trigger evidence need traceable records for oversight and follow-up. | |
| Recommendation — Tie recertification to account change events and remove stale access promptly. Revalidate access on lifecycle events and strip permissions no longer needed. Retain review evidence that shows the trigger, decision, and remediation outcome. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights should be reviewed when business need changes, not only on a fixed timetable. |
| Recommendation — Align access-rights review with joiner, mover, and leaver events. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account lifecycle and entitlement review are central to removing stale access efficiently. |
| Recommendation — Review accounts on lifecycle changes and revoke access that no longer has a business need. | ||
Practitioner Guidance
What to prioritise: Use lifecycle events for the entitlements that change with role, manager, or employment status, and reserve fixed cycles for access that lacks reliable event coverage or needs a periodic backstop.
What to verify: A lifecycle-triggered review should be able to show the underlying event, the new access context, the reviewer, and the removal or approval outcome. If you cannot evidence the trigger, you are probably running a calendar process with better branding.
Decision rule: If the access decision depends on a changed business context, trigger the review from that change; if the access is stable, inherited, or hard to event-source, keep a scheduled certification cadence as the fallback.
Practitioner takeaway: The strongest model is event-first, not event-only, because meaningful governance depends on reviews happening when access meaningfully changes, while fixed cycles remain the safety net for everything else.