Because the schedule does not correct the underlying access data. If joiner, mover, and leaver updates are late or incomplete, the review only revalidates stale entitlements. That leaves old access in place long enough to fail least-privilege expectations and weaken audit confidence.
Why stale permissions create governance risk even when reviews are on time
A review that runs on schedule is only evidence that a control happened, not that the access state being reviewed was accurate. When joiner, mover, and leaver updates lag, the review window can validate permissions that should already have been removed or reduced. That creates a governance gap: the process is compliant in form, but not reliable in substance.
iso 27001 treats access control as an ongoing governance outcome, not a calendar event. If the underlying identity record, role assignment, or entitlement inventory is stale, the organisation can miss the point of review entirely. The risk is not the review cadence itself, but the false confidence created when outdated access survives long enough to look approved.
In practice, stale permissions often come from delayed offboarding, role changes that were never applied, inherited access that was never revalidated, or entitlements that no one still owns. The control then becomes a retrospective check on bad data. That is why a clean review log can coexist with weak least-privilege enforcement and a higher audit burden.
Where the governance failure usually starts
The failure usually begins upstream of the review. If HR, IAM, application owners, and managers do not maintain a current entitlement picture, certification simply records whatever the system still shows. The review may approve access because the reviewer was never shown the true business context, or because the stale entitlement was hidden inside a role, group, inherited permission, or dormant account.
This is why the Identity Security Regulatory Map is useful: it ties identity control failures to governance and compliance expectations across major regimes, including ISO 27001. A stale-permissions problem is not just operational debt, it is evidence that entitlement governance and review evidence are out of sync.
Once that mismatch exists, the organisation may still pass a scheduled review but fail the deeper question auditors care about: whether access was timely, appropriate, and actually removed when the business event occurred. The control objective is to prevent excess access from persisting, not merely to document that someone looked at it later.
What ISO 27001 is really testing in an access review
ISO 27001 governance risk appears when review evidence suggests discipline, but the access model still allows excess entitlements to accumulate. A scheduled review only has value if it is backed by accurate joiner-mover-leaver processes, clear ownership for entitlements, and a remediation path for exceptions. Otherwise the control becomes a reporting ritual instead of a risk reduction mechanism.
That is why ISO/IEC 27001:2022 Information Security Management matters here, and ISO/IEC 27002:2022 Information Security Controls provides the implementation context. The relevant governance lesson is to treat access reviews as one part of a control chain, alongside provisioning accuracy, exception handling, and revocation timeliness, rather than as the control itself.
Stale permissions also weaken evidence quality. If an auditor cannot trace how an entitlement was granted, why it still exists, who accepted the exception, and when it will be removed, then the organisation has a governance problem even if the certification calendar was met. That gap is often what turns a routine review issue into a management finding.
Risk and Threat Considerations
Stale permissions create a window where outdated access can be used, abused, or simply forgotten until it becomes a real exposure. The longer excess access persists, the more likely it is to support privilege creep, unauthorized data access, or lateral movement after a role change or departure.
Failure mechanism: The review revalidates an access state that is already obsolete because identity updates, entitlement changes, or revocation events arrived late, so the control never sees the true least-privilege baseline.
Impact: Excess access can remain in place despite apparently successful reviews, increasing audit findings, weakening accountability, and leaving the organisation unable to prove that access was removed when it should have been.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 provides the primary governance reference for this topic.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | Stale permissions directly affect access governance and least-privilege enforcement. |
| A.5.16 — Identity management | Late joiner-mover-leaver updates create stale entitlement records and ownership gaps. | |
| A.8.2 — Privileged access rights | Stale privileged access is a direct governance and audit-risk driver. | |
| Recommendation — Align review evidence with current access state and remove excess entitlements promptly. Maintain accurate identity lifecycle records before certifying access. Review and revoke privileged rights that no longer match business need. | ||
Practitioner Guidance
What to verify: Confirm that every reviewed entitlement can be tied back to a current business need, a named owner, and a recent joiner-mover-leaver event. If that linkage is missing, the problem is not the review cycle, it is the quality of the access inventory feeding it.
What good looks like: Review outcomes should consistently produce removals, reductions, or explicit exceptions with expiry dates. A review that repeatedly approves the same high-risk access without change is usually signalling weak upstream hygiene, not control maturity.
Decision rule: If an entitlement can stay valid only because the reviewer lacks accurate context, treat it as a governance defect and fix the provisioning and recertification workflow before trusting the next cycle.
Practitioner takeaway: Timed reviews are necessary, but they are not sufficient. In ISO 27001 terms, the real control objective is current, defensible access, and stale entitlements show that the process may be punctual while the governance outcome is still wrong.
Related resources from NHI Mgmt Group
- Why do non-human identities create compliance risk even when policies exist?
- Why do Bedrock permissions create governance risk even when the platform is used legitimately?
- Why do newly released cloud permissions create governance risk even when they are added for legitimate platform features?
- Why do non-human identities create more audit risk than human accounts?