Use both, but solve different problems. Periodic reviews remove stale access from the source, while dynamic access controls limit what an identity can do at runtime if cleanup lags behind. If you only do reviews, drift persists between cycles. If you only do runtime policy, obsolete entitlements still accumulate.
Why the Sequence Matters
Dynamic access controls and periodic reviews solve different halves of the same access problem. Reviews clean up entitlement drift after it has already accumulated, while dynamic controls reduce what can be done between reviews by enforcing runtime limits, context, and least privilege. The right question is not which one is “better,” but which one closes the gap the other leaves open.
That distinction matters because access risk is rarely static. People change roles, service integrations evolve, and temporary exceptions turn permanent if nobody revisits them. A control that only works at the point of review cannot stop over-entitlement from existing for long periods, and a control that only works at runtime does not remove obsolete access paths from the population.
For teams trying to compare models, IAM and IGA Basics is the clearest starting point because it separates entitlement governance from access enforcement. The same distinction is reinforced in NIST SP 800-53 Rev 5, which treats access control, identification, authentication, and audit as related but distinct control problems.
What Dynamic Controls Actually Change
Dynamic access controls change the decision at the moment of use. They can narrow what an identity may do based on time, location, device posture, resource sensitivity, request context, or the specific action being attempted. That makes them effective against privilege creep in the moment, especially where standing access would otherwise be too broad for normal operations.
They are strongest when the risk is not just whether access exists, but whether access should be usable right now. That is why runtime policy is so useful for privileged actions, sensitive data paths, and machine-to-machine access. Authorisation Models Guide helps here because it shows how RBAC, ABAC, ReBAC, and policy-based approaches differ in how finely they can express those runtime decisions.
Dynamic controls are not a substitute for governance. They do not discover forgotten entitlements, remove dead accounts, or prove that ownership has been assigned correctly. They reduce blast radius during use, but they do not solve entitlement hygiene by themselves. For that reason, they work best as a containment layer, not as the only access strategy.
In access-heavy environments, Privileged Access Management Guide is the most direct companion because it shows how just-in-time access, session controls, and zero standing privilege turn runtime limits into an operational pattern rather than a policy wish.
What Periodic Reviews Actually Fix
Periodic reviews remove access that should no longer exist. They are the primary mechanism for finding stale entitlements, confirming ownership, and forcing accountability for access that has drifted beyond the original business need. If done well, they reduce the stock of unnecessary permissions rather than only restricting how those permissions are used.
The weakness is timing. Reviews are point-in-time controls, so access can remain excessive for weeks or months between cycles. They also depend on reviewers having enough context to make a good decision, which is why many programmes struggle with rubber-stamping. A review that is too broad, too infrequent, or too poorly contextualised can satisfy a process requirement without materially reducing risk.
Access Reviews and Certification Guide is useful because it focuses on how to make reviews remove access, not just record approval. It also explains why event-driven review and closed-loop remediation matter when entitlement drift is the actual problem. NHI Lifecycle Management Guide adds the lifecycle angle: stale access is often a provisioning and offboarding failure as much as a review failure.
For organisations with machine, application, or service access, lifecycle governance is not optional. Reviews tell you what should be removed; lifecycle controls help prevent the same exception from reappearing. That is why review cadence, ownership, and deprovisioning discipline must be treated as one control loop rather than separate tasks.
Which One Comes First in Practice?
The practical answer is to start with whichever gap is creating the greater exposure, but maintain both. If you have weak governance, missing ownership, or no reliable inventory, periodic reviews should be prioritised first because you need a way to reduce accumulated entitlement debt. If your access is already reasonably governed but the remaining risk is excessive privilege during active use, dynamic controls should be prioritised first because they reduce immediate blast radius.
Financial Services Identity Security Guide is a good example of where this becomes operational, because regulated environments often need both access certification and runtime restriction to satisfy control expectations around privileged and high-risk access. The same duality appears in cloud and platform programmes where standing access is hard to eliminate entirely.
In other words, periodic reviews are the better first step when the problem is “too much access exists,” while dynamic controls are the better first step when the problem is “too much access is usable.” Most mature programmes need both: one to shrink entitlement inventory, the other to contain the consequences of whatever still remains.
Risk and Threat Considerations
When organisations rely on only one side of the control model, they create a predictable gap. Review-only programmes leave long windows where stale or excessive access can be abused before the next certification cycle. Runtime-only programmes can still leave dormant, overprivileged, or orphaned entitlements in place, which increases the attack surface and makes recovery harder after a compromise.
Failure mechanism: Attackers and internal misuse both benefit from the same weakness, excessive access that remains either unreviewed or unrestricted. If standing privileges persist, a compromise can move faster; if reviews are weak, cleanup lags behind operational change and the entitlement base keeps growing.
Impact: The result is larger blast radius, higher likelihood of unauthorized action, more difficult incident containment, and a greater chance that access paths survive long after the business reason has disappeared.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Periodic reviews and access cleanup depend on account and entitlement governance. |
| AC-6 — Least Privilege | Dynamic access controls enforce least privilege at runtime by limiting action scope. | |
| AU-6 — Audit Review, Analysis, and Reporting | Access reviews and control effectiveness both depend on evidence of use and exceptions. | |
| Recommendation — Review and remove stale accounts and entitlements on a defined schedule. Constrain active permissions to the minimum needed for the current request. Use audit evidence to validate access decisions and identify privilege drift. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The question concerns when to apply access governance versus runtime restriction. |
| Recommendation — Define access rules that combine governance reviews with operational enforcement. | ||
Practitioner Guidance
What to prioritise: Start with the control that addresses your biggest exposure, but define the end state as both governance and runtime restriction. If you cannot yet answer who owns each entitlement, periodic review is the better first stabiliser; if you already know ownership but high-risk actions are still too permissive, tighten runtime policy first.
What to verify: The review process must actually remove access, not just re-approve it, and runtime policy must be enforced at the point of decision, not only documented on paper. If neither produces measurable reduction in standing access or effective privilege, the control is cosmetic.
Practitioner takeaway: Use reviews to shrink the access inventory and dynamic controls to cap the damage when inventory control is imperfect; mature programmes treat them as complementary layers, not substitutes.
Related resources from NHI Mgmt Group
- Why do periodic access reviews still matter when organisations already have identity controls in place?
- How should security teams run access reviews for non-human identities?
- When do NHI access reviews create more value than a one-time cleanup?
- Should organisations prioritise external exposure or internal credential governance first?