Join our Newsletter — 33% off our NHI Course

What breaks when access governance is still based on periodic reviews under DORA?

Periodic reviews miss access that changes between certification cycles, especially in organisations with suppliers, delegated administration, and machine identities. That creates blind spots in audit evidence and incident response because the current control state is unknown when an issue appears. Under DORA, that is a resilience failure, not just an IAM weakness.

Why periodic reviews fail under DORA

Periodic recertification assumes access state is stable long enough to be verified on a schedule. Under DORA, that assumption breaks quickly in environments with suppliers, delegated administration, and machine identities, because access can change between review cycles and still affect operational resilience. The result is not just an IAM hygiene issue, it is a control-state problem that can leave audit evidence and incident handling out of date.

That gap matters most when access is created outside a central workflow, inherited through third parties, or held by non-human accounts that keep operating after business context changes. The control may still look “current” on paper while the effective access path has already drifted.

Because DORA is concerned with the resilience of the financial entity’s ICT environment, the question is whether the organisation can trust its access picture at the moment it needs it, not whether it once performed a quarterly review.

What becomes invisible between certification cycles

Periodic reviews miss the short-lived but high-impact changes that matter most in regulated operations: temporary supplier access, delegated admin grants, emergency elevation, and service or machine credentials that are created, reused, rotated, or left behind outside the review window. In practice, this means the control can fail exactly where access governance is supposed to reduce uncertainty.

Access Reviews and Certification Guide is useful here because it focuses on closing the loop on review campaigns rather than treating certification as a checkbox. A DORA-aligned program has to reduce stale entitlement windows, not simply produce a periodic attestation.

For machine identities and delegated accounts, the blind spot is often worse than for human users because no one notices the access until a dependency fails, a token persists too long, or the service keeps functioning after ownership has shifted.

Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs helps show why lifecycle visibility matters more than calendar-based review when access can outlive the business need that created it.

Why DORA turns access review gaps into resilience gaps

DORA raises the bar from “did we review access?” to “can we continue to operate, detect, and respond with confidence when access changes?” If current access state is unknown during an incident, teams may misread the blast radius, miss a compromised supplier path, or waste time validating who still has privileged reach. That slows containment and weakens evidence quality.

EU Digital Operational Resilience Act (DORA) is the authoritative reference point for that expectation, because it ties operational resilience to ICT risk, incident handling, and third-party control rather than to audit cadence alone.

Identity Security Regulatory Map is useful for practitioners who need to translate this into control ownership across access governance, third-party exposure, and regulatory obligations.

That is why periodic reviews are a weak proxy for resilience. They can prove that a review occurred, but they do not prove that the access graph is accurate at the moment resilience depends on it.

Risk and Threat Considerations

When access governance depends on periodic reviews, the main risk is stale privilege persisting unnoticed long enough to be exploited or to distort incident response. In a supplier-heavy or highly automated environment, the exposure is cumulative: more paths to review, more change between cycles, and less confidence that current access matches the approved state.

Failure mechanism: Access is granted, delegated, rotated, or inherited after the last certification cycle, so the record of approval lags behind the actual operating state. That creates unreviewed privilege creep, weakens attribution, and can hide an active compromise or an overbroad third-party path.

Impact: Teams lose trust in the access evidence they rely on for audit, containment, and recovery, which can turn a routine entitlement issue into a resilience failure under DORA. The practical consequence is slower incident response, poorer scoping, and higher exposure to business interruption.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while DORA and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
DORA Digital Operational Resilience Act DORA governs ICT resilience, third-party risk, and incident response, which are central to stale-access exposure.
Recommendation — Align access governance with resilience evidence so current privilege state is knowable during incidents.
NIST SP 800-53 Rev 5 AC-2 — Account Management Periodic reviews and revocation of stale access are core account-lifecycle controls.
IA-5 — Authenticator Management Machine identities and delegated access depend on managing credentials and their lifecycle.
AU-6 — Audit Record Review, Analysis, and Reporting Incident response and evidence quality depend on timely visibility into active access state.
Recommendation — Implement account lifecycle controls that remove or disable stale access between review cycles. Rotate, revoke, and expire authenticators so access cannot persist beyond its intended window. Correlate access changes and audit evidence so responders can reconstruct current privilege quickly.
ISO/IEC 27001:2022 A.5.18 — Access rights Access rights governance directly addresses review, adjustment, and removal of stale permissions.
Recommendation — Review and adjust access rights continuously enough to keep approval state aligned with actual use.
CIS Controls v8 CIS-5 — Account Management Account management controls reduce stale access and improve revocation discipline across users and services.
Recommendation — Inventory accounts and remove unused or excess access before the next certification cycle.

Practitioner Guidance

What to prioritise: Treat high-change access as a continuous-governance problem, not a periodic-attestation problem. Supplier accounts, delegated admin roles, break-glass access, and machine credentials should be measured by freshness, ownership, and revocation latency, not by whether they appear on the last review list.

What to verify: Before trusting a review campaign, verify that it covers the full access lifecycle, including non-human accounts, inherited entitlements, and out-of-band changes. If the review process cannot surface access created after the last cycle, it is not sufficient for a DORA resilience narrative.

Practitioner takeaway: Under DORA, the control objective is current access certainty. If you cannot answer “who can act right now?” with timely evidence, periodic reviews are documenting drift, not governing it.