Join our Newsletter — 33% off our NHI Course

When should organisations prioritise continuous identity evidence over quarterly access reviews?

Prioritise continuous evidence when identities change frequently, access is delegated across cloud and SaaS, or auditors need proof of control operation rather than policy intent. Quarterly reviews can still exist, but they should consume live evidence, not replace it. Continuous control is especially important where NHIs and AI agents can alter access faster than human review cycles.

Why continuous evidence is the better control signal

continuous identity evidence is the better control signal when the real question is whether access is operating correctly right now, not whether a review happened on schedule. Quarterly recertification is still useful for accountability, but it is too slow for environments where identities are ephemeral, delegated, or machine-operated. In those settings, drift can appear and disappear between review cycles.

This is especially true when access is granted through cloud IAM, SaaS admin roles, or delegated workflows that change more often than the review calendar. A quarterly list can confirm that someone signed off on a role; it cannot, by itself, show whether the role was active, inherited, overextended, or already remediated yesterday. Continuous evidence closes that gap by showing control operation, not just control intent.

For identity programmes, the practical shift is from periodic attestation to ongoing observability. That means evidence from provisioning events, entitlement changes, revocations, exceptions, and logging should be available in near real time and retained in a way auditors can trace. Organisations that use IAM and IGA Basics as a baseline usually find that continuous evidence becomes the operational layer that makes access review outcomes defensible.

Where quarterly reviews still help, and where they fall short

Quarterly reviews still have value when you need formal accountability, owner sign-off, or a governance checkpoint for business-critical roles. They are good at confirming whether access should exist in principle. They are weaker at showing whether the underlying control has actually been keeping pace with change, especially in high-churn environments or where many entitlements are inherited through groups, roles, or integrations.

The break point is usually not the review cadence itself, but the mismatch between cadence and change rate. If the population changes daily, the review becomes a retrospective summary, not a control. In practice, Access Reviews and Certification Guide is most relevant when the organisation needs to reduce review noise and feed reviewers with evidence that already reflects live access state.

Continuous evidence also matters when the audit objective is proof that controls operated over time. Quarterly attestation can satisfy process documentation, but not always control effectiveness. That distinction becomes important when auditors, internal assurance teams, or regulated stakeholders want to see how quickly access drift was detected, whether revocation happened, and whether exceptions were handled before the next cycle began.

When identity dynamics make continuous evidence essential

Continuous evidence should move to the front when access is delegated across cloud, SaaS, workloads, service identities, or agents that can change permissions without waiting for a human approval loop. In those cases, the access population is not just large, it is dynamic. A quarterly review can miss short-lived privilege spikes, stale delegations, or orphaned non-human access that persists after the business purpose has ended.

That is why lifecycle visibility and offboarding discipline matter so much in this decision. If you cannot reliably show provisioning, rotation, and revocation as events, then the review process is depending on stale state. The NHI Lifecycle Management Guide and Joiner-Mover-Leaver (JML) Guide both support the operational view that access should be validated continuously where the entity can move faster than the review calendar.

AI agents sharpen this need further because they can receive, use, and sometimes propagate access in ways that are hard to capture in a quarterly snapshot. When agent actions are part of the control surface, evidence must show what was granted, what was actually used, and what was revoked when the task or delegation ended. For that reason, AI Agent Observability, Audit and Incident Response Guide is a useful companion where agent activity is part of the access story.

Risk and Threat Considerations

Quarterly reviews create a blind spot when access can change faster than the certification cycle. The risk is not just missed excess access, it is that an attacker or negligent operator can exploit a window of standing privilege before the next human review notices the drift. Continuous evidence reduces that window by showing whether control operation and revocation are happening as expected.

Failure mechanism: A control that depends on periodic sampling can miss short-lived privilege escalation, delegated access sprawl, stale credentials, or agent-driven changes that occur between review dates.

Impact: Excess access can persist long enough to enable misuse, weaken audit defensibility, or delay containment after a change, even when the quarterly review itself is eventually completed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Continuous identity evidence depends on ongoing auditability of access changes and revocations.
AC-2 — Account Management The question is about whether access changes are governed continuously rather than only at review intervals.
IA-5 — Authenticator Management Continuous evidence is needed when credentials and tokens can change faster than quarterly review cycles.
Recommendation — Correlate entitlement and revocation events so reviewers can validate access state from current logs. Continuously track account lifecycle events and reconcile them against access attestations. Monitor credential issuance, rotation, and revocation as live control evidence.
NIST CSF 2.0 GV.OV-01 — Oversight of Cybersecurity Risk Ongoing evidence supports oversight that control operation is effective, not merely documented.
Recommendation — Use live control evidence to verify that governance decisions are operating in practice.
ISO/IEC 27001:2022 A.5.15 — Access control Continuous evidence strengthens the operating proof behind access control decisions.
Recommendation — Record current access-state evidence so periodic reviews verify reality, not intent.

Practitioner Guidance

What to prioritise: Prioritise continuous evidence for identities whose permissions change frequently, whose access is inherited or delegated, or whose compromise would have immediate operational impact. Keep quarterly reviews for accountability, but treat them as the governance wrapper around live control telemetry, not the primary proof of effectiveness.

What to verify: Make sure the evidence set covers grant, modify, revoke, exception, and usage events, not just review completion. If you cannot tie a reviewer’s decision back to a current entitlement state, the review is being asked to do work that evidence should already have done.

Practitioner takeaway: Use quarterly access reviews to confirm ownership and decision-making, but use continuous identity evidence to prove the access model is actually under control between those checkpoints.