Join our Newsletter — 33% off our NHI Course

Should organisations review employee, vendor, and service-account access together?

Yes. Separating them creates governance gaps because the same business process often governs all three, but the risk profile is shared. A single review model gives security teams a full view of who can reach what, makes privilege creep easier to spot, and reduces the chance that offboarding or delegated access is missed.

Why a Single Access Review Model Works Better

Employee, vendor, and service-account access are often managed through the same business process, even if the underlying identity type differs. Reviewing them together gives one view of entitlement scope, ownership, and separation of duties, which makes privilege creep easier to spot and prevents narrow review processes from missing inherited or delegated access.

It also reduces the common failure mode where each group is reviewed in isolation and no one reconciles overlaps, shared systems, or access granted for a vendor relationship that later persists after the work is complete.

How Shared Reviews Expose Governance Gaps

Separate review tracks can hide the full path to a system. A contractor might appear low risk in a vendor list, while the service account tied to that vendor still has production access, or an employee and their assigned automation may both retain the same effective privilege after a role change.

A combined review forces teams to ask the more useful question: who can reach this asset, by what path, and whether that access is still justified by the current business process. That framing is especially important when review ownership is split across IAM, procurement, operations, and application teams.

When organisations review these populations together, they can compare entitlement patterns, detect excessive access that would otherwise look normal inside a single population, and spot stale access that survives termination, offboarding, or project completion. It also improves evidence quality because reviewers see the full access chain rather than a partial snapshot.

What Good Looks Like in Practice

A workable model starts with a unified inventory of workforce, third-party, and non-human access, then applies one review standard with context-sensitive evidence. Human users, vendors, and service accounts may not be approved by the same person, but they should be assessed in the same campaign or control cycle so exceptions, ownership, and remediation are visible in one place.

The strongest programmes also align review cadence to risk. High-privilege roles, production service accounts, and externally sponsored access need tighter review and faster remediation than low-risk entitlements, but the governance model should still be shared so the team can compare outcomes consistently. NHI Management Group’s Access Reviews and Certification Guide is useful here because it focuses on designing reviews that reduce volume while increasing context.

Risk and Threat Considerations

When these populations are reviewed separately, organisations can miss the compound risk created by shared business relationships, inherited privileges, and long-lived non-human access. That gap matters because a missed vendor entitlement or forgotten service account often survives longer than a typical employee permission and may retain production reach after the original justification has expired.

Failure mechanism: Fragmented review ownership breaks the chain between user access, vendor sponsorship, and machine or service access, so stale privileges are not reconfirmed together and offboarding actions do not fully remove reach.

Impact: Privilege creep, orphaned access, and delayed revocation increase the chance of unauthorised system access, lateral movement, and audit failures, especially where service accounts or delegated access can still act after the human relationship ends.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Unified access reviews depend on complete account inventory and periodic review.
AC-6 — Least Privilege Combined reviews help detect excess access across employees, vendors, and service accounts.
IA-5 — Authenticator Management Service-account and vendor access reviews often expose stale credentials and weak lifecycle controls.
Recommendation — Review all account types together and remove stale entitlements promptly. Validate each entitlement against current job need and reduce unnecessary privilege. Track credential lifecycle and rotate or revoke authenticators when access changes.
ISO/IEC 27001:2022 A.5.18 — Access rights Access-rights reviews must cover who has access and whether it remains justified.
A.5.16 — Identity management The question concerns governing multiple identity populations under one review model.
A.8.2 — Privileged access rights High-risk access needs unified review because privilege creep often hides across separate populations.
Recommendation — Periodically recertify access rights across all identity populations. Maintain one identity governance model that covers workforce, third-party, and service identities. Apply tighter review and approval for privileged access regardless of identity type.
CIS Controls v8 CIS-5 — Account Management CIS account management directly supports periodic review of user, vendor, and service accounts.
CIS-6 — Access Control Management The answer is fundamentally about controlling and reviewing access consistently across populations.
Recommendation — Inventory accounts and review them for validity, ownership, and necessity. Centralize access control decisions and remove access that lacks current justification.
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication and Access Control Shared review of identities and entitlements fits the CSF access-control function.
Recommendation — Use one access review process to verify authorized access across all identity types.

Practitioner Guidance

What to prioritise: Review access by business process first, then separate the evidence by identity type. That lets you keep one governance workflow while still applying different approvers, risk thresholds, and remediation paths for employees, vendors, and service accounts.

What to verify: Confirm that each entitlement has a current owner, a current business justification, and a clear removal path. If a reviewer cannot explain why the access exists today, treat that as a governance defect, not a documentation issue.

Decision rule: If the same system or process grants access to more than one identity population, assess them in one certification cycle. If the populations are split only for reporting convenience, that is usually a sign the control is too weak to see real risk.

Practitioner takeaway: The goal is not to force every identity into one approval bucket, but to make sure every meaningful access path is reviewed in the same governance frame so nothing slips through the seams.