Join our Newsletter — 33% off our NHI Course

What is the difference between annual access review and prompt termination of access?

Annual review is a scheduled governance check that identifies unnecessary access, while prompt termination is the immediate removal of access when the employment or contractor relationship ends. Both are needed, but they solve different problems. Review reduces drift over time, while termination closes the exposure window at the point of departure.

How annual access review and prompt termination differ in practice

Annual access review is a periodic governance activity. It looks back at who has access, whether that access is still justified, and whether permissions have drifted beyond current job or business need. Prompt termination is event-driven. It removes access as soon as the working relationship ends, so former staff, contractors, or suppliers do not retain a live pathway into systems.

The difference is mainly about timing and purpose. Review is a control for entitlement quality over time, while termination is a control for departure risk at the moment the relationship ends. Review can uncover stale or excessive access that accumulated quietly. Termination is the immediate containment step that prevents an ended relationship from becoming an active security exposure.

They also operate at different layers of the access lifecycle. Review is retrospective and governance-led, so it depends on good inventory, ownership, and timely certification decisions. Termination is operational and execution-led, so it depends on the offboarding process actually revoking accounts, tokens, roles, shared credentials, and any other access paths tied to the departing person or contractor. A clean review does not compensate for a failed offboarding step, and a fast offboarding does not remove the need to keep reviewing access that should never have accumulated.

Why both controls are needed across the access lifecycle

Annual review catches accumulated drift, inherited permissions, and access that has outlived its business purpose. Prompt termination closes the immediate exposure window when an individual leaves and their prior access can no longer be assumed safe. In mature programmes, the two controls work together: one reduces excess entitlement over time, the other prevents departure from becoming an orphaned-access problem.

For a practical control view, annual review is about assurance that access still matches current need, while termination is about revocation speed and completeness. The first question is “Should this access exist?” The second is “Does this access still exist after the person is gone?” A programme that only does annual review may still leave a departed user with active access for weeks or months. A programme that only offboards well may still allow privilege creep to build up between reviews.

That is why access review and deprovisioning usually sit in the same governance model, not as substitutes but as complementary safeguards. The review process gives the organisation a chance to clean up excessive access before it becomes entrenched, and termination ensures the access path ends when the relationship ends. For a deeper treatment of lifecycle controls, the NHI Lifecycle Management Guide and the Joiner-Mover-Leaver (JML) Guide both frame access as a lifecycle problem rather than a one-time provisioning task.

Where governance maturity matters, annual review is also the mechanism that surfaces whether termination is being executed reliably. If leavers consistently appear in review samples with lingering access, the problem is not the review itself, it is the offboarding control behind it. If you want a broad governance view, the IAM and IGA Basics guide explains how access review, entitlement management, and lifecycle control fit together.

What good control design should check, and what still goes wrong

Annual access review should not be treated as a box-ticking exercise. The useful question is whether the reviewer has enough context to decide if access is still needed, whether the access owner can prove the business justification, and whether the review outcome actually leads to removal. Prompt termination has its own failure mode: accounts may be disabled but tokens, service credentials, VPN access, federation paths, or shared secrets may remain valid if the offboarding process is incomplete.

The most common mistake is assuming that one control covers the other. It does not. Review can miss a recently departed contractor if the next cycle is months away. Termination can miss dormant access that was never tied to a departure event. Strong programmes therefore use review to reduce excess access and termination to remove it quickly at exit, with both feeding the same access governance record.

In practice, the best signal is closed-loop remediation. A review outcome should be visible as a removal action, and an offboarding event should be visible as a confirmed revocation set, not just a HR status change. If you need a structured review model, Access Reviews and Certification Guide covers how to make recertification actionable instead of ceremonial. For the lifecycle end state, Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is a useful model of provisioning through offboarding discipline.

Risk and Threat Considerations

Annual review and prompt termination reduce different forms of exposure. Review limits long-lived entitlement drift, but it is too slow to stop immediate misuse after a person leaves. Termination blocks the obvious post-departure access path, but if it is incomplete, a former insider may retain a live route into systems through an account, token, or shared credential.

Failure mechanism: Access remains active because governance is periodic while departure risk is immediate, or because offboarding revokes one path but leaves another usable credential, session, or delegated access behind.

Impact: Organisations can end up with stale accounts, excessive privilege, or a post-employment access window that supports unauthorised access, data exposure, or later misuse of retained credentials.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Annual review and prompt termination both depend on account lifecycle governance.
AC-6 — Least Privilege Access review exists to remove excess permissions and keep entitlements minimal.
IA-5 — Authenticator Management Prompt termination must revoke or invalidate authenticators, tokens, and other access material.
Recommendation — Use AC-2 to review accounts periodically and disable access promptly when it is no longer needed. Apply AC-6 to remove unnecessary access discovered during review and offboarding. Use IA-5 to invalidate authenticators and credential material when access ends.
ISO/IEC 27001:2022 A.5.18 — Access rights The topic is about reviewing and removing access rights across the lifecycle.
A.5.15 — Access control Both controls are part of access control governance and enforcement.
A.5.16 — Identity management Termination depends on managing identities through joiner-mover-leaver processes.
Recommendation — Review access rights regularly and revoke them promptly when the relationship ends. Define access control rules that support periodic review and immediate revocation. Keep identity records current so departures trigger immediate access removal.
CIS Controls v8 CIS-5 — Account Management The subject is fundamentally about governing accounts and removing stale access.
Recommendation — Use account management controls to certify access and revoke accounts quickly at departure.

Practitioner Guidance

What to prioritise: Treat leaver handling as a same-day control and access review as a periodic control with a separate objective. If a user has departed, revocation completeness matters before the next review cycle; if a user is still active, review should focus on whether access is still justified, not just whether it exists.

What to verify: Offboarding should confirm removal of human and non-human access paths tied to the departure, including roles, tokens, shared credentials, and delegated access. Access review should confirm that every retained entitlement has a current owner and a business reason, and that removals are actually executed rather than merely approved.

Practitioner takeaway: Annual review manages entitlement drift, but prompt termination manages the exposure window at exit, so mature access governance needs both a periodic cleanup cycle and a fast revocation path.