Organisations should route campaigns with fallback reviewers, role-based assignment, and multi-level approvals so the process survives leave, turnover, and distributed ownership. This is especially important in companies with subsidiaries or multiple app owners, where a single approver model does not reflect how access is actually managed.
Why access review campaigns stall in the real world
access review campaigns usually stall when the workflow assumes a single owner, a single approver, or a static org chart. Leave, role changes, business-unit fragmentation, and unclear entitlement ownership create dead ends. The campaign is then blocked not by policy intent, but by missing decision makers, unanswered exceptions, and review queues that cannot be reassigned cleanly.
For access governance teams, the practical issue is not just completion rate. A stalled campaign also undermines reviewer accountability, delays remediation, and turns the review into a point-in-time exercise rather than a live control.
How fallback reviewers and role-based assignment keep the workflow moving
The most reliable way to prevent stalling is to make reviewer assignment resilient before the campaign starts. That means defining backup reviewers, mapping approvals to roles or business functions, and using delegation rules that let the campaign continue when an owner is absent. The design should reflect how access is actually managed, not how the organisation wishes ownership worked in theory.
This is where role design and governance structure matter. A campaign that depends on one manager to approve every entitlement will fail in matrixed organisations, subsidiaries, shared services models, or environments with many application owners. Role Mining and Role Design Guide is useful here because it treats the role model as an operating control, not just an entitlement label. IAM and IGA Basics provides the broader governance context for reviewer assignment, entitlement ownership, and access certification.
In practice, role-based assignment should answer two questions in advance: who can approve if the primary reviewer is unavailable, and which role or business unit should own the decision if the original approver is no longer valid? If that logic is built into the campaign design, the workflow can continue without manual rescue every time a person changes job or leaves.
What good campaign design looks like when ownership is distributed
Well-run campaigns separate the control objective from the individual approver. The control objective is to confirm that access is still justified, while the approver may be the manager, the application owner, the role owner, or a delegated reviewer depending on the entitlement type. Multi-level approvals help when a single review is not enough to represent both business need and technical ownership.
That becomes especially important where different organisations or subsidiaries manage access differently. A central team may run the campaign, but local owners often know whether a privilege is still needed. Access Reviews and Certification Guide is directly relevant because it focuses on reducing rubber-stamping, using more context, and closing the loop after certification. IGA Buyer’s Guide is also helpful for evaluating whether a platform can support fallback reviewers, workflow routing, and review reassignment without manual intervention.
When campaigns span many applications, the important design question is whether the system can still reach a decision when the first reviewer path fails. If the answer is no, the organisation is effectively relying on perfect attendance, which is not a control design.
Risk and Threat Considerations
Stalled campaigns create control debt. Unfinished reviews leave excessive access in place longer than intended, delay remediation, and make it easier for dormant, shared, or misassigned access to persist unnoticed across business units and subsidiaries.
Failure mechanism: The campaign cannot complete because the designated reviewer is unavailable, the ownership model is stale, or the workflow has no valid delegate or fallback path, so exceptions accumulate and overdue items remain unresolved.
Impact: Access that should have been recertified or removed stays active, which increases exposure to privilege creep, orphaned ownership, and delayed detection of inappropriate access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews and fallback approvals support ongoing account governance and entitlement oversight. |
| AC-6 — Least Privilege | Campaigns aim to remove unnecessary access and keep privileges justified. | |
| AU-6 — Audit Review, Analysis, and Reporting | Stalled campaigns need auditable evidence of review completion, delegation, and exceptions. | |
| Recommendation — Use AC-2 to govern account ownership, approval paths, and periodic access recertification. Use AC-6 to remove excess entitlements when reviews show no business need. Use AU-6 to retain review evidence and exception handling records for certification campaigns. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access reviews directly support periodic review and adjustment of access rights. |
| A.5.15 — Access control | Fallback reviewers and role-based assignment are access control governance mechanisms. | |
| Recommendation — Use A.5.18 to review and adjust access rights on a defined schedule. Use A.5.15 to define access approval paths and governance responsibilities. | ||
Practitioner Guidance
What to prioritise: Build the fallback logic before launching the campaign, not after the first reviewer disappears. The highest-value control is usually a routing model that can reassign by role, business unit, or entitlement class without losing approval traceability.
What to verify: Confirm that every high-volume access category has at least one alternate decision path and that delegated reviewers are actually authorised to approve that class of access. If a backup reviewer cannot see the same context as the primary owner, the fallback exists only on paper.
Practitioner takeaway: Access review programmes stall when ownership is treated as a person, not a governed workflow. The durable fix is to make reviewer assignment resilient enough that absence, turnover, and distributed administration do not stop certification from reaching a decision.
Related resources from NHI Mgmt Group
- When should organizations review access controls?
- How should security teams design access certification campaigns to keep reviews sustainable in large organisations?
- Why do lifecycle gaps keep showing up in access review campaigns?
- How should security teams run access reviews for non-human identities?