Join our Newsletter — 33% off our NHI Course

Why do quarterly access reviews still leave the same violations in place?

Because recurring findings usually reflect upstream lifecycle problems, not just reviewer mistakes. If offboarding, role changes, contractor expiry, and access provisioning are not automated, the same orphaned, dormant, and excessive access patterns reappear every cycle. Quarterly certification then documents the problem instead of preventing it.

Why quarterly reviews miss the root cause

quarterly access review are a control checkpoint, not a lifecycle control. If the underlying joiner-mover-leaver process is weak, the review will keep rediscovering the same stale entitlements, orphaned accounts, and excessive privileges because nothing upstream changed. The review can confirm drift, but it cannot reliably remove the conditions that keep recreating it.

That is why the same violations survive from one campaign to the next. A reviewer may flag them correctly, but if provisioning, role changes, contractor expiry, and offboarding are still handled inconsistently, the access model keeps regenerating the exact same exceptions.

Quarterly cadence also creates a timing gap. Access can remain overprovisioned for weeks or months before it is challenged, which means the review becomes a delayed detection mechanism rather than a prevention mechanism. The longer the delay, the more “temporary” exceptions turn into normal state.

What usually keeps the violations in place

The common failure is not lack of visibility, it is lack of closure. Teams identify the violation, but they do not have a dependable path to revoke it, reassign ownership, or update the source record that caused it.

Typical upstream causes include:

  • termination or contractor end dates that do not trigger automatic deprovisioning;
  • mover events that do not remove old-role access when someone changes team or function;
  • role design that is too broad, so reviewers keep approving exceptions instead of shrinking entitlement scope;
  • shared or long-lived accounts that survive because no one owns the cleanup;
  • exceptions that are accepted once and then copied forward because the evidence trail is incomplete.

That is why Joiner-Mover-Leaver (JML) Guide is the more relevant control conversation than the review cycle itself: when lifecycle events drive access changes, repeat findings stop being a recurring audit artifact and start becoming a fixable process problem.

Where the issue is role structure rather than pure cleanup, Role Mining and Role Design Guide matters because poorly designed roles create systematic overreach that quarterly certification can only keep rediscovering.

How to make the next review actually reduce findings

The practical test is whether the review feeds a closed remediation loop. If every campaign ends with manual tickets but no source-of-truth correction, expect the same findings again. If the control is working, the next cycle should show fewer repeat exceptions, fewer inherited entitlements, and fewer “needs business approval” artifacts for the same users.

Use the review to target what should be removed, not just what should be recorded. The fastest way to improve outcome quality is to tie certification results to authoritative lifecycle events, ownership, and expiry dates so that a flagged entitlement can be revoked, not merely re-approved.

For recurring excessive access, a useful priority order is: remove access that is no longer justified, fix the upstream trigger that granted it, and then harden the exception process so the same pattern cannot be reintroduced without a new decision.

When the environment includes machine or service identities as well as people, Privileged Access Management Guide helps because standing privilege, shared admin credentials, and weak rotation practices tend to produce repeat violations that manual review alone does not eliminate.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Quarterly reviews expose stale accounts and entitlements that AC-2 is meant to govern.
IA-5 — Authenticator Management Recurring violations often persist because credentials and access material are not rotated or retired on time.
AC-6 — Least Privilege Repeated excessive access findings indicate privileges exceed operational need and are being preserved by review-only governance.
Recommendation — Automate account lifecycle events and recertification follow-up so invalid access is removed, not repeatedly reapproved. Enforce credential lifecycle controls so dormant or long-lived access cannot survive successive review cycles. Reduce entitlements to least privilege so certification validates necessity instead of preserving excess access.
CIS Controls v8 5 — Account Management The question centers on recurring account and entitlement violations across review cycles.
Recommendation — Continuously manage accounts and remove inactive or unnecessary access before the next review cycle.
ISO/IEC 27001:2022 A.5.18 — Access rights Repeated access violations directly concern granting, reviewing, and removing access rights.
Recommendation — Review and revoke access rights through a controlled lifecycle process, not only during periodic certification.

Practitioner Guidance

What to prioritise: Treat repeat findings as a remediation design problem first and a review-quality problem second. If the same issue appears every quarter, trace it back to the source event that created the access, not to the person certifying it.

What to verify: Check whether each recurring violation has a documented owner, a revocation path, and a lifecycle trigger. If any of those are missing, the review is only surfacing debt, not controlling it.

What good looks like: The next certification cycle should show fewer repeats of the same entitlement, shorter time-to-removal for invalid access, and fewer exceptions that survive unchanged across campaigns.

Practitioner takeaway: Quarterly access reviews work best as a backstop; if the same violations keep returning, the real fix is to automate lifecycle changes and make remediation authoritative, not manual.