Join our Newsletter — 33% off our NHI Course

Should access reviews be tied to joiner mover leaver events instead of quarterly cycles?

Yes, when the environment changes quickly. Event-driven reviews are better when role changes, contractor end dates, and privileged access grants create the real risk moment, because they align governance with actual identity change rather than a fixed calendar.

Why event-driven access reviews fit JML better than fixed quarterly cycles

Access reviews work best when they are aligned to the moment access actually changes. Quarterly certification can still be useful as a backstop, but JML-triggered reviews are sharper for movers, leavers, contractor expiry, temporary elevations, and role changes because those events create the highest probability of stale or excessive access.

That timing matters because the governance question is not just whether access exists, but whether it is still justified by the current employment state, job function, or engagement terms. When identity state changes quickly, a calendar review often arrives too late to prevent unnecessary exposure.

For a practical model of how identity lifecycle and access governance fit together, IAM and IGA Basics is the right foundation, and the JML workflow is the natural trigger point for review.

What changes when reviews are event-driven

Event-driven reviews shift the control from periodic sampling to change-based governance. Instead of asking, “Who still looks risky this quarter?” the organisation asks, “What changed today that could make existing access no longer appropriate?” That is a better fit for fast-moving environments, especially where HR events, contractor offboarding, and privilege grants happen continuously.

The operational benefit is smaller review scope with higher signal. Reviewers can focus on the delta created by a move or leaver event, rather than re-certifying the same low-risk entitlements on a fixed schedule. That reduces reviewer fatigue and makes it more likely that exceptions, inherited access, and privilege creep are actually noticed.

That is also why strong JML execution is the prerequisite. Joiner-Mover-Leaver (JML) Guide shows how lifecycle events should drive provisioning and deprovisioning, while Access Reviews and Certification Guide explains how to make review campaigns actually remove access rather than rubber-stamp it.

When quarterly cycles still belong in the model

Quarterly reviews are still useful as a control safety net. They help catch misses in event detection, bad integrations, manual exceptions, and access that may not be tied to a clean lifecycle event, such as inherited entitlements or lingering access from older systems. In other words, periodic review is a backstop for control gaps, not the primary detection mechanism for fast identity change.

A mature program usually uses both: event-driven review for the high-risk moments, plus periodic recertification for residual access, coverage assurance, and governance evidence. That hybrid approach is especially important where entitlements are spread across many applications or where not every system can emit a reliable JML signal.

For role and entitlement-heavy environments, the question is often less “quarterly or event-driven” and more “which access should be continuously event-triggered, and which access still needs periodic confirmation?” Role Mining and Role Design Guide helps reduce unnecessary review volume by making roles cleaner, while IGA Buyer’s Guide is useful when you are evaluating tooling that can support both event-driven and periodic review patterns.

Risk and Threat Considerations

When access reviews stay on a fixed quarterly cycle, stale access can persist long after the business reason has disappeared. The risk is highest for movers who inherit old-role entitlements, contractors whose end dates pass unnoticed, and privileged users whose access should be time-bounded. The longer the delay between change and review, the larger the exposure window.

Failure mechanism: JML events are not connected to review triggers, or the trigger exists but is not enforced with enough completeness, so changed identities keep access until the next calendar cycle. That creates privilege creep, orphaned access, and delayed revocation.

Impact: Unnecessary access can be abused internally, inherited by mistake, or exploited after compromise. In higher-risk environments, this can widen blast radius, complicate investigations, and leave audit evidence out of sync with the actual access state.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Access reviews are part of keeping account access current across joiner, mover, leaver events.
Recommendation — Automate account review triggers around lifecycle changes and remove stale access promptly.
NIST SP 800-53 Rev 5 AC-2 — Account Management Lifecycle-driven review and revocation map directly to account maintenance and disabling obsolete access.
IA-5 — Authenticator Management Mover and leaver events often require credential and authenticator renewal or revocation alongside access review.
Recommendation — Tie account reviews to lifecycle events and disable accounts when access is no longer justified. Revoke or rotate authenticators when identity state changes and privileges are reassigned.
ISO/IEC 27001:2022 A.5.18 — Access rights Access rights should be reviewed and adjusted when employment or engagement status changes.
A.5.16 — Identity management JML events are identity lifecycle changes that should drive access governance decisions.
A.8.2 — Privileged access rights Privileged access changes are the highest-risk moments for event-driven review.
Recommendation — Review access rights on lifecycle events and remove rights that no longer match business need. Link identity lifecycle events to provisioning, change, and removal workflows. Review privileged access immediately when roles, duties, or contracts change.
OWASP Non-Human Identity Top 10 NHI-01 — Improper Offboarding Leaver-driven access review is essential to avoid lingering machine or non-human access after offboarding.
NHI-05 — Overprivileged NHI Mover events can leave non-human identities with access that no longer matches current function.
Recommendation — Trigger offboarding reviews at the lifecycle event and revoke lingering non-human access. Re-certify non-human privileges when lifecycle changes alter the required scope.

Practitioner Guidance

What to prioritise: Trigger immediate reviews on movers, leavers, contractor terminations, and privileged access grants first. Those events are where the risk changes materially, so they deserve shorter review windows than routine quarterly recertification.

What to verify: Confirm that the review trigger is tied to the authoritative lifecycle source, not a manual notification path. If the HR, vendor, or identity event is incomplete, the review will look “event-driven” on paper while still missing the real change.

Decision rule: If the entitlement can change the user’s ability to reach sensitive systems, treat the JML event as the primary review moment; if the access is broad, inherited, or hard to classify, keep a periodic backstop as well.

Practitioner takeaway: Event-driven reviews should handle the moment risk changes, while quarterly cycles should verify what the event logic may miss. The best program uses the calendar as a safety net, not as the main control.