No. Access reviews prove that a controlled process ran over a defined population, but they do not prove the population is complete or that risky identities have been found. In an incomplete identity estate, review completion can coexist with substantial unmanaged exposure.
What access reviews can and cannot prove
Access reviews are evidence of control execution, not proof that identity security is complete. They tell you a review happened against a defined population, with an owner, a reviewer and a result. They do not, by themselves, prove that the reviewed population included every active account, service principal, shared account or dormant identity that should have been in scope.
That distinction matters because identity security fails first at coverage. If discovery is weak, review campaigns can be cleanly completed while unmanaged identities remain outside the process. In practice, a passing review can coexist with stale accounts, missing ownership, long-lived credentials and privilege that was never brought into the review universe.
Teams often overread completion as assurance. The stronger question is whether the access review was anchored to a trustworthy inventory, current joiner-mover-leaver events and a clear entitlement model. Without those upstream controls, the review is still useful, but only as a partial check on the identities the organisation already knows about.
Why incomplete identity estates make reviews misleading
An access review only governs what it can see. If the estate is fragmented across directories, SaaS tools, cloud platforms, shared admin accounts and machine identities, a reviewer may never see the full set of risky access paths. That creates a false sense of closure, because the control is functioning while the estate itself is incomplete.
This is why IAM and IGA Basics matters here: access certification sits inside a broader governance model that depends on inventory, ownership, entitlement accuracy and deprovisioning. If any of those inputs are stale, the review can confirm process discipline without confirming identity security.
For the same reason, lifecycle controls are inseparable from review quality. NHI Lifecycle Management Guide and Joiner-Mover-Leaver (JML) Guide both reinforce the point that recertification works best when provisioning, change and deprovisioning are already disciplined. If identities are not created, moved and removed cleanly, the review process becomes a retrospective cleanup exercise rather than a reliable control.
Good programmes therefore treat reviews as one checkpoint in a chain. Discovery finds the population, lifecycle updates it, entitlements define it, and the review tests it. Break any link in that chain and a completed review no longer means the estate is secure.
What to do instead of using reviews as a proof point
Use access reviews as one signal in a control set, not as the headline measure of identity security. A stronger assurance story combines inventory quality, review completion, remediation closure, exception handling and evidence that orphaned or inactive identities are being found and removed.
One useful pattern is to pair certification with visibility and posture checks. Identity Visibility and Intelligence Platforms (IVIP) Guide helps teams identify what should exist before they certify what does exist, while Identity Security Posture Management (ISPM) Guide helps surface stale accounts, standing privilege and drift that reviews often miss. Together, they shift the question from “did the campaign finish?” to “did we actually reduce exposure?”
Access reviews should also be risk-shaped, not volume-shaped. If the reviewer is seeing thousands of low-context entitlements, the process tends toward rubber-stamping. If the review is targeted at high-risk access, recent movers, shared accounts and privileged relationships, it becomes a meaningful control instead of an administrative ritual.
Access Reviews and Certification Guide and Ultimate Guide to NHIs both point to the same operational reality: certification has to close the loop on risky access, not simply document that a campaign occurred.
Risk and Threat Considerations
Access reviews can create assurance theatre when the underlying identity estate is incomplete. That is risky because unmanaged accounts, excessive privilege and stale credentials may remain live even after a successful certification round, leaving the organisation exposed to misuse, persistence and lateral movement.
Failure mechanism: The review process validates only the records it was given, so gaps in discovery, ownership or lifecycle feed incomplete populations into the campaign. Attackers and insiders benefit when unmanaged identities sit outside the review scope, because those paths are less likely to be questioned or remediated.
Impact: Organisations may overstate their identity security posture, delay remediation of real exposure and miss the identities most likely to be abused in an incident. The result is not just poor reporting, but a larger blast radius when an account, token or service credential is compromised.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Access reviews depend on accurate account governance and review coverage. |
| Recommendation — Reconcile account inventories and review results to remove stale or unauthorized access. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access reviews are part of governing account lifecycle and reviewability. |
| IA-5 — Authenticator Management | Review outcomes depend on managing credentials and revocation for risky identities. | |
| Recommendation — Maintain authoritative account inventories and review active accounts on a defined cadence. Rotate and revoke compromised or long-lived authenticators promptly. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity review quality depends on correct identity lifecycle and ownership records. |
| A.5.18 — Access rights | Certification directly concerns reviewing and removing inappropriate access rights. | |
| Recommendation — Keep identity records current so access reviews are based on complete data. Review access rights routinely and remove unnecessary entitlements without delay. | ||
Practitioner Guidance
What to verify: Confirm that the review population is reconciled against authoritative sources, includes non-human and shared identities where relevant, and excludes no major system or business unit.
Common mistake: Treating campaign completion as a security outcome. Completion is only meaningful when you can also show removals, exception handling and a shrinking set of unmanaged identities.
What good looks like: Reviews are targeted, the population is current, remediation is tracked to closure, and posture metrics show fewer stale, orphaned and overprivileged identities over time.
Practitioner takeaway: An access review is a control over known identities, not a proof that the organisation has found all identities that matter.
Related resources from NHI Mgmt Group
- How should security teams run access reviews for non-human identities?
- What breaks when organisations treat device biometrics as proof of identity for remote access?
- How should security teams govern non-human identities that have persistent access?
- When do NHI access reviews create more value than a one-time cleanup?