Quarterly reviews create less value because identity environments change continuously between campaigns. Roles shift, contractors leave, new permissions appear, and excessive access can sit active for months before anyone sees it. The longer the gap, the more the review becomes evidence of compliance rather than reduction of exposure.
Why quarterly access reviews lose value between campaigns
Quarterly reviews are a snapshot, but access risk moves every week. By the time a campaign opens, the current state may already differ from the one it is certifying, so the review often confirms historical approvals instead of finding today’s excess access. The value falls further when reviewers face too much volume and too little context.
What changes in the access environment faster than quarterly cadence
Modern access environments are dynamic: people change roles, contractors roll off, service ownership shifts, and entitlements accumulate through projects, exceptions and one-off approvals. That means the question is not whether access was once valid, but whether it is still justified now. A structured access review process has to be frequent enough to catch those changes before they become normalised.
Quarterly cadence also makes stale access easier to hide inside ordinary business churn. When reviewers see a long list of entitlements long after they were granted, the context that justified them is often missing, so the campaign becomes a memory test rather than an access decision. That is why access review value rises when the review is triggered by events such as role change, termination, or elevated access creation.
The same issue appears in longer-lived machine and service access, where access can stay active long after the original task has ended. IAM and IGA basics matter here because governance is only useful when it reflects the lifecycle of real identities, not a calendar cycle that ignores how quickly entitlements drift.
Why long gaps turn reviews into compliance theatre
When reviews are infrequent, teams tend to optimise for completion instead of remediation. Approvers click through familiar names, managers inherit entitlements they do not understand, and unresolved exceptions pile up until the next campaign. The result is a review that can prove a control existed, but cannot prove that exposure was reduced in time.
That is especially weak for privileged or high-impact access, where the business consequence of delay is much larger than the administrative effort of frequent review. A quarterly campaign can still be useful as a governance checkpoint, but it should not be the only control detecting entitlement creep, orphaned access, or missing offboarding. Privileged access management is often the better companion control because it reduces standing exposure instead of waiting for the next certification round.
Quarterly review also becomes less valuable when the organisation cannot close the loop quickly. If revocations are delayed, re-grants are manual, or ownership is unclear, the campaign may generate findings without materially changing the exposure window. In practice, the control starts to measure documentation quality more than actual risk reduction.
How to make reviews useful again
Access reviews regain value when they are tied to change, risk and actionability rather than calendar compliance. Reviews should prioritise high-risk roles, privileged entitlements, contractors, dormant access and recent changes, because those are the places where a stale permission is most likely to matter. Joiner-Mover-Leaver controls are the practical way to shrink the gap between an event and the access decision.
Useful reviews also need better evidence for the reviewer: owner, last-used data, business justification, expiration date and whether the entitlement is tied to a current function. Without that context, approval becomes habit. Identity visibility and intelligence improves the review because it turns a static list into a risk-informed decision set.
Where entitlement structures are messy, role cleanup is part of the answer, not a separate project. Role mining and role design reduce review noise by making it easier to certify meaningful roles instead of endless individual exceptions. The best review programme removes access, it does not just record votes on it.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Access reviews depend on actionable visibility into current entitlements and changes. |
| AC-2 — Account Management | Quarterly reviews are part of ongoing account governance and entitlement cleanup. | |
| IA-5 — Authenticator Management | Long-lived credentials and stale authenticators can keep access active between review cycles. | |
| Recommendation — Use AU-6 to review access-change evidence and drive timely remediation of excessive access. Use AC-2 to recertify accounts, disable stale access, and remove unnecessary entitlements. Use IA-5 to rotate, expire, and revoke authenticators that outlive their business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | Access reviews are an account-management safeguard that reduces stale and excessive access. |
| Recommendation — Use CIS-5 to remove inactive accounts and validate access against current job need. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Quarterly certification is an access-rights governance activity under Annex A. |
| Recommendation — Review access rights on a schedule that reflects business change, then revoke excess promptly. | ||
Practitioner Guidance
What to prioritise: If the review cannot reliably produce a revoke-or-keep decision with current business context, shorten the interval for high-risk access and trigger event-based reviews for movers, leavers, and elevated permissions.
What to verify: Confirm that every review item has an owner, a current business reason, and a revocation path that works immediately after approval. If those three are missing, the campaign is mostly administrative.
Common mistake: Treating quarterly completion rates as the success metric. A high completion rate is not strong evidence of reduced exposure if stale access remains live between campaigns.
Practitioner takeaway: The right question is not whether a quarterly review was completed, but whether it removed material access risk before the next business change made the review obsolete.