TL;DR: Access reviews often satisfy auditors while still consuming 149 person-days per cycle, leaving 25,000 data points, 18-day remediation delays, and recurring violations hidden in the process, according to Zluri. The real issue is not completion but governance design: manual review models are too slow, too broad, and too weak to reduce risk.
At a glance
What this is: This is an IAM governance analysis of why quarterly access reviews look compliant on paper but still break down under scale, with recurring violations, long remediation delays, and high manual effort.
Why it matters: It matters because identity teams need access review designs that actually reduce risk across human users, NHIs, and delegated access paths, not just produce audit evidence.
Context
Access reviews are meant to confirm that people still have the right access, but the model becomes brittle when the number of applications, entitlements, and reviewers grows faster than the team can assess them. In that situation, the programme can look compliant while still missing exposed access, delayed removals, and repeated violations.
The article argues that the deeper problem is not the existence of reviews but the design of the governance process around them. For IAM and IGA teams, the practical question is whether review cycles are validating access state or simply documenting that a large manual task was completed.
Key questions
Q: What breaks when access reviews rely on spreadsheets and other manual tracking methods?
A: Spreadsheets and other manual methods break down when access volume, role churn, and system integrations grow. Teams lose visibility into who has access, miss dormant accounts, and fail to spot excessive permissions in time. Manual reviews also tend to become rubber-stamps, which means the process checks a box without actually reducing security risk or improving compliance confidence.
Q: Why do quarterly access reviews still leave the same violations in place?
A: Because recurring findings usually reflect upstream lifecycle problems, not just reviewer mistakes. If offboarding, role changes, contractor expiry, and access provisioning are not automated, the same orphaned, dormant, and excessive access patterns reappear every cycle. Quarterly certification then documents the problem instead of preventing it.
Q: How can IAM teams tell whether access review coverage is actually meaningful?
A: They should measure what was excluded as well as what was approved. A strong completion percentage over a weak denominator hides the systems, roles, and accounts that never entered the campaign, and those blind spots are often where stale access survives longest.
Q: Should organisations prioritise continuous monitoring over periodic certification?
A: They should treat certification as necessary but insufficient, then prioritise continuous monitoring for controls that can fail quickly, especially access, identity, and third-party dependencies. Periodic certification still matters for governance, but only live validation shows whether the control is effective when the environment changes after the audit window closes.
Technical breakdown
Why spreadsheet-based access reviews break at scale
Manual certification workflows collapse when reviewers are asked to assess thousands of user-to-application relationships with little context. The article shows how this creates approval fatigue, slow turnaround, and recurring findings that do not materially improve governance. The technical issue is not only human effort, but the absence of machine-assisted filtering, grouping, and decision support that can reduce the review surface to what actually needs judgment.
Practical implication: Use risk-based filtering and grouping so reviewers see exceptions, not every entitlement.
Why group-based certification changes the governance model
Group-based reviews shift the unit of certification from individual access grants to role or group assignments. That works because provisioning already happens through group structures in many environments, yet review processes often ignore them and re-litigate the same access repeatedly. The governance benefit is a smaller decision set, fewer redundant reviews, and better alignment between the way access is assigned and the way it is certified.
Practical implication: Align certification workflows to the same group and role structures used for provisioning.
How closed-loop remediation closes the gap between decision and control
A review process only changes risk if the revocation decision actually reaches the target system and is confirmed. The article describes the common failure mode where decisions move into tickets, spreadsheets, and manual follow-up, which creates long delays and weak accountability. Closed-loop remediation connects decision capture, execution, validation, and proof so that the control outcome is enforced instead of merely recorded.
Practical implication: Automate revocation execution and confirmation for the systems that support API-based remediation.
NHI Mgmt Group analysis
Access review scale has become a governance design problem, not a compliance task. Once the review population reaches tens of thousands of entitlements, the limiting factor is no longer auditor expectation but human review capacity. The article shows that the control can be completed on schedule while still leaving large numbers of repeated violations unresolved. The practitioner lesson is that scale changes the nature of the control from certification to triage.
Identity review programmes fail when they treat visibility, certification, and remediation as separate steps. If the platform cannot see all apps, review the right unit of access, and execute revocations without manual handoffs, the process degrades into documentation. That is why completed reviews can coexist with recurring violations quarter after quarter. The practitioner conclusion is that governance design must bind those stages together.
Access reviews are only as strong as the upstream lifecycle that feeds them. The recurring orphaned accounts, dormant access, permission creep, and contractor overstay patterns described in the article all point to lifecycle defects rather than isolated review errors. Recurring access-violation debt: the same findings reappear because the process records exceptions after the fact instead of preventing them at joiner-mover-leaver points. Practitioners should treat review findings as evidence of lifecycle control gaps.
Continuous governance is becoming the practical baseline for IAM programmes. Quarterly recertification still has compliance value, but it is no longer enough to meaningfully reduce exposure in fast-moving application estates. The article’s core signal is that review cadence, remediation speed, and discovery coverage now determine whether the control reduces risk or simply produces evidence. IAM leaders should measure whether reviews are shrinking the attack surface, not just closing tickets.
From our research library:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
- Read next: Access Reviews and Certification Guide
What this signals
Recurring access-violation debt: review programmes often discover the same orphaned accounts, dormant entitlements, and contractor overstay because the upstream lifecycle is still manual. When that pattern repeats, the certification process is not the control that failed. The lifecycle feeding it failed, and the review is only exposing the damage.
Scale changes the control boundary: once access reviews cover thousands of entitlements, the meaningful security question becomes whether the process can see all relevant applications, assign the right reviewer, and execute the decision without delay. If any of those steps remain manual, the programme is a reporting mechanism more than a governance control.
For practitioners
- Map hidden application coverage Compare identity-provider-visible applications with finance, browser, desktop, MDM, and CASB discovery sources to find the applications that reviews are currently missing.
- Certify groups before users Review role and group assignments first, then validate membership only where needed, so certification follows the structure already used to provision access.
- Automate revocation execution Connect review decisions to application APIs so approved removals are executed and confirmed without waiting on ticket queues or spreadsheet follow-up.
- Track recurring violation patterns Classify repeated findings such as orphaned accounts, dormant access, permission creep, and contractor overstay, then use those patterns to identify upstream lifecycle gaps.
Key takeaways
- The article shows that access reviews can be completed on time and still fail to reduce risk when the workflow is too manual, too broad, and too slow to remediate.
- The evidence cited includes 149 person-days per cycle, 25,000 data points, 18 days of remediation delay, and repeated findings in every quarter.
- The control improves only when visibility, grouping, automation, and upstream lifecycle fixes are connected into one operating model.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article is about certifying and governing access permissions at scale. |
| Recommendation — Apply PR.AA-05 to align access certification, entitlement review, and revocation with actual access structures. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Repeated violations point to excess access and poor entitlement governance. |
| Recommendation — Use AC-6 to reduce standing access and remove permissions that reviews repeatedly flag. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | The article repeatedly cites orphaned accounts and contractor access overstays. |
| Recommendation — Tie offboarding workflows to NHI-01 so access is revoked when the relationship ends. | ||
| CIS Controls v8 | CIS-5 — Account Management | The article focuses on account lifecycle control and certification of active access. |
| Recommendation — Use CIS-5 to standardise account review, revocation, and lifecycle accountability. | ||
| ISO/IEC 27001:2022 | A.8.2 — Privileged Access Rights | Access reviews must validate who still holds elevated or inappropriate access. |
| Recommendation — Review privileged access rights under A.8.2 and remove entitlements that no longer match business need. | ||
Key terms
- Access Review: A formal process for confirming whether access is still needed and justified. In IAM programs, the review becomes an evidence-bearing control when decisions are recorded, scoped correctly, and traceable to the right reviewer, application owner, or auditor.
- Closed-Loop Remediation: A governance process that does not stop at finding risk. It removes or reduces access, confirms the change in the source systems, and keeps evidence that the risky condition stayed fixed. For NHIs, this is the difference between inventory and actual risk reduction.
- Role-Based Certification: A certification model that ties learning outcomes to specific job responsibilities. In practice, it helps organisations distinguish between baseline familiarity and the deeper operational capability needed for administration, recovery, or engineering tasks in complex environments.
- Identity Lifecycle Event: A business event that changes a person’s access, obligations, or record status, such as hiring, role change, or offboarding. In HR programmes, these events often drive entitlement changes and evidence requirements, so they need to be governed as part of the identity lifecycle rather than handled as isolated paperwork.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 10, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org