Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How do organisations keep access review campaigns from…
Governance, Ownership & Risk

How do organisations keep access review campaigns from stalling?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Organisations should route campaigns with fallback reviewers, role-based assignment, and multi-level approvals so the process survives leave, turnover, and distributed ownership. This is especially important in companies with subsidiaries or multiple app owners, where a single approver model does not reflect how access is actually managed.

Why access review campaigns stall in the real world

access review campaigns usually stall when the workflow assumes a single owner, a single approver, or a static org chart. Leave, role changes, business-unit fragmentation, and unclear entitlement ownership create dead ends. The campaign is then blocked not by policy intent, but by missing decision makers, unanswered exceptions, and review queues that cannot be reassigned cleanly.

For access governance teams, the practical issue is not just completion rate. A stalled campaign also undermines reviewer accountability, delays remediation, and turns the review into a point-in-time exercise rather than a live control.

How fallback reviewers and role-based assignment keep the workflow moving

The most reliable way to prevent stalling is to make reviewer assignment resilient before the campaign starts. That means defining backup reviewers, mapping approvals to roles or business functions, and using delegation rules that let the campaign continue when an owner is absent. The design should reflect how access is actually managed, not how the organisation wishes ownership worked in theory.

This is where role design and governance structure matter. A campaign that depends on one manager to approve every entitlement will fail in matrixed organisations, subsidiaries, shared services models, or environments with many application owners. Role Mining and Role Design Guide is useful here because it treats the role model as an operating control, not just an entitlement label. IAM and IGA Basics provides the broader governance context for reviewer assignment, entitlement ownership, and access certification.

In practice, role-based assignment should answer two questions in advance: who can approve if the primary reviewer is unavailable, and which role or business unit should own the decision if the original approver is no longer valid? If that logic is built into the campaign design, the workflow can continue without manual rescue every time a person changes job or leaves.

What good campaign design looks like when ownership is distributed

Well-run campaigns separate the control objective from the individual approver. The control objective is to confirm that access is still justified, while the approver may be the manager, the application owner, the role owner, or a delegated reviewer depending on the entitlement type. Multi-level approvals help when a single review is not enough to represent both business need and technical ownership.

That becomes especially important where different organisations or subsidiaries manage access differently. A central team may run the campaign, but local owners often know whether a privilege is still needed. Access Reviews and Certification Guide is directly relevant because it focuses on reducing rubber-stamping, using more context, and closing the loop after certification. IGA Buyer’s Guide is also helpful for evaluating whether a platform can support fallback reviewers, workflow routing, and review reassignment without manual intervention.

When campaigns span many applications, the important design question is whether the system can still reach a decision when the first reviewer path fails. If the answer is no, the organisation is effectively relying on perfect attendance, which is not a control design.

Risk and Threat Considerations

Stalled campaigns create control debt. Unfinished reviews leave excessive access in place longer than intended, delay remediation, and make it easier for dormant, shared, or misassigned access to persist unnoticed across business units and subsidiaries.

Failure mechanism: The campaign cannot complete because the designated reviewer is unavailable, the ownership model is stale, or the workflow has no valid delegate or fallback path, so exceptions accumulate and overdue items remain unresolved.

Impact: Access that should have been recertified or removed stays active, which increases exposure to privilege creep, orphaned ownership, and delayed detection of inappropriate access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess reviews and fallback approvals support ongoing account governance and entitlement oversight.
AC-6 — Least PrivilegeCampaigns aim to remove unnecessary access and keep privileges justified.
AU-6 — Audit Review, Analysis, and ReportingStalled campaigns need auditable evidence of review completion, delegation, and exceptions.
Recommendation — Use AC-2 to govern account ownership, approval paths, and periodic access recertification. Use AC-6 to remove excess entitlements when reviews show no business need. Use AU-6 to retain review evidence and exception handling records for certification campaigns.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess reviews directly support periodic review and adjustment of access rights.
A.5.15 — Access controlFallback reviewers and role-based assignment are access control governance mechanisms.
Recommendation — Use A.5.18 to review and adjust access rights on a defined schedule. Use A.5.15 to define access approval paths and governance responsibilities.

Practitioner Guidance

What to prioritise: Build the fallback logic before launching the campaign, not after the first reviewer disappears. The highest-value control is usually a routing model that can reassign by role, business unit, or entitlement class without losing approval traceability.

What to verify: Confirm that every high-volume access category has at least one alternate decision path and that delegated reviewers are actually authorised to approve that class of access. If a backup reviewer cannot see the same context as the primary owner, the fallback exists only on paper.

Practitioner takeaway: Access review programmes stall when ownership is treated as a person, not a governed workflow. The durable fix is to make reviewer assignment resilient enough that absence, turnover, and distributed administration do not stop certification from reaching a decision.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org