Use quarterly reviews for audit proof, but reserve recurring targeted campaigns for the access paths that change most often. That usually means production access, contractor entitlements, service accounts, and accounts with no recent use. The right model is layered: broad governance for assurance, narrower campaigns for actual risk reduction.
How to Divide Quarterly Review Work from Continuous Access Governance
Quarterly reviews and ongoing access governance solve different problems, so the balance should be explicit rather than accidental. Quarterly reviews are strongest as a governance and audit evidence mechanism. Continuous governance should focus on the access paths that change fastest, carry the most privilege, or create the largest blast radius when they drift.
The practical mistake is to treat the quarterly cycle as the control and the day-to-day process as optional. In healthy programmes, the quarterly review validates ownership, accountability, and attestation quality, while recurring campaigns or automated checks handle churn, exceptions, and high-risk access in near real time.
That split usually works best when review scope is risk-tiered. Stable, low-impact entitlements can stay on a slower certification cadence. Production access, contractor access, service accounts, dormant accounts, and privileged paths need more frequent scrutiny because those are the areas where access drift becomes operational risk fastest.
Why Quarterly Reviews Are Necessary but Not Sufficient
Quarterly reviews remain useful because they create a repeatable, defensible control point. They help management prove that access was examined, that accountable owners signed off, and that recertification happened on a defined schedule. That matters for auditability, but it does not by itself stop access creep between cycles.
Fast-moving environments make quarterly-only governance too blunt. Users change roles, contractors roll off, integrations accumulate, and application or service credentials often persist long after the original business need has faded. If the team waits for the next certification window, the organisation is effectively accepting months of avoidable exposure.
For that reason, the quarterly review should be the backstop, not the only detection mechanism. It works best when paired with event-driven or periodic campaigns that concentrate on the access categories most likely to become stale, excessive, or misaligned with current business need.
Which Access Paths Belong in Continuous Governance
Continuous governance should be reserved for the parts of the access landscape where change, privilege, or exposure is highest. That includes production access, privileged accounts, contractor entitlements, service accounts, dormant users, and shared or exception-based access paths. These are the areas where a delay in review can translate directly into overexposure or operational drift.
Targeted campaigns should also focus on accounts that are hard to govern through a single broad review. For example, service accounts and other non-interactive access often have different ownership, different lifecycle triggers, and different business dependencies from ordinary user accounts. A broad quarterly certification may confirm that they exist, but it may not reliably answer whether they still need the same permissions.
That is why the better operating model is layered governance, not one universal review rhythm. Broad attestations provide assurance across the estate, while narrower campaigns remove risk where the probability and impact of stale access are highest. For teams managing identity and access at scale, IAM and IGA Basics is a useful reference point for the distinction between access administration and access governance. If the team needs a stronger review design, Access Reviews and Certification Guide explains how to focus campaigns on higher-risk entitlements instead of repeating the same low-value attestation work.
What Good Balance Looks Like in Practice
A mature programme uses quarterly reviews to answer, “Is the governance process working?” and recurring targeted campaigns to answer, “Where is current risk concentrated?” The first is assurance-oriented. The second is operationally corrective. Both are needed, but they should not have the same scope or cadence.
In practice, teams should prioritise removals where the access path is privileged, externally owned, or difficult to justify quickly. Contractor access should not wait for a broad quarterly sweep if the contract has ended or the sponsor cannot confirm the need. Service accounts should be reviewed on a lifecycle basis, not merely as part of a generic population check. And dormant accounts should be handled as a separate campaign because inactivity is often a strong signal that access is no longer required.
Where the access model is role-based, teams should also watch for role sprawl and approval fatigue. A review that keeps approving the same low-risk population without action becomes a reporting exercise. The goal is to make quarterly evidence easy to produce while ensuring the high-risk edge cases are continuously visible and actionable. Joiner-Mover-Leaver (JML) Guide is especially relevant where access drift is driven by lifecycle events, and Privileged Access Management Guide is the better reference when the question is how to govern high-impact access paths rather than just attest them.
Risk and Threat Considerations
Quarterly-only governance creates a window in which excessive or abandoned access can remain active long after the business need has disappeared. The risk is highest where access can be used immediately for production changes, data access, or administrative actions, because a stale entitlement can become a ready-made compromise path or an internal abuse path.
Failure mechanism: Long certification intervals allow access drift to accumulate between review cycles, while broad campaigns often miss the accounts that change fastest or carry the most privilege.
Impact: The organisation may keep unnecessary production, contractor, or service access live long enough for misuse, lateral movement, or avoidable audit findings to occur.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5, CIS Controls v8 and CSA Cloud Controls Matrix set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Quarterly reviews and recurring governance both center on account lifecycle and review of access. |
| AC-6 — Least Privilege | The question is about balancing assurance with risk reduction for access paths carrying more privilege. | |
| IA-5 — Authenticator Management | Service accounts and dormant access often depend on credential lifecycle and rotation discipline. | |
| Recommendation — Use AC-2 to review, recertify, and remove stale or excessive account access on a defined cadence. Apply AC-6 to limit high-risk access paths to the minimum permissions needed. Use IA-5 to govern credential lifecycle for accounts that should not remain broadly trusted. | ||
| CIS Controls v8 | CIS-5 — Account Management | Continuous governance and periodic certification both map to managing account inventory and access removal. |
| CIS-6 — Access Control Management | Targeted campaigns are the practical expression of tighter access control for high-risk paths. | |
| Recommendation — Implement CIS-5 to inventory accounts, review access, and remove stale entitlements regularly. Use CIS-6 to enforce periodic review and restriction of privileged and sensitive access paths. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The answer is fundamentally about setting access review rhythm and governance boundaries. |
| A.8.2 — Privileged access rights | Production and admin access need tighter, more frequent governance than ordinary entitlements. | |
| Recommendation — Establish A.5.15 to define how access is granted, reviewed, and limited over time. Use A.8.2 to govern privileged access with stricter review and approval cycles. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The balance between certification and ongoing governance is an IAM operating-model question. |
| Recommendation — Use IAM to align access review frequency with privilege, change rate, and business criticality. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Contractors, service accounts, and dormant access are vulnerable when offboarding or removal is delayed. |
| NHI-05 — Overprivileged NHI | Targeted governance is needed most where accounts retain more privilege than the task requires. | |
| Recommendation — Remove access promptly with NHI-01 when the business relationship or system need ends. Apply NHI-05 to reduce excessive permissions on high-impact non-human accounts. | ||
Practitioner Guidance
What to prioritise: Put continuous attention on access that can alter systems, expose sensitive data, or outlive the business relationship. Keep the quarterly cycle for attestation and oversight, but do not rely on it to catch rapidly changing entitlements.
What to verify: Every targeted campaign should have a clear owner, a clear removal action, and a defined reason for why that population is reviewed more often than the rest. If reviewers cannot explain the cadence, the programme is usually too broad or too manual.
Practitioner takeaway: Use quarterly reviews to prove control exists, but use targeted ongoing campaigns to actually reduce risk where access changes fastest and the blast radius is largest.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org