They need both, but for different jobs. Identity reviews tell you what exists and what should still be there, while attribute-based access control helps enforce real-time decisions based on context. The practical distinction is that reviews are governance, but ABAC is enforcement. Mature programmes use both to reduce drift and limit blast radius.
Why ABAC and Identity Reviews Solve Different Parts of Access Risk
Attribute-based access control and identity reviews are not substitutes. ABAC decides access at the moment of use, based on current context such as device state, location, data sensitivity, or transaction attributes. Identity reviews work on a different cadence, confirming whether entitlements, roles, and exceptions should still exist. Used together, they address both access drift and real-time misuse.
That split matters because modern environments rarely fail in only one way. Some risks come from stale access that should have been removed, while others come from a valid identity being allowed too much at a sensitive moment. The right question is not which control is “better”, but which control governs persistence and which governs enforcement.
For access governance foundations, IAM and IGA Basics is the cleanest way to separate authentication, authorisation, reviews, and entitlement ownership.
What ABAC Changes in Practice
ABAC makes authorisation conditional rather than static. Instead of granting access because a user sits in a role, it evaluates attributes at decision time, so access can change when the context changes. That is why ABAC is useful for sensitive data, segmented environments, and situations where the same identity should not have the same access in every circumstance.
ABAC also helps reduce blast radius. If a user or process still exists in the directory but the current attributes no longer match the policy, the request can be denied without waiting for the next review cycle. That makes ABAC especially valuable where business context changes faster than governance workflows.
For teams comparing models, Authorisation Models Guide is useful because it compares RBAC, ABAC, ReBAC, and policy-based access control across people, workloads, and AI agents.
ABAC still depends on good data. If attributes are stale, incomplete, or easy to manipulate, the policy can become precise on paper but unreliable in production. The control is strongest when attribute quality, policy design, and enforcement points are all governed as one system.
What Identity Reviews Still Do Better
Identity reviews answer a governance question that ABAC cannot solve on its own: what access exists, who owns it, and whether it is still justified. They are the mechanism that surfaces entitlements, exceptions, dormant access, inherited access, and role creep. Without reviews, organisations can end up enforcing policies while never cleaning up the accumulated access surface.
Reviews are also the place to challenge business justification. ABAC can prevent an unsafe action now, but it does not inherently tell you whether the entitlement should exist at all. Reviews remove the long tail of unnecessary access and provide the evidence that access decisions are being supervised, not just automated.
For the review side of the house, Access Reviews and Certification Guide shows how to make certification useful rather than ceremonial.
For programmes where entitlements, rotation, offboarding, and discovery are all intertwined, NHI Lifecycle Management Guide is a good companion because it treats lifecycle control as the backdrop for access review quality.
Risk and Threat Considerations
The main risk is treating one control as if it covers the other. If you rely only on reviews, access can remain overbroad between review cycles and be abused long before anyone notices. If you rely only on ABAC, stale entitlements, excessive standing access, and ownership gaps can persist because the policy engine is enforcing bad inventory instead of a well-governed one.
Failure mechanism: Access drift accumulates when governance processes are slow, while policy enforcement can be bypassed or mis-scoped when attribute sources, policy logic, or exception handling are weak. The result is a control stack that looks layered but still leaves excessive privilege in place.
Impact: Attackers and insiders can exploit overly broad standing access, while legitimate users may retain access they no longer need, increasing blast radius, lateral movement potential, and audit exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Covers entitlement lifecycle and periodic access review for active accounts. |
| AC-6 — Least Privilege | Directly supports limiting standing access and reducing blast radius. | |
| AC-16 — Security and Privacy Attributes | Directly maps to ABAC decisions based on contextual attributes. | |
| Recommendation — Review accounts regularly and remove unnecessary access promptly. Constrain access to the minimum privileges needed for the task. Define trusted attributes and enforce policy decisions from them. | ||
| CIS Controls v8 | CIS-5 — Account Management | Addresses access review, account lifecycle, and removal of unused access. |
| CIS-6 — Access Control Management | Supports policy-driven access control and least-privilege enforcement. | |
| Recommendation — Inventory accounts and remove dormant or unjustified access. Apply access policies that limit use by role, context, and need. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Annex A access control aligns with governing and enforcing who may access what. |
| A.5.18 — Access rights | Covers provisioning, review, and removal of access rights over time. | |
| Recommendation — Define and enforce access rules that match business need. Review access rights routinely and revoke those no longer justified. | ||
Practitioner Guidance
What to prioritise: Use identity reviews to reduce the access surface, then use ABAC to constrain how much of that surface is usable in real time. If the inventory is poor, start with review quality and ownership before expecting policy-based enforcement to carry the programme.
What to verify: Check that attribute sources are authoritative, timely, and actually used by the policy engine. Then verify that review outcomes lead to revocation, role cleanup, or policy change, not just a signed-off spreadsheet.
Decision rule: If the problem is excess or unowned access, review and remove it. If the problem is legitimate access that should depend on context, enforce it with ABAC. If both exist, do both, in that order.
Practitioner takeaway: ABAC is the enforcement layer, but identity reviews are what keep the enforcement layer honest; mature access risk management needs both.
Related resources from NHI Mgmt Group
- How should security teams use identity attributes to improve role-based access control in complex organisations?
- How should organisations implement Attribute-Based Access Control in environments with changing roles, locations, and risk levels?
- Why does attribute based access control help healthcare organisations reduce breach risk and compliance pressure?
- How should organisations use modern identity governance to reduce separation of duties risk across complex access models?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org