Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when access reviews are the only…
Governance, Ownership & Risk

What breaks when access reviews are the only IGA control?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

They create a governance gap between review cycles. Access can change through promotions, transfers, or terminations after certification, so the organisation may still carry stale or excessive access until the next scheduled review. That is why access reviews need provisioning, deprovisioning, and monitoring around them, not just manager approval.

Why access reviews fail as a standalone IGA control

Access reviews are point-in-time attestation, not continuous control. They can confirm whether access looked acceptable on the review date, but they do not remove the gap between review cycles, and they do not by themselves prevent entitlement drift after a promotion, transfer, termination, or new integration.

That is why IAM and IGA Basics matters here: it separates governance from provisioning and shows why access review is only one control layer in the identity governance stack. When certification is the only mechanism, the organisation is effectively trusting a periodic snapshot to represent a changing access state.

The practical consequence is stale access, delayed revocation, and excessive entitlements that remain valid until the next campaign. In fast-moving environments, that delay can be long enough for a moved or departed user to retain permissions that no longer match their role.

What control gaps appear between certification cycles

The largest weakness is that certification answers the question “did someone approve this access?” rather than “does this access still belong here now?” That distinction matters because access can change through HR events, application changes, service onboarding, and delegated admin activity long after the reviewer signed off.

Joiner-Mover-Leaver (JML) Guide is the natural companion to access review because it addresses the lifecycle events that create the gap. Provisioning and deprovisioning need to be aligned to those events, otherwise review becomes a cleanup activity instead of a governance backstop.

For that reason, the better operating model is event-driven access change plus scheduled review, not scheduled review alone. Access review should validate what lifecycle controls and monitoring have already done, then highlight exceptions that still need human judgment.

Access Reviews and Certification Guide is useful for designing that model because it focuses reviews on removing access and closing the loop. The control breaks down when teams treat attestation as the end state instead of a checkpoint in an ongoing remediation flow.

What a balanced IGA model needs around reviews

Access reviews are strongest when they sit on top of accurate inventory, timely provisioning, and timely deprovisioning. If identity records, entitlements, or ownership are stale, the review process becomes a rubber stamp exercise over bad data.

IGA Buyer's Guide is relevant because it frames IGA as a broader capability set, not a single workflow. A useful platform or operating model should support requests, provisioning, certification, role governance, and connectors that keep entitlement state current.

Monitoring also matters. If nobody is watching for privilege creep, orphaned accounts, or long-lived access outside the review window, the organisation only discovers the problem when the next certification starts. That leaves a broad exposure window and makes exception handling reactive rather than controlled.

Identity Visibility and Intelligence Platforms (IVIP) Guide supports this point because visibility is what lets teams compare granted access with actual usage and ownership between campaigns. Reviews are much more effective when they are informed by live identity intelligence instead of memory and spreadsheets.

Risk and Threat Considerations

When access reviews are the only control, the risk is entitlement drift that persists for weeks or months between certification cycles. That creates a standing opportunity for misuse, especially when terminated users, moved employees, or over-entitled accounts retain access longer than the business expects.

Failure mechanism: access changes happen outside the review window, but review is the only enforcement point, so stale permissions remain active until the next scheduled campaign.

Impact: excessive access, delayed revocation, and a larger blast radius if an account is abused, compromised, or simply forgotten.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementAccess reviews depend on current account governance and removal of stale access.
Recommendation — Automate account review and removal so certifications do not become the only cleanup point.
NIST SP 800-53 Rev 5AC-2 — Account ManagementReview-only governance fails when account lifecycle changes are not continuously managed.
AC-6 — Least PrivilegePeriodic reviews must enforce privilege minimisation, not merely approve existing excess.
Recommendation — Tie account provisioning and deprovisioning to authoritative lifecycle events before certification. Reduce standing access continuously and use reviews to validate remaining exceptions.
ISO/IEC 27001:2022A.5.15 — Access controlAccess reviews are one part of broader access control governance and enforcement.
A.5.18 — Access rightsPeriodic approval alone cannot manage access-right changes across the identity lifecycle.
Recommendation — Implement access control processes that include timely change and revocation, not only approval. Review access rights on change events and revoke obsolete permissions without waiting for the next cycle.

Practitioner Guidance

What to verify: confirm that every certification campaign is paired with authoritative provisioning and deprovisioning triggers, plus a monitoring signal for access that changes after approval. If the process cannot show when access was added, removed, or changed outside review, the control design is incomplete.

What good looks like: reviews are used to validate exceptions and ownership, not to compensate for missing lifecycle automation. Mature teams can trace each entitlement back to a current business need, a named owner, and a recent lifecycle event or usage signal.

Decision rule: if an entitlement can create material privilege or data exposure before the next review date, do not rely on attestation alone. Prioritise rapid provisioning, rapid deprovisioning, and exception monitoring first, then use review as the governance checkpoint.

Practitioner takeaway: access review is necessary, but by itself it is only a snapshot; the control becomes reliable only when lifecycle events and monitoring continuously keep the entitlement set in sync with reality.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org