Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when ITGC access reviews miss ex-employees…
Governance, Ownership & Risk

What breaks when ITGC access reviews miss ex-employees or dormant accounts?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

The review becomes evidence of process rather than evidence of control. If former employees or inactive accounts still have access, auditors can conclude that the organisation cannot prove revocation, ownership, or entitlement accuracy. That creates findings even when the review was performed, because the underlying identity state was never clean enough to certify.

Why the Review Fails as an Audit Control

An ITGC access review is supposed to confirm that access is current, owned, and defensible. When it misses ex-employees or dormant accounts, the control no longer proves that revocation happened, only that a review activity occurred. IAM and IGA Basics is useful here because the failure is rooted in entitlement ownership and access certification, not just review cadence.

That distinction matters because auditors are testing the state of access, not the existence of a meeting or ticket. If stale access survives the review, the organisation has evidence of process completion but not evidence that entitlements were accurate at the point of certification.

This is why access reviews must be tied to authoritative lifecycle events. Joiner-Mover-Leaver (JML) Guide and Access Reviews and Certification Guide both reinforce the same practical point: certification only has value when leaver processing, ownership, and remediation are actually closed out.

Why Ex-Employee and Dormant Access Are So Damaging

Former employees and inactive accounts are high-signal exceptions because they directly challenge revocation hygiene. If an ex-employee still exists in a review population, the organisation must explain why deprovisioning did not occur, why the account was not flagged earlier, or why the review failed to catch it. That is a control weakness, not a paperwork issue.

Dormant accounts create a similar problem even when no one is actively using them. They suggest that the access inventory is stale, the business owner is not validating effective use, or the review logic is too coarse to distinguish live privilege from abandoned privilege. Identity Security Posture Management (ISPM) Guide is relevant because dormant and stale accounts are posture defects that should surface before annual certification, not after.

The practical consequence is that the review cannot support a clean assertion about entitlement accuracy. If access remains attached to the wrong people or to nobody at all, the reviewer is certifying a contaminated population. That is why dormant accounts, orphaned accounts, and leaked access metadata often become audit findings even when the control formally “ran”.

What Practitioners Should Prove Before They Certify

The control should prove three things: who owns the account, whether the account is still needed, and whether revocation happened when the relationship ended. If any one of those is missing, the review is incomplete in substance even if it is complete in workflow. NHI Lifecycle Management Guide is a useful lifecycle lens because it treats offboarding and visibility as part of the control, not an afterthought.

At the operating level, the most useful evidence is not the sign-off sheet but the exception handling trail: terminated-user syncs, disabled-account records, owner attestations, and remediation closure. IGA Buyer's Guide and Identity Visibility and Intelligence Platforms (IVIP) Guide both point to the same operational requirement, the review needs discovery and remediation visibility, not just a recertification interface.

Risk and Threat Considerations

Stale access is attractive to both insiders and external attackers because it creates a low-friction path to authorised systems with less scrutiny. Ex-employee accounts are especially risky when credentials, tokens, or linked access paths were never retired, since the account can remain valid after the employment relationship ends.

Failure mechanism: The organisation loses the ability to prove that access was revoked at the lifecycle event, so the review becomes a retrospective confirmation of bad data rather than a control over current entitlement state.

Impact: That opens exposure to unauthorised access, audit findings, and the possibility that dormant or orphaned accounts remain available for misuse long after the business believes they are closed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementITGC reviews fail when dormant or ex-employee accounts are not removed.
IA-5 — Authenticator ManagementRevocation gaps often persist because credentials remain valid after lifecycle end.
AU-6 — Audit Record Review, Analysis, and ReportingReview evidence must support detection of stale access and remediation closure.
Recommendation — Reconcile accounts and disable unused access before certifying review results. Rotate or revoke authenticators when employment or need-to-use ends. Use audit review evidence to confirm exceptions were investigated and closed.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights must be reviewed and removed when no longer required.
A.5.16 — Identity managementIdentity lifecycle control underpins accurate certification populations.
Recommendation — Review and revoke access rights for leavers and dormant accounts promptly. Maintain authoritative identity records so reviews reflect current user state.

Practitioner Guidance

What to verify: Confirm that every reviewed population is reconciled against an authoritative joiner-mover-leaver source, not just an access list. If a terminated user, inactive contractor, or dormant account appears in the review, treat it as a remediation case, not a reviewer judgment call.

Decision rule: If the account can still authenticate, assume the control is incomplete until revocation is evidenced. If the account is no longer needed but remains present for reporting convenience, remove it from the active certification population and document the disposal path.

Practitioner takeaway: ITGC access reviews are only defensible when they verify current entitlement state, not when they merely collect approvals over stale identities.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org