Execution breaks because reviewer assignment, fallback handling, sign-off, and evidence collection stop being repeatable. The policy may still exist, but the control becomes person-dependent and difficult to defend during audit or staff turnover.
Why quarterly access reviews collapse when the process lives in people’s heads
tribal knowledge turns a control into an informal service dependency. The review may still happen some months, but the process is no longer defined by stable inputs, explicit ownership, or consistent decision rules. That makes the control fragile: it works while the same people remember the unwritten steps, then degrades as teams change, priorities shift, or exceptions accumulate.
In practice, the biggest failure is not the review itself, but the hidden assumptions around who prepares the list, who resolves ambiguity, who approves exceptions, and how evidence gets captured. Once those steps are implicit, each cycle becomes a new interpretation exercise rather than a repeatable governance process.
Which parts stop being repeatable first
Reviewer assignment is usually the first weak point. If only a few individuals know which manager, system owner, or delegate should sign off, the campaign stalls whenever they are out of office, leave the organisation, or no longer remember the historical mapping. That is how a recurring control becomes dependent on oral history instead of an owned workflow.
Fallback handling fails next. Tribal knowledge often hides the rules for dormant accounts, shared accounts, inherited entitlements, contractors, service accounts, and edge cases where no obvious reviewer exists. Without those rules written down, reviewers either skip the decision, hand-wave the exception, or send it to the wrong approver. For a more structured baseline on access review and certification design, see the Access Reviews and Certification Guide.
Evidence collection is the other common break point. If the team does not know what artefacts to retain, the output becomes inconsistent across quarters: screenshots one cycle, exported reports the next, and informal email approvals after that. A reviewer can “complete” the task while still leaving the organisation unable to prove what was checked, by whom, and on what basis.
What this means for auditability and control quality
When access reviews rely on informal memory, the control becomes difficult to defend as a governed process. Auditors usually look for repeatable scope, defined ownership, traceable decisions, and clear remediation follow-through. Tribal knowledge weakens each of those elements because the process cannot be reconstructed cleanly from policy and records alone.
The same problem affects remediation. If reviewers cannot reliably distinguish a valid entitlement from a stale or excessive one, they may approve by habit rather than evidence. That is especially dangerous where access review is supposed to support least privilege, segregation of duties, or periodic recertification of privileged and sensitive access. A useful companion reference for the lifecycle side of that problem is the NHI Lifecycle Management Guide, which covers provisioning, rotation, offboarding, and visibility.
Tribal knowledge also hides dependency risk. If the organisation cannot replace one reviewer with another without losing decision quality, then the control is not institutionalised. It is a person-specific practice that only appears to be a process because it recurs on the calendar.
How to make quarterly access reviews survivable
Replace memory with explicit operating rules: who prepares the review, who can approve by entitlement class, what counts as acceptable evidence, and what happens when the owner is missing. If those decisions are not written down, the next cycle will re-create them ad hoc, and the same failure will repeat.
What to verify: every campaign should have a named owner, a documented reviewer map, a fallback approver path, and a standard evidence package before the first review request is sent. If any of those items must be “explained verbally,” the process is still dependent on tribal knowledge.
Common mistake: treating completion rate as proof of control health. A quarter can close on time while the review quality is degrading, especially if approvers are rubber-stamping items they do not understand. The better test is whether a replacement reviewer could run the same cycle from the documentation alone.
Practitioner takeaway: the goal is not just to finish the quarterly review, it is to make the review transferable. If another trained owner cannot execute it with the same inputs, the control is not yet operationally real.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Quarterly access reviews support ongoing account and entitlement management. |
| AU-2 — Event Logging | Auditability depends on retaining evidence of review decisions and remediation actions. | |
| Recommendation — Tie each review cycle to AC-2 and require documented recertification and revocation follow-through. Log reviewer actions and preserve review evidence so the control is defensible later. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The topic is a recurring access-control process that must be defined and repeatable. |
| Recommendation — Define access-review ownership, scope, and exceptions under A.5.15. | ||
| CIS Controls v8 | CIS-5 — Account Management | Quarterly access reviews are a core account-management safeguard against stale or excessive access. |
| Recommendation — Implement periodic access recertification and remove unneeded access promptly. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Tribal-knowledge review processes often miss stale access and failed removal paths. |
| NHI-05 — Overprivileged NHI | Review failures commonly leave excessive access in place across quarterly cycles. | |
| Recommendation — Use offboarding and review evidence to catch access that should already have been removed. Revoke excess access when the review shows privileges are broader than needed. | ||
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org