Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when user access reviews stay quarterly…
Governance, Ownership & Risk

What breaks when user access reviews stay quarterly only?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Quarterly-only reviews break when roles, applications, and offboarding events change faster than the review cycle can catch them. Access can remain excessive for months, and the certification becomes a retrospective exercise instead of a live governance control. Continuous review closes that timing gap by moving review closer to the identity event.

How quarterly-only reviews go stale

Quarterly reviews assume the access picture is stable enough to certify later. In practice, role changes, new applications, emergency entitlements, and leaver events create a moving target. When the review cadence lags the change rate, managers are asked to validate yesterday’s access state, not today’s exposure. That is why quarterly-only review often becomes a compliance rhythm instead of an effective governance control.

The control failure is timing, not intent. If a user moves teams in week two of the quarter, inherits extra access for a project in week six, and leaves in week ten, the review may not touch those changes until the next cycle. The result is accumulated excess access, weaker accountability, and less confidence that the certification outcome reflects real business need.

Continuous review changes the control from periodic affirmation to event-aware governance. It does not eliminate quarterly attestations, but it adds a closer feedback loop around joins, moves, role changes, and offboarding so certification can verify current access rather than preserve stale access for months.

What quarter-only cadence misses in the identity lifecycle

Quarterly-only review breaks most obviously at the seams of the identity lifecycle: onboarding, role change, transfer, contractor end dates, and offboarding. Those are the moments when access should be verified, reduced, or removed, and they are also the moments most likely to create drift if no one is looking between cycles. NHIMG’s Joiner-Mover-Leaver (JML) Guide and the IAM and IGA Basics both treat lifecycle events as the point where access should be corrected, not merely recorded.

That same timing gap matters when entitlements are inherited through roles or nested groups. A quarterly review can confirm that the access exists, but it may not reveal that the business reason disappeared weeks earlier. The longer the interval, the more likely certifiers approve access because it is familiar, not because it is still required.

Once access reviews lag lifecycle events, the governance signal weakens. Reviewer fatigue rises, managers begin to rubber-stamp familiar access, and remediation becomes harder because the gap between approval and correction is too large to explain confidently.

Why continuous review is the better control pattern

Continuous review works best when it is tied to meaningful identity events, not when it is treated as a replacement for all periodic governance. Event-driven review is stronger for newly granted access, privileged assignments, offboarding, and unusual access changes because those are the situations where excess privilege is most likely to form. The Access Reviews and Certification Guide frames this as a shift toward removing access, cutting review volume, and closing the loop on remediation.

Practitioners should also think in terms of completeness rather than cadence alone. Continuous review only helps if it sees the right events, has current ownership, and can route decisions to someone who can actually remove access. If the process only generates more review tasks without revocation or ownership clarity, it becomes faster paperwork rather than better control.

For organisations with broader identity governance needs, quarterly certification still has a role as a backstop, but the primary question should be whether the control is close enough to the event that it can prevent stale access from persisting. The IGA Buyer's Guide is useful here because it pushes the evaluation toward lifecycle, review, and remediation capability, not just report generation.

Risk and Threat Considerations

Quarterly-only access reviews leave a long exposure window in which excessive access can be abused, inherited, or forgotten. The main risk is not that the review never happens, but that it happens after the control value has already decayed and the organisation has carried unnecessary privilege for weeks or months.

Failure mechanism: Access changes faster than the review cycle, so excess entitlements persist between certification dates and offboarding events are not corrected quickly enough.

Impact: Stale access increases the chance of unauthorized data access, privilege creep, and misuse of accounts that should already have been reduced or removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementQuarterly-only reviews fail at account lifecycle timing and recertification.
AC-6 — Least PrivilegeStale access undermines least-privilege enforcement when reviews lag changes.
AU-6 — Audit Review, Analysis, and ReportingContinuous review depends on timely evidence and reviewable events.
Recommendation — Automate account review and removal close to lifecycle events, not only on a quarterly schedule. Reassess and trim entitlements whenever role or business need changes. Feed review decisions from current audit evidence and act on exceptions quickly.
CIS Controls v8CIS-5 — Account ManagementQuarterly-only reviews leave account changes and removals too late to control.
Recommendation — Shorten review and removal intervals for accounts that change frequently or carry elevated access.
ISO/IEC 27001:2022A.5.15 — Access controlAccess control must reflect current need, not stale quarterly approvals.
Recommendation — Tie access approval and review to current business need, not just periodic attestations.

Practitioner Guidance

What to prioritise: Put the shortest review interval around access that changes often or creates high blast radius, especially joiner-mover-leaver transitions, privileged roles, and sensitive applications. Keep quarterly certification only as the outer governance layer, not the only line of correction.

What to verify: Confirm that review outcomes trigger removal, not just attestation, and that the process can prove when an entitlement was granted, changed, reviewed, and revoked. If you cannot trace those timestamps, the control is probably too slow to be trusted.

Practitioner takeaway: Quarterly reviews are acceptable as a checkpoint, but they are too slow to be the sole control when access can change in days or hours; the control must move closer to the event that creates the risk.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org