Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations do when no single user…
Governance, Ownership & Risk

What should organisations do when no single user can answer all questions in an access review?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Governance, Ownership & Risk

Organisations should design the campaign so questions can be reassigned to another user, such as a system owner, manager, or category owner with better context. This prevents surveys from stalling and improves answer accuracy. Reassignment also supports accountability, because the person best placed to judge access can approve or reject it instead of forcing a weak guess from the original recipient.

When no single reviewer has enough context, what should the campaign do?

Access reviews should be built to allow reassignment, not dead-end to the original recipient. If a user cannot judge a particular entitlement, the campaign needs a path to route that question to someone with better business or technical context, so the review continues and the decision is based on informed ownership rather than guesswork.

That design choice matters because the purpose of an access review is not merely collection of responses, it is decision quality. A reassigned review can still be completed within the same campaign, but it should move to the person who can actually assess whether the access is needed, whether it matches role expectations, and whether it should be retained, reduced, or removed.

This is also why review campaigns often work better when they are segmented by resource, role, application, or owner group. A manager may be best for business access, a system owner for application-specific entitlements, and a category owner for shared or templated access. The campaign should make that handoff explicit so the reviewer sees the question that matches their accountability.

How does reassignment improve review quality and accountability?

Reassignment reduces the common failure mode where an access review stalls because the assigned reviewer lacks enough context to approve or reject with confidence. When the campaign can re-route a question to a system owner, manager, or category owner, the organisation gets a more reliable decision and avoids the false comfort of a quick but uninformed approval.

It also strengthens accountability by aligning the decision with the person best placed to judge the access relationship. That is especially important where access is indirect, inherited, or tied to a team function rather than a single individual’s day-to-day knowledge. The right reviewer can confirm whether the entitlement still matches the business need, whether the access is excessive, and whether the access belongs to the current user at all.

Done well, reassignment also creates a cleaner audit trail. The record shows who was initially asked, who accepted the decision, and why the question moved. That matters when teams later need to explain why a review outcome was trusted, overridden, or escalated.

What should organisations build into the review workflow?

The workflow should support a clear decision path for questions that cannot be answered by the first assignee. At minimum, the campaign should allow a reviewer to decline a question, reassign it with a reason, and return it to a queue where ownership is visible rather than implicit.

Good workflows also distinguish between temporary routing and permanent ownership. A reviewer might pass one entitlement question to a more suitable colleague, but the underlying access owner should still be identifiable for future campaigns, remediation, and recertification. The goal is to prevent ambiguity from accumulating across campaigns.

Organisations should also define when reassignment is acceptable and when it signals a deeper governance issue. If questions are repeatedly being routed because ownership is unclear, the problem is no longer the review tool, it is the access model, entitlement catalogue, or ownership data behind it.

Risk and Threat Considerations

When no one can confidently answer an access review question, the risk is not just delay, it is rubber-stamping. Weak ownership often leads to approvals based on assumption, which leaves excessive access in place and hides where accountability for that access actually sits.

Failure mechanism: the review is assigned to someone without enough context, so they either guess, approve by default, or ignore the item until the campaign closes. Over time, that creates a control gap where stale, excessive, or misaligned access survives the review cycle.

Impact: organisations lose the value of the review as a control. That can preserve unnecessary privilege, complicate audit evidence, and make it harder to prove that access decisions were made by the right owner with the right information.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess reviews and reassignment support account entitlement governance.
AU-6 — Audit Record Review, Analysis, and ReportingReassignment and decision trails need reviewable evidence for oversight.
Recommendation — Route review decisions to accountable owners and remove inappropriate access. Preserve reassignment history and review outcomes for oversight.
ISO/IEC 27001:2022A.5.15 — Access controlAccess review routing is part of controlling who can approve access.
A.5.18 — Access rightsReassignment helps validate whether access rights remain appropriate.
Recommendation — Define access review ownership and escalation paths for unanswered items. Recertify access rights through owners who can judge business need.
CIS Controls v8CIS-5 — Account ManagementCampaign reassignment helps keep account review decisions accurate and owned.
Recommendation — Assign review questions to the most informed owner and track exceptions.

Practitioner Guidance

What to prioritise: Design the campaign around accountable ownership, not just notification delivery. If a reviewer cannot answer a question, the process should route it to the person closest to the entitlement’s business use, and the system should preserve that handoff as part of the audit trail.

What to verify: Check that every entitlement type has a realistic fallback reviewer, and that reassignment does not hide ownership gaps. If the same questions keep bouncing between people, fix the owner model or the entitlement structure rather than relying on manual workarounds.

Practitioner takeaway: A good access review is one that reaches a defensible decision, even if it has to move to the right reviewer to do so.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org