They become a governance problem when the review is disconnected from discovery, offboarding, and remediation. If access is reviewed on paper but scope is stale, dormant accounts persist, or revocations do not execute, the programme is certifying risk rather than controlling it.
When access reviews stop being a control and become a governance signal
Quarterly access reviews become a governance problem when they no longer tell you whether access is correct, current, and actually removed when it should be. A review that only validates a stale list, or that cannot prove discovery and remediation are working together, is no longer managing entitlement risk, it is documenting it.
The practical shift is from “did someone sign off?” to “did the organisation maintain an accurate access state throughout the quarter?” That means the review must be connected to authoritative inventory, joiner-mover-leaver handling, and revocation execution, not treated as an isolated certification event. The review also needs enough context to judge whether the access still matches role, purpose, and business need.
When that connection breaks, the quarterly cycle turns into a reporting ritual. If dormant accounts remain in scope, inherited access is never cleaned up, or exceptions are repeatedly renewed without real remediation, the programme is measuring paperwork quality instead of entitlement health. IAM and IGA Basics frames this distinction clearly: access governance only works when review, ownership, and provisioning are part of the same control loop.
What makes a quarterly review “paper compliance”
The warning signs are usually operational, not theoretical. Scope drift is the biggest one: the review starts from an outdated population, misses shadow accounts, or inherits entries that were never removed after role changes, contractor exits, or system decommissioning. At that point, the control is certifying whatever the system already believes, not testing whether access is still warranted.
Another failure mode is non-executable remediation. If reviewers can flag excess access but revocations are delayed, manually trapped, or ignored after the attestation closes, the organisation has separated accountability from enforcement. Joiner-Mover-Leaver (JML) Guide is the right companion concept here because access reviews cannot compensate for weak offboarding or mover handling.
A third sign is review fatigue. When managers or system owners are shown too many low-value items, they approve by habit, not by judgment. That is where role clarity, entitlement quality, and review frequency matter more than the calendar itself. Role Mining and Role Design Guide supports this point: weak role design creates noisy reviews that drive rubber-stamping.
How governance changes the objective of the review
A compliance task asks whether a control ran. A governance process asks whether the control improved the access model. That difference matters because the review should feed back into ownership, role design, provisioning rules, and offboarding outcomes. If the same issues recur every quarter, the programme is not maturing, it is absorbing the same failure repeatedly.
Governance also requires visibility into the exceptions behind the numbers. Repeated temporary approvals, blanket manager sign-off, or access that is “accepted” because no owner can be found are all indicators that accountability is unclear. Identity Visibility and Intelligence Platforms (IVIP) Guide is relevant because governance depends on seeing effective access, not just what the old record says should exist.
For machine and service access, the bar is even higher. Non-human accounts often outlive the process that created them, so a quarterly review without lifecycle enforcement can miss stale tokens, shared secrets, and orphaned permissions. NHI Lifecycle Management Guide shows why discovery, offboarding, and visibility have to be treated as one control chain.
Risk and Threat Considerations
Stale access reviews create two kinds of exposure: control failure and adversary opportunity. Control failure appears when revoked access remains active, dormant accounts survive, or privileged exceptions keep being renewed without a fresh justification. Adversary opportunity appears when unused but valid access becomes a low-noise path for abuse, persistence, or lateral movement.
Failure mechanism: The organisation certifies an outdated access state, then fails to execute or verify the resulting removals, so excess access persists after the review cycle closes.
Impact: Over time, the review loses defensive value and becomes evidence that risk is being recorded but not reduced. That increases the chance of privilege creep, hidden dormant accounts, and delayed detection of inappropriate access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Quarterly reviews depend on account inventory, assignment, and removal accuracy. |
| AC-6 — Least Privilege | Access reviews exist to detect and reduce excess permissions against job need. | |
| AU-6 — Audit Review, Analysis, and Reporting | Governance requires analysis of review results and follow-through on remediation trends. | |
| Recommendation — Tie reviews to active account lifecycle controls and verify removals are executed. Use review findings to remove privileges that exceed business need. Trend recurring exceptions and escalate patterns that show weak control effectiveness. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access reviews are part of governing who retains access and why. |
| A.5.18 — Access rights | The issue is whether access rights are granted, reviewed, and removed correctly. | |
| A.8.2 — Privileged access rights | Quarterly reviews are especially material for elevated access that can cause disproportionate harm. | |
| Recommendation — Align review outcomes to documented access-control policy and ownership. Review and withdraw access rights when business need no longer exists. Subject privileged access to stricter review, approval, and removal discipline. | ||
| CIS Controls v8 | CIS-5 — Account Management | Quarterly reviews are an account governance mechanism that must reflect current users and machines. |
| Recommendation — Maintain accurate account inventories and remove accounts no longer needed. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | When reviews miss non-human access, excess machine privilege persists beyond the review cycle. |
| NHI-01 — Improper Offboarding | Governance breaks when reviewed access is not actually revoked on exit or role change. | |
| Recommendation — Reduce excessive non-human privileges and revalidate them through lifecycle controls. Ensure offboarding removes access and secrets, not just records an approval. | ||
Practitioner Guidance
What to verify: Treat a quarterly review as trustworthy only if you can trace each reviewed entitlement back to a live source of truth and prove that approved removals were executed. If the review output cannot be reconciled with current accounts, roles, and deprovisioning outcomes, it is a governance gap, not a completed control.
Decision rule: If the review can identify excess access but cannot trigger or confirm revocation within the same operating process, move the programme toward continuous or event-driven review for those populations first. Calendar-based review alone is too slow for dormant accounts, privileged access, and fast-changing non-human access.
Common mistake: Do not measure success by completion rate alone. High completion with poor remediation usually means the process is optimised for attestations, not for reduced access exposure.
Practitioner takeaway: Quarterly access reviews only remain a compliance control when they are continuously fed by discovery and closed by remediation; once they stop changing access outcomes, they have become governance theatre.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org