Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk When does a spreadsheet review become a compliance…
Governance, Ownership & Risk

When does a spreadsheet review become a compliance risk?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 14, 2026 Domain: Governance, Ownership & Risk

It becomes a risk when approvers cannot see SoD conflicts, cross-system combinations, or contractor expiry status, because then they are signing off on incomplete identity information. That creates false confidence and leaves the organisation unable to show that inappropriate access was identified and removed in a defensible way.

Why a Spreadsheet Review Stops Being “Just Admin”

A spreadsheet review becomes a compliance risk once it is used as the control evidence for access decisions, but it cannot reliably show whether segregation of duties conflicts, cross-system access combinations, or contractor expiry status were actually checked. At that point, the review is no longer a simple administrative task, it is part of the organisation’s control design, and gaps in the file become gaps in the audit trail. If the reviewer cannot see the full identity picture, the sign-off is based on incomplete information.

That matters because compliance findings usually turn on whether the process is demonstrably defensible, not whether it happened in a loose operational sense. A spreadsheet can support review activity, but it cannot by itself prove that every relevant entitlement, temporary worker expiry, or toxic combination was assessed. Controls that rely on manual aggregation often look adequate until an auditor asks how the organisation knew what was missing.

In practice, teams discover this only after they are asked to evidence a decision they assumed the spreadsheet had already covered.

How It Works in Practice

The risk emerges when the spreadsheet becomes the decision surface for access certification, instead of a summary of authoritative access data. If the reviewer has to infer contract end dates, role conflicts, or access inherited from other systems, the review loses traceability. A defensible process needs the underlying access sources, not just a static list of names and checkboxes.

Typical failure patterns include:

  • Separate spreadsheets for HR, contractors, and application access that are never reconciled fully.
  • Manual flags for segregation-of-duties conflicts that depend on reviewer memory or local knowledge.
  • No reliable join between identity records and access in downstream systems, so cross-system privilege accumulation is invisible.
  • Contractor expiry dates that exist in one system but are not surfaced at review time.

When this happens, the sign-off may still be recorded, but the organisation cannot show that the reviewer had enough information to make a valid decision. For audit purposes, the weakness is not the spreadsheet format itself, it is the missing control over completeness, freshness, and provenance of the data being reviewed. That is why many identity programmes move from manual compilation to authoritative reporting and workflow-backed approvals. Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is useful here because it shows why lifecycle control and timely revocation matter when access changes over time.

These controls tend to break down when access data is split across HR, contractor, and application teams because no single reviewer can verify completeness at the point of sign-off.

Common Variations and Edge Cases

Tighter review rules often increase operational overhead, so organisations have to balance auditability against review fatigue and data quality. In practice, the key question is whether the spreadsheet is a supporting record or the only place where access risk is being judged.

Some spreadsheet reviews remain acceptable as a low-risk coordination aid, especially when they are backed by system-generated exports, clear ownership, and an immutable record of who approved what. The risk rises sharply when the spreadsheet is expected to surface exceptions on its own, because hidden combinations are easy to miss. Contractor-heavy environments are particularly exposed, since expiry, renewal, and sponsor approval often sit in different systems and can drift apart.

Another edge case is where the review covers a narrow application with stable roles. In that scenario, manual review may be workable if the process is small, well documented, and regularly reconciled to source data. But once the review spans multiple systems, shared accounts, privileged access, or time-bound access, a spreadsheet becomes a weak control unless it is fed by governed data sources and checked for completeness before approval. The 2024 ESG Report: Managing Non-Human Identities reinforces the scale of identity-related control failures, including the finding that 72% of organisations have experienced or suspect a breach of non-human identities.

Practitioners should treat any spreadsheet-driven review as a temporary control unless they can prove the inputs are authoritative, current, and complete enough to support a defensible decision.

Risk and Threat Considerations

The material risk is control failure through incomplete visibility. If the review process cannot reliably surface toxic combinations, inherited privileges, or expiry-driven access removal, the organisation can approve access that should have been removed or challenged. That creates both compliance exposure and downstream security exposure, because the same blind spot can preserve inappropriate access long after it should have been revoked.

Failure mechanism: The weakness usually comes from fragmented data, stale exports, and manual reconciliation. A reviewer signs off on the spreadsheet assuming it reflects current entitlements, but the underlying systems may already show changes, exceptions, or revocations that never reached the file. Attackers and insiders benefit from that lag because the process gives the appearance of oversight without reliably enforcing it.

Impact: The organisation may be unable to demonstrate that access was reviewed with full information, which can lead to audit findings, ineffective remediation, and a larger blast radius if inappropriate access is later abused.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-03 — Risk Management StrategyAccess review gaps create governance and compliance risk for identity decisions.
PR.AA-05 — Identity Management, Authentication, and Access ControlSpreadsheet reviews fail when access decisions lack complete identity and entitlement data.
Recommendation — Set a governed review process that proves access decisions are based on complete, current evidence. Use authoritative access records to certify entitlements and remove inappropriate access.
CIS Controls v86.3 — Access Rights ManagementPeriodic review must validate who has access and whether it remains appropriate.
Recommendation — Review and revoke access using current entitlement data, not manually maintained lists.
NIST SP 800-63IAL3 — Identity Assurance Level 3Defensible access decisions depend on high-assurance identity evidence where access is sensitive.
Recommendation — Require stronger identity evidence for high-impact access approvals and revocations.
ISO/IEC 42001:20236.1 — Actions to Address Risks and OpportunitiesThe process is a governance control when spreadsheet reviews are used to manage access risk.
Recommendation — Document access-review risks, owners, and escalation paths in the management system.

Practitioner Guidance

What to verify: Confirm that the review input comes from authoritative source systems, not from manually maintained spreadsheets. If the file cannot prove freshness, provenance, and completeness, treat the sign-off as weak evidence rather than control assurance.

Decision rule: If a spreadsheet cannot show SoD conflicts, cross-system access, and expiry status in one reviewable view, it should not be the primary approval mechanism. Use it only as a working artefact while the real control remains in governed identity and access data.

Practitioner takeaway: A spreadsheet review is only defensible when it helps prove the completeness of the decision, not when it merely records that a decision was made.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 14, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org