They fail at the handoff points between role design, provisioning, recertification, and de-provisioning. If those steps are owned as separate tasks instead of one lifecycle, access can remain active after the business need ends, roles drift into exception bundles, and review evidence becomes cosmetic rather than operational.
Why ITGC Access Controls Break at Handoff Points
itgc access control failures usually appear where ownership changes hands. Role design, provisioning, access review, and de-provisioning are often run as separate routines, so no one is accountable for whether the original access model still matches the current business need. That separation turns access control into a documentation exercise instead of a living control.
When the lifecycle is broken apart, the control can look complete on paper while the actual entitlement state keeps drifting. Roles become overloaded to satisfy exceptions, approvals get reused without revalidation, and removal depends on someone remembering to close the loop.
In practice, the failure is less about a single bad decision than about weak control integration. A well-written policy can still produce stale access if the request path, approval path, and removal path are not tied together and measured as one process.
How Role Drift and Exception Handling Undermine the Control
Role drift is one of the most common failure modes because it accumulates quietly. A role that starts as a clean business function can absorb temporary exceptions, edge-case approvals, and inherited permissions until it no longer represents a coherent access pattern. At that point, recertification may simply reapprove the drift instead of correcting it.
Exception handling creates a second problem when it becomes the normal way work gets done. Teams often preserve access to avoid operational friction, then rationalise the exception later. Over time, the exception becomes the rule, and the control no longer enforces least privilege in any meaningful way. A useful reference point is the Authorisation Models Guide, which helps separate role-based design from finer-grained authorization decisions.
Access reviews also fail when reviewers are asked to validate a list without enough context to judge business necessity. If the reviewer cannot see who owns the entitlement, why it exists, and what event should remove it, the review becomes a signature collection exercise rather than a control over active access.
What Good Lifecycle Control Looks Like in Practice
Strong ITGC access control treats the full lifecycle as one control plane. Role design should be built with removal in mind, provisioning should be tied to an approved source of truth, recertification should test whether the access still matches current duty, and de-provisioning should be mandatory when the trigger condition ends. That is the practical difference between a process and a control.
The best programs make ownership explicit. Identity and business owners should know who can create roles, who can approve exceptions, who must review them, and who is responsible for timely removal. For baseline identity and access governance, IAM and IGA Basics is a useful internal starting point because it ties provisioning, entitlement review, and joiner mover leaver discipline together.
Controls work better when they are evidenced by events, not screenshots. Good evidence shows when access was granted, why it was granted, when it was last reviewed, and what removed it. That makes it possible to test whether the lifecycle is operating or merely being reported.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | ITGC access control failures center on provisioning, review, and removal of access. |
| AC-6 — Least Privilege | Role drift and exception creep directly weaken least-privilege enforcement. | |
| AU-6 — Audit Review, Analysis, and Reporting | The question hinges on whether review evidence is operational or merely cosmetic. | |
| Recommendation — Tie account lifecycle events to approved business need and remove access promptly when it ends. Restrict entitlements to the minimum required and review exceptions before they become permanent. Use audit evidence to validate active control operation, not just to document that reviews occurred. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | The subject is the practical failure of access governance controls in an ISMS context. |
| A.5.18 — Access rights | Provisioning, review, and removal of access rights are the core failure points described. | |
| Recommendation — Define and enforce access rules across the full entitlement lifecycle. Review access rights periodically and revoke them when business need ends. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The issue is operational failure in granting, reviewing, and removing access. |
| CIS-5 — Account Management | Lifecycle breakdowns commonly show up as stale accounts and unmanaged entitlements. | |
| Recommendation — Centralize access governance and validate that approvals, reviews, and removals stay in sync. Inventory accounts and disable or remove those no longer justified by business need. | ||
Practitioner Guidance
What to prioritise: Test the handoff chain first. If role creation, provisioning, review, and removal are owned by different teams, verify whether there is a single control owner who can prove end-to-end accountability. If not, the control is likely fragmented even when each step has a procedure.
What to verify: Check whether each privileged or sensitive entitlement has an owner, a review cadence, and a removal trigger. Confirm that approvals cannot be reused indefinitely and that exceptions expire automatically or are revalidated on a schedule.
Common mistake: Treating recertification as the whole control. Review without timely de-provisioning only confirms that stale access is visible, not that it is removed.
Practitioner takeaway: The decisive question is whether access decisions are closed-loop. If the control cannot prove that business need, entitlement, review, and removal are linked, it is vulnerable to drift even when audit evidence appears complete.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org