Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Which frameworks require periodic access reviews, and who…
Governance, Ownership & Risk

Which frameworks require periodic access reviews, and who is accountable when triggered access changes are missed?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 23, 2026 Domain: Governance, Ownership & Risk

Frameworks such as SOC 2, SOX, ISO 27001, and PCI DSS expect periodic review in some form, so the organisation remains accountable for a working baseline even when it adds event-driven controls. If a triggered change is missed, ownership usually sits with identity governance, HR data quality, and the business manager approving access, depending on the review model.

Why This Matters for Security Teams

Periodic access reviews are not just a compliance checkbox. They are the control that tests whether identity data, approvals, and entitlements still match reality after role changes, terminations, vendor offboarding, and emergency access. Frameworks such as SOC 2, SOX, ISO 27001, and PCI DSS all expect some form of review discipline, while NIST Cybersecurity Framework 2.0 reinforces governance as an ongoing function, not a one-time event.

The practical risk is missed trigger events. If HR does not update a departure, if the business manager ignores an exception, or if identity governance fails to recertify a sensitive entitlement, access can remain active long after it should have been removed. NHIMG research shows how often hidden identity problems persist in the background: the Ultimate Guide to NHIs — Regulatory and Audit Perspectives connects governance to auditability, while the broader Ultimate Guide to NHIs notes that only 5.7% of organisations have full visibility into their service accounts.

In practice, many security teams discover missed review triggers only after an audit sample, an access complaint, or a post-incident entitlement sweep has already exposed the gap.

How It Works in Practice

Most access review programs combine periodic certification with event-driven checks. The periodic element answers, “Does this person still need this access?” on a quarterly, semi-annual, or annual cadence. The event-driven element answers, “Did something change that should have altered the entitlement earlier?” Common trigger points include job changes, manager changes, termination, leave of absence, project completion, and privileged role assignment. Current guidance suggests both controls should exist together because either one alone leaves blind spots.

Operationally, accountability is usually shared but not equal. Identity governance owns the review workflow, evidence, and reminders. HR data quality owns the accuracy and timeliness of lifecycle events. The business manager or application owner usually owns the approval decision for access that is still justified. For regulated scopes, internal audit or compliance may test whether the control operated as intended, but they do not typically own remediation.

  • Use a system of record for role and status changes, then feed it into IAM and recertification tooling.
  • Define who must approve each access type, especially privileged, financial, or production access.
  • Track missed triggers as control failures, not just operational misses.
  • Require removal or reapproval within a fixed service level when a review is overdue.

This model aligns well with the OWASP Non-Human Identity Top 10 approach to lifecycle control, and with NHIMG’s NHI Lifecycle Management Guide, which emphasizes that governance only works when provisioning, review, rotation, and revocation are connected end to end. These controls tend to break down when HR, IAM, and application ownership are split across separate ticketing systems because no single team can reliably close the loop.

Common Variations and Edge Cases

Tighter review controls often increase operational overhead, requiring organisations to balance audit assurance against reviewer fatigue and slow-moving access workflows. That tradeoff matters because not every framework expects the same cadence or level of evidence, and best practice is evolving for how much automation is acceptable.

For example, SOC 2 and ISO 27001 commonly support risk-based review intervals, while SOX-scoped access may demand stricter evidence around financial systems. PCI DSS typically expects access to be restricted and periodically reviewed, but the exact frequency depends on scope and control design. Where there is no universal standard for a specific cadence, organisations should document their rationale, such as high-risk system access being reviewed more often than low-risk general user access.

Missed triggered changes raise a second question: who is accountable when the review was never started versus when the review was started but the approver failed to act? In practice, missed initiation usually points to identity governance or upstream HR data quality. Missed approval usually points to the business owner, application owner, or delegated approver. If the control was automated but failed, then the system owner and control owner both need to be in the remediation chain. NHIMG’s Ultimate Guide to NHIs - Key Challenges and Risks is useful here because it shows how governance gaps often emerge from incomplete visibility rather than a single policy failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, SOC 2 and ISO 27001 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01Ongoing oversight supports periodic review and missed-change accountability.
OWASP Non-Human Identity Top 10NHI-06Lifecycle and entitlement review gaps are central NHI control failures.
NIST SP 800-63Identity proofing and lifecycle integrity underpin who still deserves access.
SOC 2SOC 2 expects control operation and evidence for periodic access review.
ISO 27001ISO 27001 requires access control governance and periodic reassessment.

Use authoritative identity data so review decisions reflect current employment status.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 23, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org