Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do periodic access reviews leave audit gaps…
Governance, Ownership & Risk

Why do periodic access reviews leave audit gaps in identity governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

Periodic reviews create a time window where access drift, privileged activity, and segregation of duties conflicts are unobserved. That is why audit evidence built only from a review snapshot rarely tells the full story of control effectiveness across the period under test.

Why periodic reviews miss what audit evidence needs to prove

Periodic access reviews are point-in-time checks. They can confirm who had access on the review date, but they do not continuously capture entitlement drift, temporary elevation, or changes in segregation of duties risk between reviews. That creates a documentation problem for auditors, because the evidence reflects a snapshot, not the control operating across the whole period.

The issue is not that reviews are useless, it is that they answer a narrower question than most audit programs need. A review may show that a manager signed off on access, while still leaving no direct evidence of when access was granted, used, changed, or revoked during the interval under test.

In practice, the gap widens when organisations rely on review completion as proof of control effectiveness instead of pairing it with lifecycle evidence, access change logs, and exception tracking. Access that should have been removed can remain active for weeks or months, and privileged use during that time is invisible if the only artefact is the certification record.

What audit gap actually exists between a review and continuous control

A review is a validation event, not a complete control history. It does not, by itself, establish whether access stayed appropriate after approval, whether a privileged account was used outside its intended window, or whether a conflicting duty existed long enough to create exposure. The full audit story usually needs the underlying identity lifecycle, access governance, and privileged access records around the review.

That is why controls anchored only in quarterly or annual recertification often struggle to demonstrate operating effectiveness. The review can be accurate for the day it was performed and still be incomplete for the period being audited. If the control objective is ongoing least privilege or SoD enforcement, the evidence set must show more than periodic attestation.

For that reason, teams often need to treat the review as one signal among several, not the sole source of truth. Supporting evidence usually includes provisioning and deprovisioning events, ticketed approvals, privileged session records, role changes, and denial or exception history. A useful overview of that lifecycle context is in the IAM and IGA Basics guide, which ties access reviews to broader governance and entitlement management.

Why the gap matters for governance, privilege, and SoD findings

Audit gaps become material when the organisation must explain not just that access was reviewed, but that it was controlled throughout the audit window. That matters most for privileged users, shared accounts, service accounts, and any role set where segregation of duties can be violated silently between campaigns. In those cases, a clean review can coexist with a period of real exposure.

Periodic models also make it easier to miss reviewer fatigue and rubber-stamping. When the population is large or the context is weak, approvers may confirm access without checking whether the entitlement still matches job function, system ownership, or compensating controls. The result is a paper trail that looks complete while the underlying access posture keeps drifting.

NHIMG’s Access Reviews and Certification Guide is useful here because it treats review design as a governance control problem, not just a workflow problem. When SoD conflicts or privileged activity are in scope, the better question is whether the review process is closing the loop on actual access removal and conflict resolution.

Risk and Threat Considerations

Periodic reviews create a blind spot that adversaries and careless insiders can both exploit. The longer the interval between reviews, the more time there is for privilege creep, orphaned entitlements, and unobserved misuse of elevated access. That makes the control easier to satisfy administratively while still leaving a live exposure in production.

Failure mechanism: The review validates a historical snapshot, but access can change immediately afterward and remain effective until the next cycle. If revocation, monitoring, and exception handling are not tied to the review process, the organisation may record compliance without detecting the period of actual overexposure.

Impact: Audit evidence becomes weaker than the control it is meant to prove, SoD violations can persist undetected, and any breach investigation has less reliable history for reconstructing who could do what and when.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Audit EventsReviews need event history to prove control operation over time.
AC-2 — Account ManagementPeriodic reviews are part of account lifecycle governance and removal.
AC-5 — Separation of DutiesAudit gaps often hide SoD conflicts that arise between review cycles.
Recommendation — Log access grants, changes, and revocations so review evidence can be reconstructed. Tie recertification to account lifecycle actions and timely revocation. Monitor and remediate conflicting access continuously, not only at certification time.
CIS Controls v85 — Account ManagementPeriodic access reviews must be backed by account inventory and timely removal.
Recommendation — Maintain accurate account inventories and remove unneeded access promptly.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights need ongoing review, not only point-in-time approval evidence.
Recommendation — Review and revoke access rights using current entitlement evidence.

Practitioner Guidance

What to verify: Confirm that your evidence set shows both the review decision and the lifecycle events around it, especially provisioning, deprovisioning, privilege elevation, and exceptions. If you cannot demonstrate when access became active and when it was removed, the review alone is not strong audit evidence.

What to prioritise: Put high-risk access on shorter feedback loops, then reserve periodic recertification for lower-risk populations or as a backstop. Privileged and high-change access needs evidence that reflects ongoing control operation, not just campaign completion.

Practitioner takeaway: Treat access reviews as one control checkpoint in an identity governance chain, not as proof that access was continuously appropriate across the audit period.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org