Because access often drifts between review cycles. Roles change, temporary permissions linger, and non-human identities can keep standing privilege long after the original need has ended. Reviews can confirm that access existed, but they cannot by themselves maintain least privilege as a continuous operating state.
Why periodic reviews find some excess access but not all of it
Periodic access reviews are point-in-time checks, so they can confirm whether a permission was valid on the day of review, but they do not stop privilege from accumulating between cycles. In modern iga programmes, that gap matters because access is no longer static: roles shift, apps proliferate, and machine credentials can outlive the business need that created them.
Two things make the miss rate worse. First, review scope is often too coarse, so certifiers see broad role membership instead of the effective permissions that matter. Second, reviewers are asked to approve or revoke access without enough context about usage, ownership, or business purpose, which makes “looks familiar” a common outcome.
That is why certification can become a control for evidence, not a control for continuous least privilege. The access may have been justified when granted, but if the review model does not capture drift, exception ageing, or non-human standing privilege, excessive access survives the cycle.
Where modern IGA breaks down in practice
The failure is usually not that reviews are absent, but that the operating model treats them as the main cleanup mechanism. When lifecycle events are disconnected from reviews, movers keep old access, temporary entitlements are never reclaimed, and orphaned service accounts retain privileges because nobody owns their removal.
Review fatigue also plays a real role. Large campaigns with many low-signal items push approvers toward rubber-stamping, especially when the reviewer cannot easily tell whether an entitlement is still used, inherited, or duplicated elsewhere. In that environment, the control becomes administratively complete but security-light.
Access review quality improves when IGA is fed by current ownership, entitlement lineage, and usage context. Access Reviews and Certification Guide and IAM and IGA Basics both reflect the practical gap between certification events and continuous governance.
How to reduce drift between review cycles
Effective programmes shift from review-only governance to review plus lifecycle enforcement. That means movers should trigger entitlement recalculation, leavers should trigger rapid revocation, and privileged or exception-based access should have explicit expiry rather than waiting for the next campaign. For non-human identities, periodic review is only useful if it is paired with ownership, rotation, and offboarding discipline.
The strongest control signal is not whether a reviewer clicked approve, but whether the entitlement still has a current business owner, a current purpose, and a bounded duration. If those three facts are missing, the access should be treated as suspect even if the last review passed.
Joiner-Mover-Leaver (JML) Guide, NHI Lifecycle Management Guide, and Role Mining and Role Design Guide support the practical move toward access that expires, remaps, or is redesigned before it becomes a recurring certification problem.
Risk and Threat Considerations
Excess access that survives review cycles creates a standing attack surface. If an account, role, or service credential keeps privileges after the original need has ended, an attacker who compromises it inherits more reach than the current business process intended.
Failure mechanism: Review campaigns are periodic, while privilege drift is continuous, so stale entitlements, inherited access, and unattended service credentials can remain effective long after they should have been removed.
Impact: The result is greater blast radius, easier lateral movement, and more opportunity for abuse of dormant or overextended access, especially where ownership and expiry are weak.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Periodic reviews miss lingering access when credentials and tokens are not managed continuously. |
| AC-2 — Account Management | The question is about access being granted, retained, and removed across its lifecycle. | |
| AC-6 — Least Privilege | Excess access is fundamentally a least-privilege failure that periodic review alone does not prevent. | |
| Recommendation — Enforce credential lifecycle controls so standing access expires or is rotated between review cycles. Automate account and entitlement changes so access is removed when business need ends. Continuously constrain permissions to the minimum needed for the current task and role. | ||
| CIS Controls v8 | CIS-5 — Account Management | The issue centers on account and entitlement drift that reviews fail to correct in time. |
| Recommendation — Maintain timely account and entitlement processes so stale access is removed between reviews. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Periodic reviews are an access-control mechanism that must be paired with ongoing enforcement. |
| Recommendation — Tie access approval to current business need and revoke access that no longer fits. | ||
Practitioner Guidance
What to prioritise: Focus first on access categories that can create irreversible or high-blast-radius exposure, including privileged roles, shared accounts, long-lived exceptions, and non-human identities with standing access. Those are the places where a missed review has the highest security cost.
What to verify: For each reviewed entitlement, verify the current owner, the current business justification, and whether the access is time-bounded or usage-bounded. If any one of those is missing, treat the item as incomplete governance rather than a clean approval.
Practitioner takeaway: Periodic reviews should be treated as a backstop, not the mechanism that preserves least privilege. Continuous lifecycle enforcement is what prevents drift; certification only tells you whether the drift was visible when the campaign ran.
Related resources from NHI Mgmt Group
- Why do periodic access reviews miss real identity risk in modern estates?
- Why does continuous access monitoring matter more than periodic access reviews in modern identity programmes?
- Who is accountable when access reviews miss excessive or orphaned access in a modern identity programme?
- How should security teams run access reviews for non-human identities?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org