Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do spreadsheet access reviews create compliance risk…
Governance, Ownership & Risk

Why do spreadsheet access reviews create compliance risk even when managers sign them?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Because a signature only proves that a list was checked. It does not prove that reviewers understood the access, identified a conflict, or that revoked access was removed and documented. Compliance risk remains when the workflow cannot show decision context, remediation timestamps, and exception rationale.

Why a manager’s signature is not enough

A signed spreadsheet can show that a review happened, but it does not prove the review was informed, complete, or acted on. In access certification, the compliance question is usually whether the business can demonstrate who reviewed the access, what they understood, what they approved, what was revoked, and when remediation was completed. A signature without that trail leaves a weak audit record.

That weakness matters because spreadsheet reviews are often treated as evidence of control operation when they are really only evidence of form completion. If the process cannot tie each line item to a specific business rationale, risk owner, or remediation outcome, the organisation may pass the review operationally while still failing the control objective. The signature becomes a proxy, not proof.

Spreadsheet reviews also degrade quickly when the list is stale, the reviewer does not own the application, or the access model mixes people, shared accounts, service accounts, and temporary exceptions. In practice, the control needs to show that access decisions were made against current entitlements, not against an export that may already be out of date by the time it is signed.

What auditors expect beyond the signature

A defensible access review needs evidence of decision context, not just approval marks. That usually means the reviewer can explain why access was retained, removed, or escalated; the system can show who executed the remediation; and the record captures the date the change actually took effect. Reviews that stop at a checkbox rarely satisfy that standard because they do not establish control closure.

Access Reviews and Certification Guide is useful here because it focuses on closing the loop, cutting review volume, and adding context to decisions. That is the difference between a ceremonial recertification and an access governance control that can stand up in audit.

What matters most is traceability. If a reviewer flags access as unnecessary, the workflow should show when the revocation was raised, who approved or executed it, and whether the account still existed after the supposed remediation date. If that chain is missing, the organisation may be able to prove review activity, but not control effectiveness.

How to make spreadsheet reviews defensible

Spreadsheets can still be used as a working tool, but only if the process around them creates durable evidence. The review should preserve the original entitlement list, the reviewer identity, the business justification for each decision, and the final state after remediation. Without those elements, the organisation is relying on memory and manual follow-up rather than a verifiable control record.

IAM and IGA Basics is a helpful baseline because it frames access review as part of governance, not a one-off administrative task. For teams still using spreadsheets, that framing is important: the review output must be reconciled back to the identity and entitlement source of truth, or exceptions and stale access will persist unseen.

Segregation of Duties (SoD) Guide also matters because many spreadsheet reviews are supposed to detect toxic combinations, not merely confirm that names appear on a list. If the workflow does not identify conflicts, mitigations, and approvals separately, a signature can hide a material control failure rather than resolve it.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess reviews and revocation evidence are core account governance functions.
AC-6 — Least PrivilegeReviews should remove unnecessary access and enforce minimum required privileges.
AU-2 — Event LoggingReview workflows need timestamps and evidence of who approved and when remediation occurred.
Recommendation — Document access decisions and verify revocation is completed and recorded. Use review outcomes to reduce entitlements to the minimum needed. Log review decisions and remediation actions with time-stamped evidence.
ISO/IEC 27001:2022A.5.15 — Access controlThe subject concerns governing and reviewing access rights and entitlements.
A.5.18 — Access rightsAccess rights must be reviewed, adjusted, and revoked with documented accountability.
Recommendation — Require access reviews to produce auditable access-control evidence. Review access rights regularly and retain evidence of revocation.

Practitioner Guidance

What to verify: Check that each review record contains the decision, the rationale, the remediation owner, and the timestamp for actual removal, not just reviewer sign-off. If those fields are absent, the control is evidentially weak even if the spreadsheet is complete.

Common mistake: Treating a signed file as equivalent to closed remediation. In practice, that shortcut leaves a gap between approval and enforcement, which is where compliance findings usually emerge.

Decision rule: If you cannot show that revoked access was removed from the live system and documented with timing, classify the review as incomplete for audit purposes until that evidence exists.

Practitioner takeaway: The control objective is not to collect signatures, it is to prove that access decisions were informed, conflicts were handled, and remediation actually happened.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org