Identity Governance

Access Review Statistics: What 215 Security Leaders Told Us in Our Survey

Deeksha Chowdhury
Product Marketing Manager, Zluri
Last Updated
September 17, 2025
8 MIn read

Ready to secure your identity surface?

About the author

Deeksha is a Product Marketing Manager at Zluri. She has five years of SaaS experience. Her work focuses on product positioning, messaging, and GTM strategy for Zluri’s Identity Governance and Administration platform. With an IT background, she understands the challenges IT and security teams face around access management and automation. That helps her bridge technical depth with clear, outcome-driven messaging for decision-makers. In her spare time, she enjoys traveling, dancing, and drawing.

How long does an access review really take, who actually misses deadlines, and does automation deliver what it promises? We surveyed 215 security, GRC, compliance, and IT leaders at US companies with 500 to 5,000 employees, all of whom hold decision-making power over access reviews. In this analysis, we break down what the data says, including a few findings that surprised us.

Every vendor in this market, us included, tells you that manual access reviews are painful and automation fixes them. That claim deserves numbers, not adjectives. So we ran the survey and, in this piece, we're publishing the analysis: where the time actually goes, who misses deadlines and by how much, what automation measurably changes, and, just as honestly, where it changes less than the pitch suggests.

Who we surveyed

All 215 respondents work at US companies with 500 to 5,000 employees, hold at least partial decision-making power over access reviews, and work in organizations that conduct them. Roles span CEOs and CIOs, IT directors and managers, VPs of IT and security, CISOs, security directors, compliance officers, and information security managers. Industries lean toward IT and telecoms, technology, manufacturing, finance, retail, and healthcare.

On automation maturity, the sample breaks into three groups we'll compare throughout:

One context point before the findings: these are not occasional reviewers. 47% run reviews quarterly and another 27% run them monthly. Whatever the review process costs, most organizations are paying it at least four times a year.

Finding 1: A single review cycle eats a working week, and manual teams lose far more

Asked how long one full review cycle takes from start to finish, 38% of all respondents said five to seven days. The distribution shifts sharply by process maturity:

Read the top and bottom rows together. Nearly half of fully automated organizations finish inside three days; only a fifth of manual organizations do. And manual teams are three times more likely than fully automated ones to blow past a full week.

Headcount tells the same story. The most common answer overall is 11 to 20 people involved per cycle, but 43% of manual organizations pull in 21 to 50 people, versus 18% of fully automated ones. At quarterly cadence, that's a cross-functional crowd assembled four times a year.

Finding 2: 41% of manual organizations overshoot their deadlines

We asked about the main challenges organizations face in reviews. Among fully manual organizations, 41% report overshooting deadlines, against 18% of fully automated ones and 27% of the full sample.

The full challenge ranking is revealing:

Notice what sits at number two: modifying access individually for each application after the review. That's remediation, and it outranks visibility, coordination, and errors. The decisions get made; pushing the resulting changes into each application, one app at a time through each app's owner, is where the process grinds. It's the same open loop we've written about in closed-loop remediation, now visible in survey data.

And one number on the other side of the ledger: 40% of fully automated respondents selected "there are no main challenges." Among manual respondents, 4% did.

Finding 3: Everyone claims their reviews are effective. The word "very" tells the real story

Here's the finding that made us look twice. Asked how effectively access policies are enforced during reviews, 96% of respondents across all three groups answered "very" or "somewhat" effectively. By that measure, nobody has a problem.

Split out "very effectively" alone and the groups separate:

  • Fully automated: 68% say policies are enforced very effectively
  • Fully manual: 49%
  • Partially automated: 44%

The gap between manual and automated isn't in whether leaders think enforcement works; almost everyone says it does. It's in how confidently they say it. Half of manual-process leaders hedge down to "somewhat," which is a reasonable position for someone whose enforcement depends on spreadsheets they can't fully verify.

The partial-automation dip is worth pausing on. Partially automated organizations report the lowest "very effective" rate of all three groups, lower than fully manual. One reading: partial automation surfaces problems that manual processes never see, without yet providing the means to fix them. You've bought visibility into your gaps before you've bought the ability to close them.

Finding 4: Remediation is the last thing anyone automates

Among respondents with partial or full automation, we asked which review steps are actually automated:

Remediation comes last, and it's the only step where nearly half of even the automated cohort still works manually. Combine this with Finding 2, where per-app access modification ranks as the second-biggest challenge overall, and the pattern is hard to miss: organizations automate the parts of the review that produce decisions and documents, and leave the part that changes actual access for last. The loop stays open precisely at the step the data says hurts most.

Finding 5: What automation measurably returned

Respondents who automated reported their reductions since doing so. The median lands in the 21 to 40 percent band on every metric:

  • Time spent on reviews: mean reduction around 38%, with 56% of respondents reporting a reduction above 30%
  • Errors: mean reduction around 37%, with half reporting above 30%
  • People needed to manage the process: mean reduction around 34%, with 47% reporting above 30%

These are self-reported and worth treating as directional, but the direction is consistent: automation returns roughly a third of the time, a third of the errors, and a third of the headcount. Meaningful, and also more modest than the 10x claims this market is fond of. The gains concentrate where automation actually reaches; per Finding 4, for many organizations that still excludes remediation, which caps the return.

Finding 6: Leaders connect access failures to breaches, in their own incident data

We asked respondents what share of security breaches, per their organization's own incident data, traces to three access failures:

  • Over-permissive access: 92% attribute at least some breaches to it; 49% attribute more than 30% of breaches to it
  • Third-party vendors retaining access: 88% attribute some; 48% attribute more than 30%
  • Ex-employees retaining access: 85% attribute some; 43% attribute more than 30%

These three failure modes are exactly what user access reviews exist to catch. Roughly nine in ten leaders see them showing up in real incidents, which explains the urgency in the next finding.

Finding 7: The barriers to automating aren't what you'd guess

91% of respondents agree their organization would benefit from automating access reviews, and 88% intend to automate within the next year. So what's holding the rest of the process back? Among organizations not yet fully automated, the top barriers:

Budget is second from the bottom. The blockers that actually rank are trust and fit: will a tool that holds the keys to every application be safe, will it map to how our organization actually works, and will it clear compliance review. That matches what respondents prioritize when evaluating tools, where accuracy (43%), security measures (43%), and ease of use (40%) lead the list, ahead of cost at 32%.

For anyone evaluating in this market, the data suggests the right first questions. Not "what does it cost," but "how does it secure its own access, and does its remediation reach our actual app stack." Our guide to the five ways to automate user access reviews maps the approaches against exactly these questions.

What the data adds up to

Three threads run through all seven findings.

The cost is real and concentrated. A working week per cycle, up to 50 people involved, four or more cycles a year, and a 41% deadline-miss rate among manual teams. The challenges IT teams report aren't hypothetical; they're the top rows of a ranked table.

Remediation is the stubborn remainder. It ranks second among all challenges, it's the least-automated step even among automated organizations, and it's the most plausible explanation for why partial automation shows the weakest confidence numbers. Reviews that decide but don't execute leave their teams holding the gap.

The market is about to move. With 91% convinced of the benefit and 88% planning to automate within a year, the question for most organizations is no longer whether but what to buy, and the data says they'll be evaluating on trust, fit, and reach into remediation rather than price.

We'll keep publishing what we find. If your own review process looks like the manual column in these tables, the numbers above are a reasonable forecast of what changing it returns.

Methodology

We surveyed 215 full-time leaders at US companies with 500 to 5,000 employees. All respondents hold senior management, C-level, or ownership roles; carry responsibility in at least one of compliance, GRC, identity governance, audit, security assurance, security or identity engineering, security operations, or InfoSec; work at organizations that conduct access reviews; and have at least input-level decision-making power over them. The sample was screened to include organizations across the automation spectrum: 24% fully manual, 53% partially automated, 23% fully automated. Percentages are of the full sample unless a segment is named. Reduction figures in Finding 5 are self-reported by respondents whose organizations have automated.

Frequently Asked Questions

How long does a user access review take on average?

In our survey of 215 enterprise leaders, the most common answer for one full review cycle was five to seven days (38% of respondents). Fully manual organizations skew longer: 18% take more than a week per cycle, versus 6% of fully automated organizations. Since most organizations review quarterly or monthly, that cost repeats at least four times a year.

What percentage of organizations miss access review deadlines?

27% of all respondents cite overshooting deadlines as a main challenge. Among fully manual organizations, that rises to 41%, versus 18% of fully automated ones.

How much time does automating access reviews save?

Respondents who automated report a mean time reduction of roughly 38%, with more than half reporting reductions above 30%. Error reductions (around 37%) and headcount reductions (around 34%) follow the same pattern. Gains are capped where remediation remains manual, which our data shows is the least-automated step.

How many people are involved in an access review?

The most common range is 11 to 20 people per cycle. 43% of fully manual organizations involve 21 to 50 people, versus 18% of fully automated organizations.

What share of breaches trace back to access issues?

Per respondents' own incident data: 92% attribute at least some breaches to over-permissive access, 88% to third-party vendors retaining access, and 85% to ex-employees retaining access. Roughly half of respondents attribute more than 30% of their breaches to each of these failure modes.

Ready to secure your identity surface?