Status: IN
CloudFormation does not detect drift on DynamoDB resource-based policies and does not reconcile out-of-band policy changes unless the template itself contains a policy change.
Source: entries/2026/03/11/amazondynamodb-latest-developerguide-rbac-considerationshtml.md