Of course it's a review process. That's why you need a developer ID. The only difference is that the app will be reviewed "later". Here is an example:
You sign an app like "uTorrent", all is working great, people can download and run it. Then mpaa tells Apple to ban your application because it's used to pirate their content. Apple now "reviews" your app and suspends your developer id. O top of that it tells gatekeeper to stop running the installed instances. Review done! Any question? Please review our TOS to find out why we blocked your app...bla bla blah
No it's not. It's an automated malware scan.
They can already revoke Developer ID certificates and block whatever they want by updating XProtect (even unsigned apps).