Banks should centralise identity governance, automate certification workflows, and align identity controls with organisational change rather than treating IAM as a standalone tool project. When reviews are standardised and automated, teams can complete certifications on time more consistently, reduce manual effort, and lower the complexity of security administration across fragmented environments.
Why This Matters for Security Teams
Manual access certification is one of the fastest ways for identity governance to become a bottleneck. When reviewers are asked to validate sprawling access lists without context, they default to rubber-stamping, delaying decisions, or escalating everything for exception handling. For banks, that creates audit friction, weakens least privilege, and consumes time that should be spent on risk reduction. The control problem is not just volume. It is the lack of standardisation across business units, applications, and privileged entitlements.
NHIMG research shows that only 5.7% of organisations have full visibility into their service accounts, which helps explain why certification campaigns often miss the identities that matter most. The Ultimate Guide to NHIs also highlights how excessive privileges and poor lifecycle discipline make identity review a recurring operational burden rather than a one-time cleanup. Banks that still rely on spreadsheet-driven attestations usually discover access drift only after an audit finding or an incident forces a deeper review.
Current guidance from the OWASP Non-Human Identity Top 10 and NIST SP 800-53 Rev 5 Security and Privacy Controls points toward repeatable identity governance, not ad hoc review cycles. In practice, many security teams encounter certification failure only after reviewers have already approved access they could not meaningfully assess.
How It Works in Practice
Banks reduce the burden by shrinking what reviewers must decide. Instead of asking managers to inspect every entitlement, identity governance should pre-classify access by risk, owner, and business function, then route only material exceptions to human review. Standard entitlements, low-risk roles, and time-bound access can be auto-certified under policy, while privileged or out-of-pattern access is escalated.
This works best when certification is fed by authoritative identity data and lifecycle events. Joiner-mover-leaver signals, role mappings, application ownership, and usage evidence should be normalized before the campaign begins. That means reviewers see business-relevant context, not raw technical lists. The 52 NHI Breaches Analysis is useful here because it shows how missed governance often begins with identities that were never properly classified, owned, or retired.
- Use policy-driven certification tiers so low-risk access can be auto-approved.
- Group entitlements by role, application, and business owner instead of reviewing line by line.
- Trigger certifications from change events, such as transfers, new applications, or privilege grants.
- Feed review screens with usage, last access, and approval history so reviewers have context.
- Retire stale access continuously, so campaigns focus on exceptions instead of cleanup.
For control design, banks should align identity governance with the control intent in NIST SP 800-53 Rev 5 Security and Privacy Controls while using the Ultimate Guide to NHIs — Key Challenges and Risks to identify where certification noise is being driven by excessive privilege, missing ownership, or poor offboarding. These controls tend to break down when entitlement data is fragmented across legacy platforms and cloud services because reviewers cannot tell which access is still valid.
Common Variations and Edge Cases
Tighter certification automation often increases policy design and data-quality overhead, requiring organisations to balance reviewer workload against the effort needed to maintain accurate role models and ownership records. That tradeoff becomes sharper in banks with mergers, outsourced operations, or heavy use of privileged service accounts, where no single certification template fits every environment.
Best practice is evolving, but current guidance suggests that manual attestation should be reserved for high-risk access, not treated as the default. For third-party access, shared admin accounts, and emergency privilege, banks usually need separate review paths with shorter review intervals and stronger evidence requirements. The Sisense breach is a reminder that exposed credentials and unmanaged access paths can create review blind spots long before a formal campaign starts.
Where organisations rely on exception-heavy access models, certification automation will not fully eliminate manual work. It will, however, concentrate effort where risk is highest. That is the right outcome. The practical goal is not zero human involvement, but fewer reviews that matter more.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Access review noise often starts with poor NHI ownership and classification. |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege review and periodic access validation map directly to access control governance. |
| NIST AI RMF | GOVERN | Automated certification needs accountability, oversight, and documented decision logic. |
| OWASP Agentic AI Top 10 | A07 | Where AI assistants help with review, unsafe automation can approve access without context. |
| CSA MAESTRO | IAM | MAESTRO emphasizes identity-aware controls and workflow governance for automated access decisions. |
Constrain AI-assisted review to recommendation support and keep approval authority human-governed.
Related resources from NHI Mgmt Group
- How should security teams use AI to reduce certification fatigue in access reviews?
- Why do manual access reviews break down as entitlement sprawl grows?
- What breaks when healthcare teams rely on manual access reviews and role management?
- How should security teams run access reviews for non-human identities?