Join our Newsletter — 33% off our NHI Course

What do organisations get wrong about user access certification in ERP governance?

A common mistake is treating certification as a periodic paperwork exercise instead of an active control over access appropriateness. Effective certification should regularly confirm that privileges still match job function, regulatory expectations, and internal policy. When combined with automated identity data aggregation, it becomes a practical control for reducing access creep and supporting audit readiness.

Why Organisations Misread ERP Access Certification

ERP certification fails when it is treated as a calendar-driven sign-off rather than a control over whether access is still justified. In ERP environments, roles often accumulate through reorganisations, emergency grants, acquisitions, and job changes, so the reviewer is rarely looking at a clean snapshot. That is why Ultimate Guide to NHIs — Regulatory and Audit Perspectives matters even for human access: auditors care about evidence that privileges were actively validated, not merely touched. The same logic appears in the NIST Cybersecurity Framework 2.0, where governance and access review are linked to operational risk rather than paperwork completeness.

Many teams also underestimate how often ERP entitlements are technically “valid” but operationally wrong. A manager may approve access because the person still belongs to the department, while missing that the user no longer performs the duties tied to a sensitive finance or procurement role. In practice, many security teams discover access creep only after segregation-of-duties conflicts or audit exceptions have already surfaced, rather than through intentional review design.

How Effective Certification Works in Practice

Good certification starts with identity data quality, not reviewer effort. The certification campaign should compile current ERP roles, last-login evidence, SoD conflicts, ticket history, manager data, and system ownership so the approver sees context, not just a list of accounts. This aligns with the OWASP Non-Human Identity Top 10 emphasis on lifecycle control, because stale access is often a lifecycle failure before it is a permissions failure. It also mirrors Ultimate Guide to NHIs – Lifecycle Processes for Managing NHIs, which stresses continuous identity hygiene over one-time review events.

  • Segment reviews by risk, not by convenience. Sensitive ERP entitlements should be reviewed more often and by the right business owner.
  • Use auto-remediation for obvious mismatches, such as terminated users, duplicate accounts, and expired temporary access.
  • Require reviewers to attest to business need, not just acknowledge presence in the system.
  • Feed outcomes back into joiner-mover-leaver processes so recurring exceptions are eliminated at source.

Certification is strongest when it is integrated with access request, provisioning, and deprovisioning workflows, so that approval status and actual entitlement state stay in sync. It should also be supported by exception handling for shared service accounts, break-glass access, and delegated admin rights, because these cases need separate justification and shorter review windows. These controls tend to break down when ERP entitlements are fragmented across multiple instances or when business ownership for roles is unclear, because reviewers cannot reliably determine what the access is for.

Where Certification Gets Distorted by Real-World ERP Complexity

Tighter certification often increases reviewer workload, requiring organisations to balance audit defensibility against operational fatigue. That tradeoff becomes sharper in ERP estates with custom roles, inherited entitlements, and regional variants, where a simple approve-or-revoke workflow can hide risk instead of reducing it. Current guidance suggests that high-risk roles should be reviewed with stronger evidence, but there is no universal standard for how much evidence is enough in every ERP model.

One useful signal is whether the organisation can explain why a role exists, who owns it, and what business event should remove it. If that answer is missing, certification becomes a proxy for poor role engineering rather than a standalone control. The same governance problem is reflected in the 52 NHI Breaches Analysis and in the State of Non-Human Identity Security, where weak lifecycle discipline and poor visibility repeatedly show up as root causes. For mature programmes, certification should be a closing mechanism for residual risk, not the main mechanism used to discover it.

Certification also becomes less reliable when organisations rely on a single manager approval for inherited access, because line managers rarely know the full technical consequences of ERP entitlements. In those environments, current practice is evolving toward combined business-owner and control-owner review, especially for finance, payroll, and procurement. That approach reduces false confidence, but it only works when ownership is explicit and the review scope is narrowly defined.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AC-4 Access permissions must be reviewed to keep ERP rights aligned to job need.
OWASP Non-Human Identity Top 10 NHI-03 Lifecycle control applies when ERP accounts and entitlements go stale over time.
OWASP Agentic AI Top 10 Agentic review tools still need governed approval and context-aware guardrails.
CSA MAESTRO GOV-04 Governance should define ownership and accountability for access review decisions.
NIST AI RMF AI risk governance is relevant if analytics or AI assist access review decisions.

Tie ERP recertification to PR.AC-4 and require removal of access that no longer has business justification.