Manual certification processes tend to miss stale entitlements, overload reviewers, and slow remediation, especially when users span multiple systems and business units. That creates audit fatigue, inconsistent decisions, and delayed revocation of unnecessary access. In practice, manual review also makes it harder to prove control effectiveness because evidence is fragmented and difficult to reproduce.
Why This Matters for Security Teams
Manual access certifications fail in ERP environments because the access model is rarely simple enough for human review to keep pace. Roles are layered, entitlements are inherited across finance, procurement, HR, and operations, and the same user may appear under multiple accounts or business units. That creates blind spots that turn review campaigns into paperwork rather than control assurance. Current guidance from the OWASP Non-Human Identity Top 10 also reinforces a broader point: when identity is complex, governance breaks down first at the review step, then at revocation.
For ERP platforms, the problem is not just stale access. It is the operational cost of forcing reviewers to decide on dozens or hundreds of entitlements without reliable context about business ownership, segregation of duties, or whether access is still needed for a live process. NHIMG research shows only 5.7% of organisations have full visibility into their service accounts in the broader identity estate, which is a useful warning sign for ERP governance as well. In practice, many security teams discover access drift only after an audit exception or a post-incident cleanup, rather than through intentional review discipline.
How It Works in Practice
Effective certification in complex ERP environments depends on separating policy definition from review execution. Manual campaigns usually ask managers to approve or reject access based on names, titles, or spreadsheet exports. That approach breaks down because ERP entitlements are often indirect. A user may inherit access through a position, a composite role, a temporary project assignment, or a cross-system integration account. Reviewers cannot reliably infer whether access is appropriate unless the campaign includes ownership metadata, entitlement lineage, last-use evidence, and segregation-of-duties conflicts.
Practitioner guidance increasingly favors automated evidence gathering, policy-based scoping, and exception handling routed to the true business owner. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because access review, least privilege, and auditability are not separate problems in ERP. They are one control chain. Teams should ensure each certification item can answer four questions at review time: who approved the access originally, what business process depends on it, when it was last used, and what revocation path exists if it is no longer justified.
NHIMG’s Ultimate Guide to NHIs notes that 97% of NHIs carry excessive privileges, which matters in ERP because service accounts, batch jobs, and integration identities often bypass the same review discipline applied to humans. When those identities are included in manual certifications, reviewers usually lack the technical context to judge whether the access is safe. A stronger model is to pre-classify entitlements by risk, route privileged or indirect access to specialist approvers, and revoke low-confidence access automatically when evidence is missing. These controls tend to break down when ERP customisations are heavy and entitlement metadata is incomplete because reviewers cannot validate ownership or usage with confidence.
Common Variations and Edge Cases
Tighter certification rules often increase operational overhead, requiring organisations to balance governance quality against reviewer fatigue and process cycle time. That tradeoff becomes more visible in ERP landscapes with shared service centers, seasonal workforce changes, acquired business units, or highly customised role hierarchies. In those cases, manual review may still have a place for a narrow set of high-risk entitlements, but current guidance suggests it should not be the default for broad population recertification.
There is also no universal standard for how much runtime evidence a reviewer must see before approving access. Some teams use last-login signals, others use transaction history, and others rely on compensating controls such as downstream approval logs. The important point is consistency: if a control is not reproducible, it is difficult to defend during audit or incident response. NHIMG’s 52 NHI Breaches Analysis is a reminder that identity failures often compound through stale access and weak governance, not through a single obvious misconfiguration. Manual certification becomes especially weak when ERP roles are shared across environments or when revocation requires coordinated changes in multiple connected systems because a reviewer may approve removal in one system while access persists elsewhere.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Manual certifications often fail to keep least privilege current across ERP entitlements. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management covers provisioning, review, and removal of ERP access. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Stale or excessive non-human access in ERP mirrors the NHI governance failure pattern. |
| NIST AI RMF | Manual review loses context under complex, adaptive system behaviour and weak traceability. | |
| CSA MAESTRO | Complex ERP workflows need policy-driven approvals and continuous oversight, not one-time reviews. |
Apply MAESTRO-style controls to automate context collection and exception handling for access reviews.
Related resources from NHI Mgmt Group
- How should organisations control access to export controlled information in complex ERP environments?
- How should organisations extend access governance across complex application environments without losing control of compliance risk?
- What breaks when access certifications and lifecycle controls are missing from SAP identity governance?
- How should security teams unify identity controls across human and non-human access in complex enterprise environments?