Join our Newsletter — 33% off our NHI Course

Who is accountable for authentication risk when organisations move from passwords to passkeys?

Accountability usually sits with identity, security, application, and help desk owners together. Identity teams define assurance and recovery policy, application teams ensure compatibility, and support teams handle user access restoration. Executive ownership matters because migration changes both security posture and user experience, so success depends on coordinated governance rather than a single technical control.

Why This Matters for Security Teams

Moving from passwords to passkeys changes more than the login screen. It shifts authentication risk into device binding, recovery, lifecycle ownership, and support workflows. That means accountability cannot sit only with IAM engineering. It also touches application compatibility, help desk identity verification, policy exceptions, and executive risk acceptance. This is why passkey migration is a governance problem as much as a technical one.

Security teams often miss that authentication risk does not disappear when passwords do. It moves into enrollment quality, recovery assurance, sync behaviour, and fallback paths. Current guidance in NIST Cybersecurity Framework 2.0 and NIST SP 800-53 Rev 5 Security and Privacy Controls points to shared responsibility for identity assurance, access control, and incident handling rather than a single owner.

That is consistent with NHIMG research on identity risk. The Ultimate Guide to NHIs — Why NHI Security Matters Now shows how hidden identity weaknesses persist when ownership is unclear, and the same pattern appears in human authentication migrations. In practice, many security teams encounter passkey failures only after account recovery abuse or support escalation has already occurred, rather than through intentional governance design.

How It Works in Practice

Accountability for passkey authentication risk is usually distributed across four functions. Identity teams own assurance policy, enrollment standards, recovery rules, and step-up requirements. Security teams define acceptable risk, monitor abuse patterns, and verify that phishing-resistant authentication is actually enforced where it matters. Application owners must confirm that their systems support passkeys without weakening fallback paths. Help desk teams are responsible for identity proofing during account restoration and for resisting social engineering during recovery.

The practical control point is not the passkey itself, but the lifecycle around it. A secure migration needs:

  • Clear ownership for enrollment, recovery, suspension, and revocation.
  • Documented rules for high-risk recovery events, including device loss and account takeover suspicion.
  • Testing of application flows that still allow password fallback, legacy MFA, or bypass paths.
  • Logging and review of recovery actions, since support-assisted resets often become the weakest step.
  • Executive approval for residual risk where business constraints prevent full passkey coverage.

For organisations formalising identity governance, the Top 10 NHI Issues is a useful reminder that credentials fail when lifecycle ownership is fragmented, even when the authentication mechanism is strong. Passkeys reduce phishing exposure, but they do not remove the need for policy, assurance, and recovery discipline. Where possible, align the migration with ISO/IEC 27001:2022 Information Security Management so risk ownership, exception handling, and control testing are tied to a formal security management process.

These controls tend to break down in high-support environments with frequent device replacement, outsourced service desks, or legacy applications that still require password-based fallback because recovery pressure encourages weaker verification.

Common Variations and Edge Cases

Tighter authentication controls often increase support burden, requiring organisations to balance phishing resistance against user friction and recovery delays. That tradeoff is real, especially during staged migrations where not every application or user population can move at once.

There is no universal standard for passkey recovery accountability yet, so guidance suggests assigning one primary owner for policy and one accountable executive for residual risk. Shared accountability works best when it is explicit, written, and testable. If a vendor-managed identity platform handles sync or recovery, the customer still retains responsibility for approving the risk model and verifying it against internal requirements.

Edge cases matter. Shared-device environments, contractor populations, call-center workflows, and regulated step-up authentication can all require exceptions. In those cases, organisations should define when a passkey is mandatory, when an alternate factor is permitted, and who can approve temporary bypasses. The strongest programs treat these exceptions as time-bound risk decisions, not permanent workarounds. The lesson from NHIMG’s 2024 ESG Report: Managing Non-Human Identities is that unclear ownership and weak governance correlate with hidden identity exposure; the same pattern applies when passkey rollout leaves recovery and fallback controls ambiguous.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA Passkey migration depends on identity assurance and authenticated access governance.
NIST SP 800-63 Digital identity guidance frames assurance levels and recovery requirements for passkeys.
NIST AI RMF GOVERN Risk ownership and accountability must be explicit when authentication changes.
NIST Zero Trust (SP 800-207) PL-1 Zero Trust requires strong identity verification and controlled access paths.
OWASP Non-Human Identity Top 10 NHI-03 Credential lifecycle weaknesses mirror passkey recovery and fallback risk patterns.

Assign accountable owners for enrollment, recovery, and fallback authentication decisions.