Join our Newsletter — 33% off our NHI Course

When does periodic access certification stop working for identity governance?

Periodic certification stops working when identities change faster than a review cycle can observe them. That is common in cloud, automation, and agentic environments where access is created, reused, and expanded between review windows. At that point, certification becomes historical documentation rather than a control that meaningfully limits exposure.

When review cycles become slower than the access changes they are meant to catch

Periodic certification stops being an effective governance control when access can be created, inherited, reused, or expanded between review dates. In cloud and automation-heavy environments, that gap is often large enough that the review only confirms what was true at a point in time, not what is safe now. At that stage, certification still has audit value, but it no longer meaningfully constrains exposure.

That shift matters because identity governance is supposed to reduce standing access, validate ownership, and catch privilege drift before it becomes a control failure. When the environment changes faster than the certifier can observe it, the process becomes backward-looking documentation rather than an active control. The 2024 ESG Report: Managing Non-Human Identities shows why this gap is material, with 72% of organisations saying they have experienced or suspect a breach of non-human identities, and two-thirds reporting a successful attack resulting from compromised non-human identities.

In practice, many teams only discover the weakness after an access path has already been abused or inherited far beyond what the last review approved.

How periodic certification fails in fast-moving environments

Periodic review works best when access changes slowly, ownership is stable, and the reviewer can reliably judge whether the entitlement is still justified. That assumption breaks down when systems create short-lived tokens, automated jobs spin up new access, and autonomous software expands its own operational reach without waiting for a governance cycle. In those conditions, the review window is too coarse to protect the actual trust boundary.

The failure is usually structural, not procedural. The reviewer may still ask the right questions, but the environment has already moved on. The result is a lagging signal that can miss privilege escalation, orphaned access, stale approvals, or access inheritance that was never visible in the original certification set. For a useful comparison of how privilege creep and review blind spots show up across machine access, see Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs, which is most useful here for understanding why lifecycle control matters more than a point-in-time attestation.

  • Access is granted and consumed faster than the next certification round.
  • Inherited permissions change without a visible owner-triggered event.
  • Reviewers approve an entitlement that is already obsolete or over-broad by the time they see it.
  • Evidence exists for audit, but not for timely risk reduction.

These controls tend to break down when access decisions are driven by automation, ephemeral infrastructure, or delegated execution paths that can change multiple times inside a single review cycle.

What to do when certification is no longer the primary control

Tighter certification often increases administrative overhead, requiring organisations to balance governance value against the speed of change. The practical answer is not to abandon certification, but to stop treating it as the main safety mechanism where access is dynamic. In those environments, certification should become a backstop for ownership and exception review, while day-to-day control shifts toward preventative entitlement design, short-lived access, and stronger lifecycle visibility.

That usually means more frequent event-driven checks, narrower default permissions, clear ownership for every privileged path, and evidence that access can be revoked quickly when a system or workflow changes. If the access model includes autonomous or machine-operated components, the reviewer should also verify whether the entitlement is still necessary at the point of execution, not only at the point of approval. For a control-oriented baseline, OWASP Non-Human Identity Top 10 helps frame the kinds of access and lifecycle weaknesses that periodic review often misses.

Where teams rely heavily on static, time-based review, the most common failure is mistaking recertification completion for actual access reduction. The process can look healthy while exposure keeps growing underneath it.

Practitioner Guidance:

What to prioritise: Treat any entitlement that can change between review windows as a candidate for stronger preventative controls, because the business risk is usually privilege drift, not review omission.

What to verify: Confirm that the certification population reflects current inherited access, delegated access, and active execution paths at the moment the review starts, not at export time.

Decision rule: If access can be created or expanded automatically, use certification as an exception-control and audit signal, while putting removal, expiry, and ownership checks closer to the source of change.

Practitioner takeaway: Periodic certification still has value, but only when the environment changes slowly enough that a point-in-time review can keep pace with real exposure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP Non-Human Identity Top 10 NHI-01 — Lifecycle and Ownership Periodic review fails when machine access changes faster than ownership can be reassessed.
NHI-04 — Privilege Management Overbroad access that expands between reviews is the core governance failure here.
Recommendation — Track lifecycle and ownership for non-human access so reviews reflect current exposure. Enforce least privilege and remove standing access that certification cannot keep current.
CIS Controls v8 6 — Access Control Management Access certification is an access-control process that needs stronger revocation and review discipline.
Recommendation — Review and revoke access paths that exceed current business need.
NIST CSF 2.0 PR.AC — Identity Management, Authentication and Access Control The issue is access control timing and governance across changing entitlements.
GV.RM — Risk Management Strategy Certification becoming historical documentation is a governance risk that needs a different control mix.
Recommendation — Align access control decisions to current identity state instead of stale review cycles. Shift governance to risk-based controls when periodic review lags operational change.