Join our Newsletter — 33% off our NHI Course

How should security teams sequence access certification and segregation of duties analysis in an identity governance program?

Most teams should start with access certification, then use the cleaned entitlement set to run segregation of duties analysis. That order removes stale access, narrows the conflict surface, and makes reviews more efficient. It also creates a current baseline of who really needs access, which improves policy quality and reduces wasted effort on obsolete privileges.

Why this sequence works in identity governance

Access certification should usually come first because it answers a simpler but essential question: what access is still present, and who can actually justify it today? Once that entitlement set is cleaned, segregation of duties analysis becomes sharper because you are testing a current access model rather than a pile of stale grants, orphaned roles, and legacy exceptions.

The practical benefit is not just efficiency. Certification reduces noise in SoD rules, lowers false conflict rates, and gives reviewers a baseline that better reflects real business use. That matters most in mature identity governance programmes where entitlement inventories are large, role mining is imperfect, and review fatigue can quickly undermine control quality.

Teams that reverse the order often end up analysing conflicts against access that should have been removed in the first place. That creates unnecessary remediation work, makes exceptions harder to interpret, and can leave a false impression that SoD problems are larger or more deeply embedded than they really are.

Where sequencing can change the control outcome

Sequencing is not only about process hygiene, it affects the quality of the policy itself. If certification runs first, the SoD model can be tuned against a cleaner entitlement baseline, which improves the precision of toxic combination detection and makes role redesign more realistic. If SoD runs first, policy teams may spend time flagging conflicts on access that disappears during certification anyway.

That said, the order can be adjusted in narrow cases. If you are onboarding a highly regulated population, or if a new application has a very small and well-understood entitlement set, a preliminary SoD pass can help define hard blocks before certification begins. In most enterprise programmes, though, the better default is still to certify access first, then run SoD against the reduced set.

This is especially important when entitlements are spread across roles, direct grants, and inherited privileges. Certification exposes those overlaps, while SoD analysis interprets whether the remaining access creates a real duty conflict that should be removed, remediated, or formally approved with compensating controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 6 — Access Control Management CIS Control 6 directly covers access review and least privilege for identity governance.
5 — Account Management Account lifecycle hygiene supports clean entitlement data for certification and SoD.
Recommendation — Review and remove unnecessary access before evaluating toxic combinations. Revoke stale accounts and privileges before running segregation of duties checks.
NIST CSF 2.0 PR.AA — Identity Management, Authentication, and Access Control PR.AA governs access control decisions that underpin certification and SoD.
GV.RM — Risk Management Strategy Sequencing certification before SoD is a governance decision about control quality and risk reduction.
Recommendation — Use access reviews to validate current entitlements before enforcing conflicting-access rules. Set review sequencing that reduces stale access before conflict analysis.
ISO/IEC 42001:2023 A.5.6 — AI System Monitoring and Measurement Only if identity governance is partly automated by AI, sequence controls so cleaner data improves decision quality.
Recommendation — Measure whether upstream access cleaning improves downstream policy decisions.

Practitioner Guidance

What to prioritise: Start with the highest-risk access classes, such as privileged, financial, production, and third-party entitlements, then move into broader population reviews. That sequence gives you the fastest reduction in blast radius before you invest effort in conflict analysis.

What to verify: Confirm that certification outputs are actually feeding the SoD model as a cleaned entitlement source, not as a static report. If the SoD engine is still analysing expired, inherited, or duplicate access, the programme is doing extra work without improving control quality.

Common mistake: Treating SoD analysis as a standalone compliance exercise. In practice, the strongest programmes use certification to remove stale access first, then use SoD to govern what remains, which makes remediation clearer for application owners and auditors alike.

Practitioner takeaway: The best sequence is the one that turns access review into a data-cleaning step for conflict analysis, because SoD only becomes trustworthy when it is applied to a current and defensible entitlement baseline.