Join our Newsletter — 33% off our NHI Course

What happens when an organisation cannot attribute an account to an owner during access review?

An unattributed account cannot be measured against a job function, so it cannot be treated as normal access. It should go directly to a human reviewer, because the absence of ownership is itself a governance finding. In practice, these accounts often reveal weak account lifecycle control, incomplete inventory, or unmanaged access that no policy engine can safely classify.

What it means when an account has no attributable owner

When an access review cannot tie an account to a named owner, the review has lost the basic context needed to decide whether the access is still justified. That account is no longer simply “approved” or “unapproved”; it is an unresolved governance issue that may represent stale access, a shared credential, or a process gap in lifecycle control.

For practitioners, the key point is that ownership is not a cosmetic field. It is the link that lets reviewers test business purpose, recertify entitlement, and decide whether the account belongs in the current access model at all. Without that link, the safest assumption is that the account needs manual investigation, not automated approval.

Why unattributed accounts break access review logic

Access review depends on comparing an account to a legitimate role, function, or control objective. If no owner can be identified, the reviewer cannot reliably confirm whether the account still serves an active business need, whether it has been transferred, or whether it should have been removed already.

This is why unattributed accounts often surface weaknesses beyond the review itself: incomplete inventory, poor joiner-mover-leaver handling, orphaned entitlements, or shared use of credentials. In identity programs, missing ownership is usually evidence that the surrounding governance model is not maintaining a dependable map between accounts and accountable people or systems.

A related IAM and IGA Basics resource is useful here because it frames access review as part of broader identity governance, not a standalone checkbox.

How teams should treat the account during review

An unattributed account should be escalated into a human review queue and held out of any bulk recertification path until ownership is established. The reviewer should determine whether the account is active, what system or function it serves, who can approve it, and whether the account should be re-owned, disabled, or removed.

In practice, the immediate question is not “is this access low risk?” but “can anyone responsibly vouch for it?” If the answer is no, the account has already failed the governance test. The organization should then trace the account back through provisioning records, system logs, change tickets, or directory metadata to reconstruct ownership or prove the account is obsolete.

That approach aligns with the lifecycle and cleanup emphasis in NHIMG’s NHI Lifecycle Management Guide and the broader issue set in Top 10 NHI Issues, both of which stress ownership, discovery, and offboarding as control points.

Risk and Threat Considerations

Unattributed accounts create governance risk because they can sit outside normal recertification, making them easier to miss, harder to revoke, and more likely to accumulate excessive access. They also create a trust gap: if no owner exists, an attacker or careless operator may be able to exploit the account with less visibility and weaker accountability.

Failure mechanism: The organization cannot validate entitlement against a business purpose, so stale, shared, or orphaned access can persist through review cycles and escape cleanup.

Impact: Over time, these accounts can expand the blast radius of a compromise, weaken audit evidence, and undermine confidence in the access review itself.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Unattributed accounts often indicate weak credential and account lifecycle control.
AC-2 — Account Management Access review depends on accountable account ownership and lifecycle governance.
AU-6 — Audit Review, Analysis, and Reporting Review findings need escalation and follow-up when account ownership cannot be established.
Recommendation — Track ownership for each authenticator and revoke or reissue credentials when ownership is unknown. Require accountable ownership records before recertifying or retaining any account. Escalate unattributed accounts as audit findings and document remediation before closure.
ISO/IEC 27001:2022 A.5.16 — Identity management Owner attribution is part of managing identities across their lifecycle and accountability.
A.5.18 — Access rights Access rights cannot be properly reviewed when the account owner is unknown.
Recommendation — Maintain identity records that tie each account to a responsible owner and lifecycle state. Review and remove access rights that cannot be justified by a verified owner.

Practitioner Guidance

What to verify: Confirm whether the account has a current system owner, approver, or service owner in the authoritative inventory before trusting any recertification result. If no owner exists, treat the record as unresolved until the gap is closed.

Decision rule: If the account cannot be linked to a responsible owner and a defensible business function, do not approve it by exception. Put it on a remediation path that ends in re-ownership, disablement, or deletion.

What practitioners underestimate: Missing ownership is often the symptom, not the root cause. The real issue is usually weak lifecycle discipline, so fixing only the review workflow without correcting provisioning and deprovisioning controls will leave the same problem in place.

Practitioner takeaway: An unattributed account should be treated as an exception requiring investigation, not as a neutral record awaiting routine approval, because the absence of ownership already signals a control breakdown.