A campaign is failing when reviewers are working from stale data, the review window is too vague, or the process becomes so frequent that people stop giving it proper attention. Other warning signs include unclear objectives, inconsistent ownership, and responses that cannot be acted on because the evidence is incomplete. Those conditions make the results misleading instead of usable.
When Access Certifications Stop Producing Reliable Decisions
The clearest sign of a failing campaign is that the review no longer changes access in a meaningful way. If reviewers are looking at stale entitlements, vague scopes, or poorly defined ownership, they are not certifying current access risk, they are validating outdated records. At that point, the campaign may still be completing, but it is not producing defensible governance.
Another warning sign is reviewer fatigue. When the cadence becomes too frequent or the request set is too broad, people begin approving by habit rather than judgment. That is especially visible when the same entitlement patterns recur every cycle and nothing downstream is corrected. The process exists, but it is no longer functioning as a control.
A third failure mode is weak remediation closure. If reviewers raise exceptions but the evidence is incomplete, the action cannot be executed, or ownership is unclear, the campaign creates noise instead of risk reduction. A certification programme should produce decisions that can be acted on, not a queue of unresolved comments.
What the Failure Pattern Looks Like in the Process
One practical indicator is that the campaign is built around the review event instead of the access model. In a healthy programme, the review window is narrow, the objective is explicit, and the reviewer understands what decision is being made. In a failing one, the campaign becomes a generic attestation exercise with too many items, too little context, and no meaningful prioritisation.
Ownership problems are another strong signal. If no one can answer who owns the entitlement, who should respond to an exception, or who is accountable for cleanup after approval, the certification output will drift toward rubber-stamping. That is why access reviews need tight linkage to role ownership, application ownership, and remediation workflow, not just a mass send-out of reviewer notifications. NHIMG’s Access Reviews and Certification Guide is a useful reference for that operating model.
Campaign quality also declines when access data is incomplete or poorly classified. If entitlements are missing business context, duplicated across systems, or disconnected from actual usage, reviewers cannot tell whether access is appropriate. That is where broader identity governance discipline matters, because recertification depends on inventory, ownership, lifecycle status, and a usable access model. NHIMG’s IAM and IGA Basics and NHI Lifecycle Management Guide both reinforce that point from different angles.
How Practitioners Separate a Healthy Campaign from a Broken One
A healthy certification campaign is narrow enough to be reviewed carefully, current enough to be trusted, and tied to a remediation path that actually removes or corrects access. A broken campaign usually shows the opposite pattern: high volume, low signal, weak evidence, and repeated approvals that do not reduce standing privilege. If the campaign cannot influence revocation, role cleanup, or ownership correction, it is only reporting activity.
Practitioners should also watch for signs that the campaign is compensating for a bad access model. If every cycle requires reviewers to sort through too many exceptions, unclear entitlements, or poorly designed roles, the issue is no longer the review process alone. The underlying access architecture needs attention, including role quality, segregation rules, and lifecycle hygiene. NHIMG’s Role Mining and Role Design Guide and Segregation of Duties (SoD) Guide help make that distinction visible.
At scale, the most useful question is not whether the campaign finished on time, but whether it changed access posture. If the answer is no, the organisation may be measuring process completion instead of control effectiveness. That is the point where access review metrics should be tied to removal rates, exception closure, and stale-access reduction, not just reviewer response counts.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Access certification is a core account and entitlement review control. |
| Recommendation — Review accounts and entitlements routinely, then remove or correct stale access. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Certification campaigns support ongoing review and control of account access. |
| AC-6 — Least Privilege | Failed certifications often leave excessive access in place, undermining least privilege. | |
| Recommendation — Validate account access periodically and disable or adjust accounts that are no longer justified. Reduce privileges to the minimum required and remove unnecessary access after review. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access review outcomes should govern granting, changing, and removing rights. |
| A.8.2 — Privileged access rights | Certification failures are especially risky when privileged access is not properly revalidated. | |
| Recommendation — Periodically review access rights and revoke those that are no longer needed. Reassess privileged access regularly and ensure exceptions are explicitly approved and tracked. | ||
Practitioner Guidance
What to prioritise: Start by checking whether the review is current, scoped to a real access decision, and connected to cleanup. If the campaign lacks those three traits, the output should be treated as weak evidence rather than a reliable certification result.
What to verify: Confirm that each reviewer can see enough context to make a decision, that unresolved exceptions have an owner, and that the campaign can drive revocation or role correction without manual reconstruction. If those conditions are missing, the process is already failing operationally.
Common mistake: Treating completion rate as success. A fast campaign with stale data and habitual approvals is usually worse than a slower one with fewer, better-supported decisions.
Practitioner takeaway: An access certification campaign only works when it changes access reality; if it cannot produce current, actionable, and closed-loop decisions, it is governance theatre.
Related resources from NHI Mgmt Group
- What are the signs that a legacy access management stack is failing in practice?
- What are the signs that third-party access controls are failing in practice?
- What are the signs that a just-in-time access process is failing in practice?
- What are the signs that a ClickFix campaign is failing in practice?