Join our Newsletter — 33% off our NHI Course

What do organisations get wrong about access reviews and certification in IAM?

The most common mistake is relying on manual review cycles without enough automated analytics or normalized data feeding the IAM platform. That makes certification slow, expensive, and inconsistent, while also distracting business owners. The result is weak remediation discipline, poor visibility into entitlement drift, and a higher chance that violations survive multiple review cycles.

Why access reviews fail when they are treated as a calendar task

Access reviews go wrong when organisations treat them as a periodic checkbox instead of an evidence-driven control. If reviewers are forced to sign off on raw entitlement lists with no context, they cannot reliably tell which access is legitimate, stale, risky, or inherited. That is where certification becomes noisy, slow, and easy to rubber-stamp.

Good review design starts with the quality of the data being reviewed. Normalised entitlements, ownership data, role context, and usage signals turn certification from a memory test into a decision process. That matters because the control is supposed to confirm whether access is still justified, not merely whether someone clicked approve.

Organisations also underestimate how much access review quality depends on the surrounding operating model. If business owners do not understand the access they are certifying, or if remediation is handed off without closure, the process creates paperwork but not reduction in exposure. The better metric is not completed campaigns, but completed removals of unjustified access.

Where review programmes become expensive and inconsistent

The biggest cost driver is volume without prioritisation. When every entitlement is reviewed with equal weight, approvers spend time on low-risk items and miss the accounts, roles, and exceptions that actually need attention. Access Reviews and Certification Guide is built around this problem: reduce review load, add context, and focus effort where access risk is highest.

Another common failure is poor entitlement normalisation. If the same access appears in different formats across applications, clouds, and directories, reviewers cannot compare like with like. That is why review quality improves when entitlement data is mapped into a consistent model before the campaign starts, rather than after exceptions have already been approved.

Certification also breaks down when organisations expect business managers to compensate for weak IAM hygiene. IAM and IGA Basics is useful here because access review is only one part of a wider governance loop that also includes provisioning, role design, and entitlement ownership. If those upstream controls are weak, the review cycle becomes a recurring cleanup exercise.

What a more defensible access review model looks like

A defensible model starts with reviewing the right population at the right cadence. High-risk access, privileged roles, dormant access, and exception-heavy entitlements should not be treated the same as routine low-risk access. IGA Buyer’s Guide is relevant because platform capability matters here: connectors, role data, and workflow design determine whether the review process can actually scale.

Reviewers should see enough context to make a judgment without leaving the platform. That usually means last-use signals, business owner, application criticality, role membership, and whether the access is tied to a current job function. Without that context, certification tends to become an approval ritual rather than a control that reduces entitlement drift.

The strongest programmes also close the loop on remediation. If a reviewer flags access for removal, the item should move into tracked remediation with clear ownership and deadlines, not disappear into an email thread. Joiner-Mover-Leaver (JML) Guide supports this point because certification is most effective when it is tied to lifecycle events, not treated as a standalone annual event.

Risk and Threat Considerations

When access reviews are shallow or inconsistent, the main risk is not just inefficiency. Excess access survives long enough to create privilege creep, segregation-of-duties violations, and unnoticed residual access after role changes or departures. In environments with many applications or machine accounts, that becomes a standing exposure rather than a one-time control failure.

Failure mechanism: Weak data quality, broad review scopes, and manual approval pressure allow unjustified entitlements to be repeatedly re-certified, while remediation gaps let flagged access remain active.

Impact: Organisations accumulate stale and excessive access, lose confidence in certification outcomes, and increase the chance that misuse or lateral movement is enabled by access that should have been removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Access reviews exist to remove excessive access and enforce least privilege.
AC-2 — Account Management Certification depends on accurate account and entitlement lifecycle governance.
AU-6 — Audit Record Review, Analysis, and Reporting Evidence from usage and review outcomes improves access certification decisions.
Recommendation — Review entitlements regularly and remove access that is no longer justified. Maintain authoritative account records and retire stale access promptly. Use audit and activity evidence to support reviewer decisions and remediation.
ISO/IEC 27001:2022 A.5.15 — Access control Access reviews are a core access control governance activity.
A.5.18 — Access rights Certification is about confirming and revoking access rights that are no longer needed.
Recommendation — Define and enforce a formal access review process with clear ownership. Periodically recertify access rights and revoke unjustified entitlements.
CIS Controls v8 CIS-5 — Account Management CIS account management covers review, removal, and oversight of active accounts.
Recommendation — Inventory accounts and remove unused or inappropriate access on a recurring basis.
OWASP Non-Human Identity Top 10 NHI-05 — Overprivileged NHI The same certification failure pattern applies when non-human accounts retain excess privilege.
Recommendation — Review machine and service access for privilege creep and remove excess rights.

Practitioner Guidance

What to prioritise: Start with the entitlements that create the most blast radius, privileged access, shared access, dormant access, and roles with repeated exceptions. If a review cannot materially change exposure, it probably should not consume the same effort as a high-risk certification item.

What to verify: Before trusting a campaign, verify that the platform is pulling normalised entitlement data, current ownership, and usable context for reviewers. If reviewers are still asking basic questions about what an entitlement does, the operating model is not ready for certification at scale.

Common mistake: Treating a completed review cycle as evidence of control effectiveness. The control is only working if unjustified access is actually removed, not merely acknowledged.

Practitioner takeaway: Access reviews work when they are designed to reduce access, not to document a review event, so the real test is whether the process consistently converts decisions into remediation.

NHI Lifecycle Management Guide