Join our Newsletter — 33% off our NHI Course

Should IAM and GRC teams use a third recertification state for every campaign?

No. Use it only where the governance decision genuinely needs a separate path and a distinct operational follow-up. If the extra state is not tied to a specific outcome, it adds complexity without improving recertification quality or accountability.

When a Third State Helps, and When It Just Adds Noise

A third recertification state is only justified when it represents a distinct governance outcome, such as confirmed revocation, a bounded exception, or a pending remediation path that needs its own tracking and owner. In most campaigns, the core decision is already captured by approve, revoke, or defer, so a third state often becomes a cosmetic label rather than a control.

The practical test is whether the extra state changes how the review is executed, who must act, and what evidence is retained. If it does not change workflow or accountability, it is a reporting variant, not a governance requirement.

Where teams already struggle with review volume, ambiguous ownership, or weak closure discipline, the added state can make the process harder to interpret. A clean state model is usually better for reviewer speed, auditability, and exception handling unless the campaign truly needs a separate branch for follow-up.

How Third-State Design Affects Recertification Quality

Recertification quality depends more on decision clarity than on the number of status values. The campaign should force a reviewer to decide whether access stays, goes, or needs a specific follow-up action, and each state should map to one operational outcome. If a third state does not change the downstream response, it tends to hide indecision rather than improve governance.

That is especially important for IAM and GRC teams because recertification is only useful when it closes the loop on entitlement risk. A separate state can be useful when the workflow must distinguish between “approve temporarily with conditions” and “revoke after remediation,” but that distinction needs defined ownership, timing, and evidence capture.

In practice, the better design is usually the smallest state model that still preserves the decision trail. The more states a campaign has, the more likely reviewers are to treat the process as administrative triage instead of a meaningful access decision.

What Good Campaign Design Looks Like in Practice

Good design starts with state semantics, not tooling. Each state should answer a specific question: is access approved, denied, or waiting on a separate operational action? If the answer for the third state is vague, the campaign design is too complex.

For access reviews and certification, the strongest campaigns reduce reviewer effort while increasing closure quality, so they should minimise ambiguous outcomes and make remediation explicit. That same logic appears in IAM and IGA basics, where review and entitlement decisions are part of a broader governance loop rather than a standalone administrative task.

When the campaign includes service accounts, shared access, or other non-human entitlements, the state model must still support the same governance outcome: retain, remove, or route for a defined exception. A separate state is justified only if it changes the owner, the SLA, or the evidence required to close the item.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CIS Controls v8 CIS-5 — Account Management Campaign recertification is an account and entitlement governance control.
Recommendation — Standardise periodic access reviews and remove access that no longer has business justification.
NIST SP 800-53 Rev 5 AC-2 — Account Management Recertification campaigns govern account and entitlement lifecycle decisions.
AC-6 — Least Privilege A recertification state should support removal or containment of unnecessary access.
Recommendation — Require periodic review and adjustment of account privileges and roles. Use access reviews to reduce permissions to the minimum necessary.
ISO/IEC 27001:2022 A.5.18 — Access rights The question concerns governance of access-right decisions and their review state.
Recommendation — Review access rights on a defined cadence and revoke or adjust them when no longer justified.
CSA Cloud Controls Matrix IAM — Identity and Access Management Third-state recertification design is an IAM governance concern.
Recommendation — Define review states so access decisions map cleanly to IAM governance actions.

Practitioner Guidance

Decision rule: Use a third state only when the organisation can name the exact follow-up action, the accountable owner, and the evidence that proves the item was resolved. If you cannot do that, keep the model to the smallest set of states that reviewers can apply consistently.

What to verify: Test whether the extra state changes remediation time, closure rate, or audit clarity. If it merely creates a different label for “not yet finished,” it is adding process overhead without improving control effectiveness.

What good looks like: A reviewer can make the decision quickly, the state maps unambiguously to one workflow path, and exceptions do not linger because the campaign design already forces a closure owner and deadline.

Practitioner takeaway: recertification campaign should optimise for unambiguous outcomes, not for more statuses, because governance quality comes from enforced follow-through rather than from state count.