They collapse nuanced governance into a false binary, which can distort audit trails and produce misleading certification evidence. Reviewers may approve a case they do not fully endorse or remove access before the right follow-up is complete, so the workflow no longer reflects the decision that was actually made.
Why approve-or-remove recertification breaks governance
Recertification is supposed to capture a real decision about access, not force reviewers into a binary that hides the true outcome. When the workflow only permits approve or remove, it can turn partial confidence, pending investigation, time-boxed exceptions, or delegated follow-up into the wrong recorded action. That weakens the governance value of the review and makes the evidence less trustworthy.
The core problem is that the workflow no longer matches the reviewer’s intent. A reviewer may believe access should remain in place until compensating checks are complete, yet the system records approval; or they may want to signal concern without immediate removal, yet the system records revocation. In either case, the recertification record becomes a simplified surrogate for a more nuanced judgment.
This matters because access certification is not just an administrative step, it is part of the control history used to show that entitlements were reviewed, challenged, and resolved appropriately. When the control only exposes two outcomes, the resulting evidence can overstate certainty, understate residual risk, or create ambiguity about who accepted what and when.
How the binary choice distorts audit trails and control evidence
Auditability suffers when the workflow cannot preserve the reasoned path from review to final disposition. If a reviewer is forced to approve an access path they would have conditionally accepted, the log suggests an endorsement that never existed. If they remove access before a follow-up step is completed, the audit trail may show a stronger action than the business or control owner actually intended.
That distortion is especially harmful in recurring certification cycles, where teams rely on prior review outcomes to demonstrate consistency, exception handling, and control effectiveness. A binary workflow can make reports look clean while masking the operational reality of deferred decisions, compensating controls, or unresolved ownership questions. The control may appear complete even when the underlying governance decision was not.
For review programs that span many systems or identities, this also creates comparability problems. One team may be using “approve” to mean full endorsement, another may be using it as a temporary placeholder, and a third may be using removal as a stand-in for “reassess later.” The evidence set then becomes internally inconsistent even if each reviewer acted in good faith.
What a better recertification workflow needs to preserve
A useful recertification workflow should separate decision capture from disposition, so the process can express the real governance state without losing enforceability. At minimum, it should preserve whether the reviewer approved, removed, deferred, conditionally accepted, or escalated a case, and it should retain the rationale and any required follow-up. That gives the control a faithful record rather than a compressed approximation.
It also needs a clean handoff between review and remediation. If follow-up work is required, the workflow should show who owns it, what condition must be satisfied, and whether access remains in force under an explicit exception or temporary approval. If removal is chosen, the system should still preserve the reviewer’s reasoning so the control history reflects why access was considered inappropriate, not just that it disappeared.
For programs that use identity governance tooling, the practical design goal is to keep the certification step expressive enough that audit evidence and operational execution stay aligned. The Access Reviews and Certification Guide is a useful reference point for designing review flows that close the loop instead of reducing every case to a rubber-stamp or revoke-only decision.
Risk and Threat Considerations
When recertification collapses into approve-or-remove, the main risk is governance drift: the control starts recording simpler outcomes than the reviewer actually intended. That can mislead auditors, obscure exception handling, and let weak access decisions persist because the workflow no longer captures the intermediate states that real review programs depend on.
Failure mechanism: reviewers use the nearest available button to represent a conditional or incomplete decision, so the system records a disposition that is stronger or weaker than the actual governance judgment. Over time, that creates inaccurate certification evidence and can hide unresolved access risk.
Impact: audit trails become less reliable, exception governance becomes harder to prove, and access decisions may be either over-retained or removed before compensating checks are complete. In a large review program, that can degrade control confidence across many accounts and make remediation less defensible.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Recertification is part of account governance and review of access status. |
| AC-6 — Least Privilege | Remove-or-approve decisions directly affect whether access stays excessive or justified. | |
| AU-2 — Event Logging | The workflow must preserve the actual review decision and follow-up state for audit evidence. | |
| Recommendation — Use AC-2 to ensure account review outcomes are recorded and acted on accurately. Use AC-6 to reduce standing access that is no longer justified by review. Use AU-2 to log review decisions with enough context to reconstruct the governance outcome. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights review and adjustment depend on preserving the real review decision, not a binary proxy. |
| A.5.28 — Collection of evidence | Certification records are evidence that must reflect the actual governance decision and follow-up. | |
| Recommendation — Use A.5.18 to review and adjust access rights based on documented certification outcomes. Use A.5.28 to retain evidence that shows the true review state and remediation path. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Access reviews are a core access-control operation and need accurate decision handling. |
| Recommendation — Use CIS-6 to ensure review outcomes drive access changes without losing decision fidelity. | ||
Practitioner Guidance
What to verify: Check whether your recertification tool can record conditional approval, deferral, escalation, and documented exception states, not just approve or remove. If it cannot, treat the workflow as an evidence-risk issue, not just a usability issue.
Decision rule: If a reviewer may need to separate “I accept this for now” from “I fully endorse this entitlement,” the workflow needs more than two outcomes. Otherwise, the control will force people to encode nuance in comments while the system records the wrong state.
What good looks like: The review record should show the decision, the reason, any temporary condition, and the follow-up owner. The operational action should then match that recorded intent without requiring manual reinterpretation later.
Practitioner takeaway: A recertification control is only as strong as the decision vocabulary it gives reviewers; if the workflow cannot express nuance, it will produce neat-looking evidence that is less truthful than the real governance decision.