Join our Newsletter — 33% off our NHI Course

What breaks when identity governance still depends on periodic certification?

Periodic certification breaks when identities change faster than the review cycle can capture. Access drift, standing privilege and delegated permissions can remain in place long after the business context has changed. In mixed human, non-human and AI estates, that means governance can look complete on paper while actual exposure keeps growing between review windows.

When certification lags behind changing access

Periodic certification assumes access remains stable long enough for a scheduled review to catch drift. That breaks down when roles, projects, vendors, automations and delegated permissions change continuously. The control becomes retrospective rather than preventive, so it can validate yesterday’s access while today’s effective privileges keep expanding.

In practice, the failure is not that certification is worthless, but that it is too coarse for fast-moving entitlement states. If the review window is longer than the access change window, certification will miss the point at which access stopped being justified and started becoming exposure.

Mixed estates make that gap larger. Human users can accumulate stale access after transfers, but systems, service accounts and AI-driven workflows can also keep credentials or delegated authority long after the original business need has shifted. IAM and IGA Basics is useful here because the problem is really about lifecycle control, not just review mechanics.

Why the control starts to give false assurance

Periodic certification often measures completeness, not effectiveness. A campaign can close on time, all reviewers can click approve, and the organisation can still retain standing privilege, role creep and unrevoked delegated access. That is why periodic review can produce a clean governance record while leaving the actual access graph materially unchanged.

The deeper issue is that certification is usually designed as an evidence process, but the risk lives in the intervals between campaigns. If the entitlement model is broad, the reviewer workload is high, or the business context is changing quickly, people tend to rubber-stamp what looks familiar. Access Reviews and Certification Guide addresses this exact failure mode by focusing review effort on decisions that actually remove access.

This is also where access governance and role design intersect. If roles are too coarse, the certifier is forced to approve bundles of access instead of specific entitlements, which makes drift harder to see and harder to remove. Role Mining and Role Design Guide is relevant because better role structure reduces the amount of false choice in the review process.

What has to replace pure periodic review

Periodic certification should be treated as one control in a broader lifecycle model, not as the lifecycle model itself. The control set needs discovery, ownership, revocation paths, exception handling and review triggers that can fire when risk changes, not only when the calendar says so. In that sense, certification should confirm a current state, while other controls should keep the state bounded between campaigns.

That is especially important for non-human identities and delegated access, because their access often exists to support automation rather than a person’s job role. When the workflow changes, the access may still persist unless someone explicitly closes the loop. Joiner-Mover-Leaver (JML) Guide helps because lifecycle events are where stale access should be removed, not merely noted for the next review.

Where access has direct business or fraud implications, separation controls also matter. A periodic check may say a permission is assigned, but it will not necessarily reveal whether that permission creates a toxic combination with another standing privilege. Segregation of Duties (SoD) Guide is a better fit when the question is whether the access state itself is inherently unsafe, not just whether it was approved in the last cycle.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Periodic certification is part of managing account lifecycle and access review states.
AC-6 — Least Privilege The question centers on access drift and standing privilege that certification can leave behind.
IA-5 — Authenticator Management Long-lived credentials and delegated access depend on credential lifecycle, not just periodic review.
Recommendation — Tie certification to account lifecycle events and remove access when ownership or need changes. Continuously reduce standing access so reviews validate least privilege instead of preserving excess rights. Rotate and retire authenticators on lifecycle triggers rather than waiting for scheduled certification.
NIST CSF 2.0 PR.AA-05 — Identity Management, Authentication, and Access Control The issue is whether access governance keeps pace with entitlement changes across identities.
GV.OC-03 — Mission and Stakeholder Expectations Are Understood Certification fails when governance expectations lag behind how access is actually used.
ID.AM-01 — Physical Devices and Systems Are Inventoried Discovery and inventory underpin visibility into what should be certified and revoked.
Recommendation — Use access-control processes that continuously reflect current entitlement state. Align access governance frequency to the business pace of change and ownership. Maintain an accurate inventory of identities and entitlements before running certification.

Practitioner Guidance

What to prioritise: Focus first on identities whose access changes faster than your certification cadence, especially admins, contractors, shared roles, service identities and any delegated access path that can outlive the original approval.

What to verify: Confirm that every certification campaign is paired with a concrete revocation workflow, a current owner for each entitlement set and an exception path for access that cannot wait for the next cycle.

Common mistake: Treating completion rates as evidence of control effectiveness. High review completion can coexist with high residual exposure if reviewers are approving bundles, stale roles or unmanaged machine access.

What good looks like: Review prompts are driven by actual change signals, access decisions are granular enough to remove specific entitlements, and stale privilege is reduced continuously rather than rediscovered on the next campaign.

Practitioner takeaway: Certification should validate governed access, not compensate for weak lifecycle management. If access can materially change between reviews, the real control problem is not the certification form, it is the speed and precision of revocation.