They stall because the programme keeps reassembling ownership context instead of governing from a stable record. Each cycle forces teams to rediscover who should review what, which creates manual chasing, late responses, and fatigue. The weaker the ownership data, the slower the governance loop becomes.
Why periodic attestation campaigns slow down
Periodic NHI attestation is often treated as a recurring cleanup exercise rather than a governed record. That matters because every cycle asks reviewers to reconstruct ownership, purpose, and business context from scratch. When the underlying inventory is weak, review queues fill with questions instead of decisions, and the campaign begins to behave like manual case management.
The stall usually comes from missing or stale context: no clear owner, no dependable asset classification, no stable reviewer mapping, and no agreed rule for what constitutes acceptable access. In that state, attestation does not validate the record, it becomes the process that tries to repair it.
At scale, the failure mode is predictable. Each additional identity increases the amount of chasing, exception handling, and approval ambiguity, so governance latency grows faster than the portfolio itself. A campaign can look active while actually accumulating unread or unresolved attestations.
What weak ownership data does to the review loop
Ownership data is the hinge that turns attestation from labour into governance. If the owner, backup owner, or reviewer is unclear, the workflow has to infer responsibility from naming conventions, ticket history, or tribal knowledge. That creates delays, and it also creates inconsistent decisions because different teams fill the gap in different ways.
When ownership is stable, the campaign can route decisions automatically and reviewers can focus on change since the last review. When ownership is unstable, teams spend time finding the right approver, validating whether the identity is still in use, and deciding whether the control belongs to IT, application owners, or a platform team. The process slows because the question is not just “is this acceptable?” but “who is qualified to answer that?”
This is why attestation often degrades into repeated human follow-up. The programme is not just checking access, it is reestablishing accountability before it can even check access.
How to recognise when the campaign is failing as a governance mechanism
Stall is usually visible in the operational signals. Reviews linger in open status, exception queues grow, the same identities reappear every cycle, and managers receive requests for context they expected the system to already know. The pattern shows that the control is being run as a periodic event rather than a living governance state.
The most common trigger is ownership churn. If teams cannot tell whether a service account belongs to a product, a platform, or a vendor integration, the attestation task expands into investigation. That is also where fatigue appears: reviewers learn that each cycle will ask them to rediscover the same facts, so they defer, delegate, or approve with limited confidence.
At that point the issue is not simply speed. It is governance quality. A delayed campaign is often a symptom that the organisation does not yet have a stable identity record worthy of attestation.
Risk and Threat Considerations
Stalled attestation campaigns increase exposure because unresolved ownership and access questions leave privileged or long-lived NHI records in circulation longer than intended. The risk is not just administrative delay, it is that unmanaged or ambiguously owned identities are harder to challenge, harder to revoke, and easier to overlook during changes or incidents.
Failure mechanism: Weak ownership data forces every review cycle to rediscover accountability, which delays decisions and allows stale access, orphaned identities, and unnecessary privileges to persist.
Impact: The longer the campaign stalls, the larger the window for abuse, accidental overexposure, and missed offboarding, especially where many identities depend on the same broken review path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Stalled attestation leaves ownership and removal decisions unresolved. |
| NHI-05 — Overprivileged NHI | Delayed reviews let excess access persist while ownership is being reestablished. | |
| NHI-10 — Human Use of NHI | Campaigns stall when humans must reconstruct and approve machine access manually. | |
| Recommendation — Tie attestation outcomes to timely offboarding and revoke stale NHI access. Review and reduce excess NHI privilege during each attestation cycle. Separate human approval paths from machine identity governance where possible. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Attestation depends on governed credential and secret lifecycles for NHIs. |
| AC-2 — Account Management | Recurring reviews depend on stable account ownership and disposition decisions. | |
| AC-6 — Least Privilege | Slow campaigns often leave unnecessary access in place longer than intended. | |
| Recommendation — Track, rotate, and retire authenticators on a defined lifecycle. Maintain authoritative account records with clear owners and review cadence. Limit each NHI to the minimum access needed for its function. | ||
| NIST CSF 2.0 | ID.AM-01 — Physical devices and systems are inventoried | A reliable inventory foundation is needed before recurring identity attestation can scale. |
| PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and audited | Attestation is the governance loop that validates issuance, review, and revocation states. | |
| Recommendation — Maintain an up-to-date inventory of identities and supporting systems. Connect attestation to identity lifecycle events and revocation decisions. | ||
| ISO/IEC 27001:2022 | A.5.9 — Inventory of information and other associated assets | Attestation stalls when teams lack a dependable inventory of identities and assets. |
| A.5.15 — Access control | Periodic review is an access-control activity that loses speed without clear ownership. | |
| Recommendation — Keep an authoritative inventory to support repeatable review cycles. Define and enforce access review rules with explicit accountability. | ||
Practitioner Guidance
What to prioritise: Stabilise the ownership record before trying to accelerate the campaign. If a reviewer cannot be assigned without manual interpretation, the process is already operating below an acceptable control threshold.
What to verify: Confirm that each NHI has a current business owner, a technical owner, and a deterministic reviewer mapping that survives staff changes. If any of those fields are inferred case by case, expect the next campaign to stall again.
Common mistake: Treating attestation output as the fix. The control only scales when the record is durable enough that reviewers are validating state, not reconstructing it.
Practitioner takeaway: The fastest attestation programme is not the one with the most reminders, it is the one with the least need to rediscover who owns what.