NHIs change too quickly and exist in too many places for periodic review to keep pace. When service accounts, tokens, and automation identities are reviewed only after the fact, evidence is already stale and over-privilege persists unnoticed.
Why periodic reviews break down at NHI scale
Quarterly access reviews assume identities are relatively stable, evidence is still current, and reviewers can meaningfully assess each entitlement in a bounded window. That model breaks when service accounts, API keys, workload identities, and automation accounts are created, changed, rotated, or repurposed continuously across cloud, SaaS, CI/CD, and infrastructure.
At NHI scale, the review problem is not only volume. It is the mismatch between review cadence and identity churn. By the time a quarterly certification lands, the access path may already have changed, the business owner may no longer recognise the account, and the reviewer is forced to certify stale state rather than current risk.
That is why access review quality degrades fastest when inventories are incomplete, ownership is unclear, and entitlements are hidden inside tooling or platform defaults. The practical result is rubber-stamping, not control.
What makes NHI access so hard to certify after the fact
NHI access is usually operational, distributed, and dependency-driven. One automation workflow may rely on several secrets, several service accounts, and several downstream systems, each with different owners and renewal cycles. A quarterly review rarely reconstructs that full chain well enough to judge whether the access is still necessary.
Lifecycle gaps also matter. If a service account is never clearly owned, rotated, or retired, the review becomes an administrative check rather than a governance decision. The NHI Lifecycle Management Guide and NHI Ownership and Accountability Guide both support the same operational point: certification is only useful when the organisation can trace each identity to a current purpose and a current owner.
This is also where broad identity governance and NHI-specific guidance converge. The Access Reviews and Certification Guide and IAM and IGA Basics reinforce that recertification only works when review scope, entitlement context, and remediation are designed together. Without that, the review answers a paperwork question, not a security question.
For machine access specifically, the problem is compounded by credentials that are long lived, embedded in pipelines, or reused across environments. The Service Account Security Guide and Lifecycle Processes for Managing NHIs show why periodic review misses the operational reality: these identities often change through automation, not through a ticket that waits for a quarter-end meeting.
How to replace quarterly review with controls that keep pace
Quarterly certification should be treated as a backstop, not the primary control. The better pattern is continuous inventory, ownership at creation, scoped rotation, and event-driven review for high-risk changes such as privilege increases, new environment access, failed rotation, or orphaned identity detection.
A useful anchor is whether the account still has a live, business-justified dependency. If the answer depends on tribal knowledge or a manual spreadsheet, the control has already lost pace. The Key Challenges and Risks section and the Top 10 NHI Issues page both point to the same operating model: reduce sprawl, expose ownership, and make excess access easier to detect before review season arrives.
Practitioners should also distinguish between reviewable access and mechanically necessary access. A quarterly reviewer can certify a business purpose, but they cannot reliably validate whether a token is still embedded in code, whether a workload has switched dependencies, or whether a certificate or secret is still being consumed somewhere in production. Those are discovery and lifecycle problems first, review problems second.
In practice, the control objective shifts from “recertify everything every quarter” to “continuously know what exists, who owns it, what it can do, and when its access should expire or be revalidated.”
Risk and Threat Considerations
When NHI access reviews are too slow, excess privilege persists long enough to be abused, and stale approvals become an attractive path for lateral movement or covert persistence. The risk is not only missed cleanup, but also the false confidence that a review stamp means the access was current at the time of certification.
Failure mechanism: Identity churn outpaces periodic certification, so reviewers validate outdated inventories, miss hidden dependencies, and leave unnecessary machine access in place until the next cycle.
Impact: Orphaned, overprivileged, or undocumented NHIs can continue to authenticate and act inside production long after the business need has ended, widening blast radius and delaying detection of misuse.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Quarterly reviews miss retired or repurposed NHIs that should have been removed. |
| NHI-05 — Overprivileged NHI | Stale quarterly approvals leave excessive machine access in place between review cycles. | |
| NHI-07 — Long-Lived Secrets | Long-lived secrets and tokens outlast quarterly review evidence and keep access active. | |
| Recommendation — Tie certification to offboarding events and revoke orphaned NHIs immediately. Continuously trim NHI entitlements to least privilege and revalidate high-risk access changes. Shorten secret lifetimes and trigger review when credential age or scope changes. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Stale reviews need supporting monitoring and timely analysis to surface access changes sooner. |
| IA-5 — Authenticator Management | NHI access often depends on secrets and tokens whose lifecycle determines review accuracy. | |
| AC-2 — Account Management | Quarterly certification is weak without account lifecycle controls for creation, review, and disablement. | |
| Recommendation — Review access events continuously and investigate anomalous NHI use before certification. Manage authenticator issuance, rotation, and revocation as part of the access review process. Maintain current account inventories and disable unused NHIs as soon as they lose purpose. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Periodic certification is an access-control practice that must stay aligned to current need and scope. |
| A.5.16 — Identity management | Identity management must cover NHIs whose existence and ownership change faster than quarterly reviews. | |
| Recommendation — Apply access-control rules that require timely review of machine access and entitlements. Keep identities inventoried, owned, and traceable throughout their lifecycle. | ||
| CIS Controls v8 | CIS-5 — Account Management | Quarterly reviews depend on active account governance, especially for service and automation accounts. |
| CIS-6 — Access Control Management | Access control management must limit standing machine privilege between review cycles. | |
| Recommendation — Inventory, review, and disable inactive accounts continuously rather than waiting for quarter-end. Enforce least privilege and remove unnecessary NHI access as soon as it is detected. | ||
Practitioner Guidance
What to prioritise: Start with the identities that can still reach production, especially service accounts, automation credentials, and tokens with broad or cross-environment reach. Those are the places where stale certification creates the most real exposure.
What to verify: Before trusting any quarterly result, verify that each reviewed NHI has an owner, a current purpose, a current scope, and a remediation path if the reviewer rejects it. If you cannot produce those four items, the review outcome is not operationally reliable.
What good looks like: A mature process uses quarterly review as confirmation, while continuous discovery, expiration, rotation, and event-triggered revalidation do the real control work. The best signal is not a passed certification, but a shrinking set of unknown, unowned, or long-lived identities.
Practitioner takeaway: At NHI scale, access review fails when it is used as a periodic audit of a moving target; the control must shift toward live inventory, ownership, and lifecycle enforcement if it is meant to reduce privilege rather than record it.