Lifecycle governance first. Certification is only trustworthy when the identity inventory, ownership, and decommissioning paths are already accurate, because you cannot certify what you cannot reliably enumerate or retire.
Why lifecycle governance has to come before certification
lifecycle governance is the control layer that makes an NHI population knowable. It covers how identities are created, owned, changed, rotated, suspended, and retired, so the organisation can tell which assets are real, current, and eligible for review. Without that foundation, certification turns into a paperwork exercise over an inventory that may already be stale.
The practical distinction is that lifecycle governance reduces ambiguity, while certification tests what already exists. If provisioning is inconsistent, ownership is missing, or decommissioning is incomplete, access review outcomes will be noisy at best and misleading at worst. That is why NHIMG’s NHI Lifecycle Management Guide is the better first control to stabilise the population before you ask reviewers to attest to it.
A mature lifecycle process also creates the evidence base that certification depends on: authoritative inventory, named owners, last-seen state, and retirement status. Those are the conditions that make review decisions actionable rather than theoretical. For that reason, the lifecycle question is not just about efficiency, it is about whether the organisation can trust the review result at all.
What access certification can do well, and where it fails first
access certification is strongest when it validates an already-clean population and forces an explicit keep, remove, or exception decision. It is useful for detecting privilege creep, dormant access, and accounts that have outlived their business purpose. But certification does not repair weak upstream governance, because a reviewer cannot reliably judge what should be removed if the identity record itself is incomplete.
That is especially true for NHIs, where access often exists through service credentials, tokens, keys, or federated trust paths that are easy to lose track of. When review campaigns operate on poor data, they can unintentionally rubber-stamp access, miss orphaned identities, or treat partial information as authoritative. Access Reviews and Certification Guide is most effective as the validation step after inventory and ownership are already dependable.
Certification therefore works best as a decision control, not as a discovery control. It can confirm whether an existing entitlement should remain, but it should not be the mechanism used to find hidden identities, infer ownership, or determine whether a retirement path exists. Those are lifecycle governance problems first.
How to sequence the two controls in practice
The right sequence is simple: establish the lifecycle baseline, then run certification against that baseline, then feed exceptions back into the lifecycle process. Start by making sure every NHI has an owner, a source of truth, a renewal or rotation path, and a defined retirement path. Only then can periodic review produce decisions that are durable rather than temporary.
- Use lifecycle governance to answer: what exists, who owns it, where it lives, and when it should expire.
- Use certification to answer: should this access still exist, and who is accountable for keeping it?
- Use exceptions to fix the inventory, ownership, or retirement process, not just the individual review item.
This is why organisations often get better results by treating certification as a downstream quality check on lifecycle governance, not a substitute for it. The control order matters because certification depends on trustworthy enumeration, and enumeration depends on lifecycle discipline. NHIMG’s IAM and IGA Basics is a useful companion reference for understanding how provisioning, access review, and entitlement governance fit together.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | NHI lifecycle depends on managing credentials, tokens, and rotation. |
| AC-2 — Account Management | Lifecycle governance and certification both rely on accurate account inventory and disposition. | |
| AC-6 — Least Privilege | Certification is used to remove excess access once lifecycle inventory is trustworthy. | |
| Recommendation — Manage NHI authenticators with rotation, expiry, and revocation tied to lifecycle state. Maintain authoritative NHI account records with ownership, status, and timely disablement. Revoke unnecessary NHI privileges after review confirms business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | The question is about governing accounts and reviewing access for NHIs. |
| CIS-6 — Access Control Management | Access certification is an access-control discipline that depends on current identity state. | |
| Recommendation — Inventory NHI accounts, owners, and lifecycle status before certifying access. Use periodic review to remove obsolete NHI access after lifecycle cleanup. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity Management | NHI inventory and ownership are identity management prerequisites for trustworthy certification. |
| A.5.18 — Access Rights | Certification validates whether access rights should remain after lifecycle governance is stable. | |
| Recommendation — Define and maintain authoritative NHI identity records before access attestation. Review and remove unnecessary NHI access rights on a recurring basis. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | The topic directly concerns lifecycle governance, ownership, and access certification for NHIs. |
| Recommendation — Govern NHI lifecycle data first, then certify access against the controlled inventory. | ||
Practitioner Guidance
What to prioritise: Fix inventory completeness and owner assignment before opening the first certification campaign. If you cannot show a current owner and a retirement status for each NHI, the review output will not be operationally trustworthy.
What to verify: Check whether the certification population is drawn from an authoritative lifecycle register, not from a one-off export or manually curated spreadsheet. If identities can be created or left behind outside the normal process, review results should be treated as provisional.
Decision rule: If the control gap is “we do not know what exists,” start with lifecycle governance. If the gap is “we know what exists but need to confirm continued need,” certification becomes the right next step.
Practitioner takeaway: Certification is only as good as the lifecycle data behind it, so the first hard question is not who approved access, but whether the organisation can accurately enumerate, own, and retire the NHI in the first place.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise transaction governance or access certification first?
- Should organisations prioritise compliance certification or access evidence first?
- Should organisations prioritise access review or lifecycle automation first?