Join our Newsletter — 33% off our NHI Course

What breaks when ISO 27001 maintenance does not cover non-human identities?

The certification model can still pass while service accounts, secrets, and certificates remain unmanaged. That creates a gap between documented compliance and actual access control, because machine identities may outlive their owners, retain standing privilege, or escape review entirely. In practice, the ISMS looks complete while the highest-risk access paths remain least governed.

What breaks in the ISO 27001 maintenance model when non-human identities are left out?

ISO 27001 maintenance can still look successful on paper while service accounts, secrets, certificates, and other machine identities remain outside the operating rhythm. The break is not certification itself, but the link between the ISMS and real access governance. When those identities are not in scope, controls can be documented, tested, and passed without governing the access paths that actually carry production risk.

Why the ISMS stays compliant while access control becomes incomplete

ISO 27001 is built around a management system, so maintenance activities often centre on policy reviews, evidence collection, and control operation. If non-human identities are omitted, the system can satisfy the process requirement while missing the assets that authenticate workloads, applications, integrations, and automation. That creates a narrow form of compliance that does not reflect who or what can still reach critical systems.

This is where the gap becomes practical: a service account may keep working long after the team that created it has changed, a secret may never be reviewed as an accountable asset, and a certificate may expire or persist without clear ownership. The result is not just weaker hygiene, but a control model that assumes identity governance is complete when a major class of identities was never included.

For maintenance to be meaningful, the scope has to cover the full population of identities that can exercise access. A useful benchmark is the broader identity governance view described in the Identity Security Regulatory Map, because it shows how identity controls map into governance and compliance obligations rather than living only in one certificate cycle.

Where non-human identities create hidden failure modes

Non-human identities usually fail differently from people. They are often provisioned for a project, embedded in pipelines or applications, then left standing with no formal offboarding trigger. They may also carry broader permissions than a human administrator would accept, because they were created for convenience and never re-tuned after deployment.

That means the maintenance failure is often a lifecycle failure: no owner, no expiry discipline, no review cadence, and no inventory that proves the credential still has a business purpose. The Service Account Security Guide is useful here because it treats service accounts as governed access subjects, not just technical artifacts.

Certificates and tokens add another layer of fragility. If certificate renewal, secret rotation, and dependency review are not maintained together, teams can end up with long-lived access that survives personnel changes and system changes. In practice, the organisation loses visibility into whether access is still justified, even though the documentation still claims the control is operating.

The maintenance blind spot is especially damaging for ownership. The NHI Ownership and Accountability Guide is relevant because orphaned identities are a common reason access survives beyond its intended use and never reaches review or retirement.

Why this matters to audit evidence, not just operational hygiene

When non-human identities are excluded, audit evidence can become misleading. The ISMS may show that reviews happened, exceptions were recorded, and controls were assessed, but none of that proves the highest-risk machine access paths were inventoried or revalidated. In other words, the organisation can demonstrate process completion while still lacking evidence that the control covered the real exposure.

That matters because ISO 27001 maintenance is supposed to keep the management system aligned with changing risk. If the environment now depends heavily on automation, cloud services, and machine-to-machine access, then leaving those identities out means the scope is no longer aligned with the operating reality. A broader reference such as Ultimate Guide to NHIs is useful because it frames the issue as governance over a live identity population, not just a list of technical secrets.

Practitioners should treat that misalignment as a sign that the ISMS may be complete in form but incomplete in substance. The strongest signal is when a team can produce certification evidence for access control and lifecycle management, yet still cannot answer which non-human identities exist, who owns them, or when they were last reviewed.

Risk and Threat Considerations

Leaving non-human identities out of ISO 27001 maintenance creates a direct exposure gap, because the most persistent credentials are often the least observed. That can leave standing privilege in place long after the original business need has disappeared, which increases the chance of misuse, compromise, or unnoticed lateral movement.

Failure mechanism: Identity maintenance is performed only for human or documented admin access, so service accounts, keys, certificates, and tokens drift out of inventory, outlive ownership, and escape recertification.

Impact: The organisation gets a compliance-positive control story while real access remains overprivileged, stale, and harder to detect or revoke during incident response.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.5.15 — Access control Maintenance gaps here directly affect whether machine identities are governed in scope.
A.8.5 — Secure authentication Service accounts and certificates are authentication mechanisms that require ongoing maintenance.
A.5.18 — Access rights Unreviewed service accounts create standing access that this control is meant to govern.
Recommendation — Include non-human identities in access review and control operation evidence. Review and maintain machine authentication credentials on the same cadence as human access. Recertify non-human access rights and remove unused or orphaned entitlements.
NIST SP 800-53 Rev 5 IA-5 — Authenticator Management Secrets and certificates are authenticators whose lifecycle must be controlled.
IA-9 — Service Identification and Authentication Non-human identities authenticate services and workloads, so the control is directly implicated.
Recommendation — Track, rotate, and retire non-human authenticators under formal lifecycle control. Apply service authentication controls to workload and integration identities.

Practitioner Guidance

What to verify: Test whether your ISO 27001 maintenance scope explicitly includes service accounts, API keys, certificates, workload identities, and other non-human credentials. If the answer depends on a team’s memory rather than an inventory, the control is already too weak to trust.

Decision rule: If an identity can authenticate to production or influence production data, treat it as a governed identity subject for maintenance, review, ownership, and retirement decisions, even when it is not human-operated.

Common mistake: Teams often rely on policy language that says “access” is reviewed, but the actual review list only contains employee accounts. That leaves the highest-risk paths outside the evidence set while the audit trail still appears complete.

Practitioner takeaway: ISO 27001 maintenance only works when the identity population matches the real environment; if non-human identities are excluded, the certificate may be valid while the access model is not.