Join our Newsletter — 33% off our NHI Course

When do recurring access certifications become more important than one-time approvals?

Recurring certifications matter once access risk can outlive the original business need. That is common in organisations with changing roles, outsourced service delivery, or regulated evidence requirements. The point is to catch privilege drift before it becomes a compliance gap or an audit exception.

When recurring certification beats a one-time approval

One-time approval is enough when access is tightly scoped, short-lived, and tied to a stable business task. Recurring certification becomes the better control once the access decision ages faster than the work it was approved for, especially where roles change, entitlements accumulate, or auditors need proof that access still exists for a current reason.

A recurring review is not just a second look, it is a control reset. It forces the business owner to re-affirm that the access is still justified, which matters when approvals are made by someone who no longer sees the day-to-day use of the account.

In practice, that shift usually happens when access has any of these traits: it is persistent rather than ephemeral, it spans multiple systems or environments, it is held by contractors or service providers, or it can be reused after the original project is finished. At that point, the original approval says less about today’s risk than a current certification does.

What recurring certification is really controlling

Recurring certification is designed to catch privilege drift. The access may have started as legitimate, but over time the entitlement set can expand, the user role can change, or a temporary exception can become the default. That is why access reviews and certification are most valuable when they are tied to real ownership, not just a calendar reminder.

It is also stronger than a one-time approval when the organisation depends on governance evidence. A single approval can show that access was granted correctly, but it does not show that the access remained appropriate through movers, leavers, outsourcing changes, or role redesign. If the question is whether the permission still belongs in the estate, recurring certification is the right control.

This is why access governance and lifecycle management tend to converge. The control is not just about asking “who approved this?”, but “does this still match the current business need, and can we prove it?” That is the point where IAM and IGA basics and lifecycle management become operationally important rather than theoretical.

When one-time approval is still the better control

One-time approval is usually enough for narrowly scoped, low-risk access where the entitlement is self-expiring, the usage window is short, and the access path is easy to observe or revoke. That is common for temporary projects, break-glass scenarios, or tightly bounded access that is automatically removed after use.

The mistake is to use recurring certification for everything. If the access changes frequently but the review process is slow, you create review fatigue and turn the exercise into rubber stamping. In those cases, it is better to reduce standing access first, then certify the smaller set of meaningful exceptions. A recurring review works best when there is something stable and material left to review.

For broader access governance, recurring certification should pair with role design and SoD rather than substitute for them. A recurring review can detect that a role is wrong, but it cannot on its own prevent badly designed roles, conflicting duties, or inherited privilege from becoming normalised. See role mining and role design and segregation of duties for the structures that make certification more accurate.

Risk and Threat Considerations

Recurring certification matters because stale access becomes an attack path as well as a governance gap. When approvals are never revisited, orphaned access, overprivileged accounts, and reused entitlements can persist long after the original business need has disappeared.

Failure mechanism: The original approval is treated as durable evidence, so changed roles, expired vendor relationships, and accumulated permissions are never revalidated. That leaves a control gap where attackers or insiders can exploit stale rights that no longer have an active business owner.

Impact: Privilege drift increases the chance of unauthorized access, audit exceptions, and wider blast radius after compromise. At scale, recurring certification is one of the few controls that can continuously surface access that is technically working but no longer defensible.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Recertification and removal of stale access are core account-management concerns.
AC-6 — Least Privilege Recurring certification helps detect privilege creep and enforce least privilege over time.
IA-5 — Authenticator Management Long-lived approvals often leave credentials and authenticators in place beyond need.
Recommendation — Review accounts periodically and remove or adjust access that no longer matches business need. Revalidate entitlements periodically and strip permissions that exceed current job need. Rotate or revoke authenticators and related secrets when access is no longer justified.
ISO/IEC 27001:2022 A.5.15 — Access control Recurring certification supports controlled access decisions and periodic review of permissions.
A.5.18 — Access rights This control directly covers granting, reviewing and removing access rights over time.
Recommendation — Define periodic access review requirements and remove access that no longer has a valid basis. Review access rights regularly and revoke those that are no longer required.

Practitioner Guidance

What to prioritise: Certify access that has the highest likelihood of drifting, not the largest volume. Start with privileged accounts, contractor access, shared access, and any entitlement that survives role changes or outsourcing transitions.

What to verify: Each review cycle should confirm an accountable owner, a current business justification, and a removal path for any entitlement that no longer matches the job. If those three things are missing, the review is probably ceremonial.

Practitioner takeaway: Use one-time approval for short-lived, well-bounded access, but move to recurring certification when access can outlast the decision that created it.