Join our Newsletter — 33% off our NHI Course

What do IAM teams get wrong about certification campaign design?

They often treat certification as a policy exercise and overlook the operational design of the review path. If the workflow creates reviewer confusion, language barriers, or hidden queues, the programme may still exist but fail to deliver timely, defensible outcomes.

Certification campaigns are operational workflows, not just policy artefacts

Certification only works when the review experience is designed to produce a decision. That means the campaign has to make it easy to understand what is being reviewed, why the reviewer owns it, and what action should follow. When those basics are unclear, reviewers default to speed, assumptions, or non-action, and the campaign becomes a reporting exercise rather than a control.

One common miss is treating the campaign as a one-size-fits-all data dump. A good design separates routine access from sensitive access, groups items in ways that match how reviewers think, and makes the ownership model obvious. Campaigns that force reviewers to interpret every entitlement from scratch create avoidable friction and lower the quality of the decision.

Another design failure is weak operational routing. The review path has to account for approver availability, inherited access, delegate handling, and escalation when a queue stalls. If the workflow cannot move decisions to the right person at the right time, the certification exists on paper but does not generate timely revocation, exception handling, or defensible sign-off.

What review-path design needs to optimise for

The real design question is not whether a certification campaign exists, but whether it is reviewable at scale. That means reducing cognitive load, minimising ambiguity, and giving the reviewer enough context to make a grounded decision without forcing extra investigation. If the campaign design does not reflect how access is actually granted and used, reviewers will miss risk signals or rubber-stamp the list.

Operational design also has to respect the shape of the audience. A reviewer who sees terminology they do not recognise, a system owner who receives entitlements outside their domain, or a manager asked to judge technical access without context is more likely to delay or approve broadly. Review design should therefore align to clear ownership boundaries, stable naming, and consistent presentation of access scope.

Good campaigns also make outcomes actionable. If a reviewer marks access for removal, the workflow should clearly capture the decision, route it to enforcement, and preserve evidence. If a reviewer flags uncertainty, the campaign should provide a defined escalation path rather than burying the item in a hidden queue. That is how certification becomes control execution, not just attestation.

Why campaign failures show up as backlog, noise, and weak evidence

Many bad campaigns fail quietly. They do not look broken from a policy standpoint, but they accumulate hidden work in the form of unread items, unowned exceptions, and reviewers who cannot finish because the interface or queue logic is poor. Over time, this produces stale decisions, inconsistent handling, and evidence that is difficult to defend in audit or incident review.

Review-path design problems also distort metrics. A campaign can show high completion while still leaving material access untouched if reviewers are unsure, overloaded, or pushed toward blanket approvals. That creates a false sense of control because the programme reports activity without proving that access changed in a timely and traceable way.

For teams building broader identity governance, the lesson is that campaign success depends as much on workflow engineering as on policy content. The Access Reviews and Certification Guide is useful here because it frames certification as a design problem, not a paperwork problem, and the IAM and IGA Basics guide reinforces why review, entitlement, and governance design have to work together.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-2 — Account Management Certification campaigns directly govern access review and revocation decisions.
AC-6 — Least Privilege Campaign design should surface excess access so reviewers can right-size privilege.
AU-6 — Audit Review, Analysis, and Reporting Defensible certifications depend on review evidence, exceptions, and traceable decisions.
Recommendation — Use AC-2 to review accounts regularly and remove access that is no longer justified. Apply AC-6 to identify and reduce permissions beyond the minimum needed. Use AU-6 to retain review evidence and verify decisions are recorded and actionable.
ISO/IEC 27001:2022 A.5.18 — Access rights Certification campaigns are a core mechanism for reviewing and adjusting access rights.
Recommendation — Review access rights periodically and remove approvals that no longer match job need.
CIS Controls v8 CIS-5 — Account Management Campaign design affects how organizations manage access approval, review, and removal.
Recommendation — Implement account review and removal processes that keep access current and defensible.

Practitioner Guidance

What to prioritise: Fix the review path before adding more campaigns. If reviewers cannot quickly understand scope, owner, and required action, more frequency will only increase noise.

What to verify: Check whether every queue has a clear owner, every exception has an escalation route, and every approval or revocation can be traced back to a specific reviewer action.

Common mistake: Teams often optimise for policy coverage and completion rates, then discover too late that the workflow made the campaign hard to execute. A campaign that finishes on time but changes nothing is a failed control, not a successful one.

Practitioner takeaway: Design certification so the reviewer can decide quickly and the organisation can enforce that decision immediately. If the workflow does not reduce ambiguity and close the loop, the campaign will produce artefacts, not control.