The control becomes stale as soon as roles, projects, contractors, or applications change. A one-time approval proves access was appropriate at a moment in time, but it does not prove the same after business conditions shift. Recertification exists because entitlement state drifts, and governance has to keep revalidating that access still matches current need.
Why One-Time Certification Fails as a Control
access certification is only meaningful if it is repeated often enough to catch drift. When you certify once and stop, the decision quickly becomes historical rather than current, because roles, projects, vendor relationships, and application entitlements keep changing. That makes the control look complete on paper while leaving governance blind to stale or excessive access in practice.
A one-time review also misses the lifecycle events that create risk: movers inherit old access, contractors outlast their original need, and applications accumulate permissions as integrations expand. The control objective is not just to approve access, but to keep proving that the approval still matches the business need.
One-time certification is best understood as a point-in-time checkpoint, not an access governance program. It can tell you that a reviewer agreed at one moment, but it cannot tell you that the same entitlement remains justified after the environment shifts.
What Stale Access Looks Like in Real Operations
Once certification stops, the organisation depends on memory, informal ownership, or ticket history to know whether access still makes sense. That is fragile because the access decision often outlives the original context, especially where IAM and IGA Basics are not being used to tie entitlement state to ownership and review cycles.
The failure shows up differently across identities and systems. People keep entitlements after role changes, contractors retain access after engagements end, and service access remains active after application decommissioning or reconfiguration. A review process that never recurs cannot distinguish current need from leftover permission.
This is why good review programs are designed around entitlement state, not just approvals. Access Reviews and Certification Guide is useful here because it focuses on how review campaigns remove access, include context, and close the loop instead of treating certification as a paperwork exercise.
How Recertification Keeps Governance Aligned
Recertification exists because governance has to keep revalidating access against current need, current ownership, and current business context. That is why lifecycle management matters even when the original approval was legitimate. NHI Lifecycle Management Guide reinforces the same operational truth: access must be renewed, rotated, or removed as conditions change, not merely approved once.
The strongest recertification programs are tied to events that change entitlement validity, such as role moves, project closure, supplier offboarding, application migration, and privilege expansion. In that model, the review is not a periodic ritual detached from reality. It is a control that tracks whether the justification for access still exists.
That also affects how organisations design review scope. Broad, infrequent campaigns tend to create reviewer fatigue and rubber-stamping, while smaller, event-driven reviews are easier to act on and more likely to remove genuinely stale access. Governance is strongest when the review cadence reflects how quickly access can become obsolete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access certification is part of maintaining account and entitlement status over time. |
| AC-6 — Least Privilege | Stale access turns previously valid permissions into excess privilege. | |
| Recommendation — Recertify accounts and entitlements on a defined cadence and remove stale access promptly. Review entitlements regularly and reduce any access that exceeds current job need. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access rights must be reviewed and adjusted as business conditions change. |
| Recommendation — Maintain periodic access reviews and revoke rights that no longer match business need. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account governance requires ongoing review, not one-time approval, to stop entitlement drift. |
| Recommendation — Implement recurring access reviews and promptly disable unnecessary accounts and privileges. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions Management | The question is about keeping access permissions aligned as conditions change. |
| Recommendation — Revalidate permissions on a schedule and remove access that no longer has a business need. | ||
Practitioner Guidance
What to verify: Confirm that the review process has a renewal trigger, an owner, and a removal path. If a certification outcome does not lead to timely revocation or reapproval, it is not closing the governance loop.
Decision rule: If access can change faster than the review cadence, treat the certification as insufficient on its own. Shorten the interval, move to event-driven recertification, or limit the entitlement so the blast radius stays small between reviews.
Common mistake: Teams often measure success by whether a campaign was completed, not by whether stale access was actually removed. Completion is administrative; removal is the control outcome.
Practitioner takeaway: One-time certification answers “was this access ever approved?”, but recertification is what answers “is this access still justified now?”