TL;DR: Audit prep turns into a fire drill when access governance runs on fixed cycles while entitlements, ownership, and business processes keep changing, according to Saviynt. Continuous audit readiness depends on always-current evidence across identities, applications, and remediation, because completion alone does not prove control effectiveness.
At a glance
What this is: This is a practitioner analysis of why periodic access reviews fail to keep audit evidence current, and the key finding is that continuous governance matters more than audit-season effort.
Why it matters: It matters because IAM, IGA, PAM, and NHI teams need access evidence, ownership, and remediation to stay current across human users, service accounts, integrations, and AI agents.
By the numbers:
- Breach cases involving stolen or compromised credentials took 292 days on average to identify and contain, according to IBM's 2024 Cost of a Data Breach Report.
- The Association of Certified Fraud Examiners' 2024 Report to the Nations estimates that organizations lose 5% of revenue to fraud each year, with a median loss of $145,000 per case.
- Only 5.7% of organisations have full visibility into their service accounts.
👉 Read Saviynt's analysis of continuous control readiness for audit governance
Context
Continuous control readiness is the discipline of keeping access evidence, ownership, certifications, and remediation current as access changes. In practice, that means audit readiness is built throughout the year, not reconstructed when the audit clock starts. For IAM and IGA teams, the problem is not just volume. It is the gap between how quickly access changes and how slowly many review processes adapt.
The article is especially relevant to NHI governance because the same evidence problem extends beyond human users to service accounts, integrations, and AI agents. When those identities operate across ERP, SaaS, cloud, and infrastructure, the audit question shifts from whether a review happened to whether the control environment still reflects reality. That is the primary weakness this post surfaces: static certification models cannot keep pace with dynamic access.
Key questions
Q: How should teams reduce audit prep time without weakening access governance?
A: Start by keeping access evidence current throughout the year. Trigger reviews when access changes, maintain clear ownership for every entitlement, and record approvals, removals, and exceptions as part of normal governance. That approach shortens audit prep because teams validate existing evidence instead of rebuilding it from disconnected reports.
Q: Why do access certifications fail in practice?
A: Access certifications fail when reviewers are asked to approve entitlements without context, ownership, or sensitivity data. In that situation, the review becomes a formality rather than a governance control. Teams should measure whether certification decisions remove unnecessary access and produce audit-ready evidence, not just whether the task was completed.
Q: What breaks when reviews only cover one application at a time?
A: Cross-application risk stays hidden. A permission that looks acceptable in one system can become dangerous when combined with access elsewhere in the process. That is especially true for ERP, SaaS, cloud, and infrastructure workflows, where the harmful condition is created by the combination, not any single entitlement.
Q: Why do service accounts and AI agents need different controls from human users?
A: Service accounts and AI agents authenticate and act without the predictable patterns that human identity systems expect. They can operate across runtimes, scale quickly, and carry permissions into automated workflows. That means access decisions should consider workload context, runtime behaviour, and time-bound authority rather than relying only on user-centric IAM patterns.
Technical breakdown
Why periodic access certification goes stale
Periodic certification assumes the access state remains stable long enough for reviewers to assess it. In real environments, roles change, entitlements are added, temporary access becomes persistent, and business processes keep moving while the review is still open. That creates a timing mismatch: the control is checking yesterday's access against today's risk. Once access spans multiple applications, a single review loses context even faster because entitlement relationships are only visible when systems are correlated.
Practical implication: tie review triggers to access change events, not just calendar cycles.
Cross-application visibility and segregation of duties
Cross-application visibility is the ability to see identities, entitlements, ownership, and related access across the systems that make up a business process. It matters because segregation of duties conflicts rarely live inside one application. A user can hold individually approved permissions in separate systems that, combined, enable a prohibited action. Spreadsheet-based reviews are especially weak here because they record decisions without exposing those combinations.
Practical implication: map access combinations across ERP, SaaS, cloud, and infrastructure before reviewers certify them.
Continuous control evidence for human and non-human identities
Continuous control evidence is the steady capture of approvals, removals, exceptions, and ownership changes as governance work happens. That matters for service accounts, API integrations, and AI agents because these identities often lack the clear lifecycle checkpoints that humans have. Without an owner and current evidence, they can retain sensitive access long after the business need changes. Continuous evidence turns audit prep from reconstruction into validation.
Practical implication: maintain current ownership and remediation records for service accounts, integrations, and AI agents as part of normal governance.
Threat narrative
Attacker objective: The objective is not a traditional intruder goal but a governance failure state in which outdated evidence and weak visibility let risky access persist through audit review.
- entry: Audit pressure begins when teams discover that access evidence is scattered across disconnected systems and no longer matches the current access state.
- escalation: Reviewer fatigue, unclear ownership, and cross-application entitlements allow risky access patterns to survive a certification cycle without being meaningfully challenged.
- impact: The organisation enters the audit with stale evidence, unresolved conflicts, and incomplete visibility into whether access controls are actually reducing risk.
Breaches seen in the wild
- Sisense breach — unauthorized GitLab access led to exfiltration of access tokens, API keys and certificates.
- Meta AI Instagram Account Takeover — 20,225 Instagram accounts hijacked via compromised Meta AI support chatbot with overprivileged access.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Continuous audit readiness is an access governance problem, not an audit-season problem. The article is correct to move the focus from frantic evidence gathering to always-current control state. In identity programmes, the control is only as strong as the freshness of the evidence behind it. The practitioner conclusion is simple: if access evidence is stale, the control story is already weak.
Cross-application visibility is the named concept that separates real governance from spreadsheet compliance. Access risk lives in the combination of entitlements across ERP, SaaS, cloud, infrastructure, and NHI processes, not in isolated approvals. That is why reviewer completion rates can look healthy while segregation of duties risk still survives. Practitioners should treat cross-application visibility as the minimum basis for any credible certification programme.
Continuous control readiness exposes the limits of review models built only for human users. Service accounts, integrations, and AI agents do not follow employee-style lifecycles, so periodic review cadences routinely miss ownership drift and persistent access. The relevant governance lens is lifecycle discipline across actor types, not one-off certification. Practitioners should extend the same evidence standard to non-human identities that they expect for people.
The 292-day credential containment figure shows why late discovery and weak evidence are operational, not theoretical, risks. When compromised credentials take that long to identify and contain, any audit model that depends on end-of-cycle reconstruction is already behind the threat. Access governance has to surface changes while they happen, not after the fact. The practitioner conclusion is to align control evidence with runtime change, not reporting deadlines.
Continuous readiness validates NIST CSF-style governance, but it also reveals where control ownership is unclear. The programme gains value when decisions, exceptions, and remediation stay linked to named owners across the full business process. That is especially important for NHI-linked workflows, where the accountable human often disappears behind the identity. Practitioners should make ownership traceable before they try to make audits faster.
From our research:
- Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.
- Only 97% of NHIs carry excessive privileges, increasing unauthorised access and broadening the attack surface.
- That visibility gap is why the NHI Lifecycle Management Guide is the right next step for teams trying to bring ownership, rotation, and offboarding under control.
What this signals
Continuous control readiness: this is where access governance is heading, because audit evidence that is rebuilt on demand is already behind the environment. Teams that still rely on quarterly evidence collection will keep discovering the same control gaps under deadline pressure, especially where service accounts and integrations do not fit human review cycles.
The governance shift is broader than audit efficiency. When organisations cannot see who or what has access across systems, they cannot prove that certifications, remediation, and ownership are keeping pace with risk. That is why lifecycle-aware access controls and current evidence need to be treated as operational controls, not compliance paperwork.
The practical implication for IAM programmes is that audit readiness, NHI governance, and human access review are converging on the same design requirement: current, attributable, cross-application evidence. Teams should align their governance model to that reality before the next certification cycle starts.
For practitioners
- Implement event-driven access reviews Trigger certification workflows on role changes, high-risk entitlement grants, ownership changes, and unusual activity so reviews reflect current access rather than a stale quarterly snapshot.
- Correlate entitlements across business processes Build a cross-application view that connects ERP, SaaS, cloud, infrastructure, and NHI access so reviewers can see toxic combinations before approving them.
- Assign accountable owners to every entitlement Require a named business or technical owner for human and non-human access, including service accounts, integrations, and AI agents, and record approval rationale and remediation status.
- Capture audit evidence as governance happens Store approvals, removals, exceptions, and remediation decisions in the normal control workflow so audit prep becomes evidence validation instead of reconstruction.
Key takeaways
- Periodic access reviews are too slow to keep pace with modern entitlement change, so stale evidence is now a governance risk in its own right.
- Cross-application visibility is the control gap that most often separates a completed certification from a truly reduced risk posture.
- Audit readiness improves when ownership, evidence, and remediation are maintained continuously for human and non-human identities alike.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Access governance and current evidence align with identity and access control management. |
| NIST SP 800-53 Rev 5 | AC-2 | Account management is directly implicated by continuous certification and ownership tracking. |
| OWASP Non-Human Identity Top 10 | NHI-03 | Credential and entitlement drift are central NHI governance risks in the article. |
| NIST Zero Trust (SP 800-207) | Continuous verification is relevant to access changes across distributed systems. |
Map NHI lifecycle controls to NHI-03 and ensure non-human access is reviewed continuously.
Key terms
- Control Readiness: The extent to which an organisation has the access, policy, logging, and data structures needed to govern a new technology safely. It is the practical test for whether AI adoption will be contained or allowed to create unmanaged exception paths.
- Cross-Application Visibility: The ability to see identities, entitlements, ownership, and related access across the systems that support a business process. It matters because risk often emerges from combinations of access, not from a single permission inside one application.
- Access Certification: Access certification is the periodic review of whether an identity still needs its current entitlements. For NHIs, certification is only reliable when reviewers know the identity's owner, purpose, and expiry, otherwise stale machine access can persist long after the original use case has ended.
- Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
What's in the full article
Saviynt's full blog post covers the operational detail this post intentionally leaves for the source:
- How the Application Access Governance workflow ties approvals, removals, and exceptions to audit evidence.
- How the platform correlates access across SAP, Oracle, SaaS, cloud, and infrastructure environments.
- How cross-application SoD enforcement and connected remediation are handled in practice.
- How teams can use continuous posture visibility to keep access evidence current between audit cycles.
Deepen your knowledge
NHI governance, IAM, and identity lifecycle management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on July 24, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org