By NHI Mgmt Group Editorial TeamBased on Nexis: “NEXIS Impulse July” (July 8, 2025)

TL;DR: Nexis says IAM programmes still struggle with orphaned accounts, static permission models, and recertification campaigns that can take up to five months, while one CSS Insurance case reduced recertification to eight weeks by shifting to role-based governance. Governance speed now matters as much as coverage when entitlements keep changing.


At a glance

What this is: This is a Nexis roundup on IAM hygiene, recertification backlogs, and a CSS Insurance case study showing that role-based governance can compress review cycles from five months to eight weeks.

Why it matters: It matters because slow access governance creates a growing mismatch between who should have access and who still does, especially in environments with frequent entitlement changes and audit pressure.

👉 Read Nexis's analysis of IAM hygiene and recertification backlogs


Context

IAM hygiene fails when identity data, entitlement models, and review cycles do not keep pace with how access actually changes in the business. Orphaned accounts, static permission structures, and review backlogs are not separate problems, because they compound into slow governance decisions and stale authorisation states.

Nexis uses CSS Insurance as an example of what changes when role-based governance becomes structured rather than manual. The article frames the issue as a governance velocity problem, not simply a coverage problem, and that is the right lens for large IAM programmes that must keep recertification moving without losing control.


Key questions

Q: What breaks when IAM recertification campaigns take months to finish?

A: When recertification campaigns drag on for months, reviewers are certifying access that may already be obsolete by the time decisions are made. That creates governance lag, weakens audit confidence, and leaves orphaned or excessive access in place longer than the business can justify. The core failure is not review volume alone, but stale decision-making.

Q: Why do static permission models increase IAM governance risk?

A: Static permission models lock access into structures that do not adapt as job roles, applications, and business relationships change. Over time, they create exception sprawl, make reviews harder to interpret, and preserve permissions that no longer match operational need. That is why dynamic role and entitlement design is a governance issue, not just an administration preference.

Q: How can security teams tell whether privileged access reviews are actually working?

A: They are working when every privileged entitlement is inventoried, every decision is traceable, and revoked access is removed from all connected systems without delay. If the organisation can only show approvals but not downstream revocation, the review is administrative recordkeeping rather than governance. Proof of removal is the best maturity signal.

Q: Should organisations prioritise role modelling or recertification first?

A: Most organisations should stabilise the role model first if reviews are drowning in one-off entitlements, because better structure makes recertification faster and more accurate. If the role model is already mature, then improving review workflow and offboarding discipline may deliver quicker gains. The right sequence depends on whether the main problem is structure or throughput.


Technical breakdown

Why recertification backlogs persist in IAM

Recertification backlogs usually appear when review processes still depend on spreadsheets, ad hoc business approvers, and entitlement lists that are out of sync with current access. In that model, every campaign becomes a reconciliation exercise instead of a governance control. The result is delayed certification, inconsistent decisions, and a growing gap between actual access and approved access. For IAM teams, the technical issue is not only scale, but also the poor structure of the underlying entitlement data.

Practical implication: reduce the manual reconciliation burden before the next certification cycle starts.

How role models change access governance throughput

A role model turns repeated access decisions into governed structures that can be reviewed at the level of business function rather than individual entitlement. That matters because role-based governance reduces the number of items reviewers must assess and makes patterns easier to validate. The CSS Insurance example shows the operational effect: more access managed through roles and less through one-off exceptions. The architecture issue is not just efficiency, but reviewability at enterprise scale.

Practical implication: treat role model quality as a throughput control for access reviews, not only a design exercise.

Why ghost accounts and static permissions are governance debt

Ghost accounts and static permission models create governance debt because they keep access alive after the business reason for that access has changed. Orphaned identities are not only a cleanup problem, they also distort recertification by forcing reviewers to validate stale access paths that should already have been removed. Static authorization concepts make the situation worse because they preserve permissions that no longer reflect actual job function or target-system reality. The practical failure is accumulation, not just exposure.

Practical implication: link offboarding, entitlement design, and recertification so stale access does not re-enter the review cycle.


NHI Mgmt Group analysis

Governance velocity has become an IAM control objective, not an operational afterthought. When recertification takes months, the access model is already behind the business reality it is supposed to govern. That makes certification a lagging activity unless entitlement structures and review workflows are designed for current-state speed. Practitioners should measure governance latency, not just review completion.

Role-based governance is only useful when role hygiene is strong. The CSS Insurance example shows the value of compressing review cycles through roles, but that benefit depends on role definitions that are understandable, stable enough to govern, and broad enough to reduce exception sprawl. Otherwise, roles become a new layer of complexity instead of a control amplifier. The practical conclusion is to govern the role model as carefully as the entitlements it replaces.

Ghost accounts and static permissions are not isolated hygiene issues, they are lifecycle failures. Orphaned accounts expose weak offboarding, while static permission models reveal that access has not been translated into a living governance structure. This is the same failure pattern seen in many mature IAM environments: the review process is trying to compensate for missing lifecycle discipline. Teams should see recertification backlog as evidence of unresolved lifecycle debt.

Explainable automation matters more than blind acceleration. Nexis points to using explainable AI to speed up role recertification, which is directionally useful only if reviewers can understand why a recommendation exists. In access governance, speed without traceability creates review fatigue and weakens audit defensibility. The practitioner takeaway is to automate the analysis step, not the accountability step.

IAM and GRC are converging around evidence, not just access control. The article’s integrated risk framing reflects a broader shift in governance programmes: identity data must now support compliance, audit readiness, and risk reporting at the same time. That convergence favours organisations that can connect access reviews to actual control evidence. The implication for practitioners is to design IAM outputs for both operations and assurance.

What this signals

Governance latency is becoming a measurable IAM risk. If certification takes months, the programme is confirming access that may already have changed, which turns review into documentation rather than control. Teams should track cycle time alongside completion rates because speed is now part of access assurance.

Role models only reduce pressure when they are actively maintained. A role-based approach can shrink review scope, but stale roles simply move the backlog from entitlements into governance structure. Practitioners need to treat role hygiene as an ongoing operating duty, not a one-time design exercise.


For practitioners

  • Audit orphaned accounts first Identify former employee accounts, stale service access, and dormant identities that still appear in certification scope, then remove them before the next review campaign starts.
  • Replace spreadsheet recertification inputs Move certification inputs from exported lists to live entitlement data so reviewers work from current access states instead of outdated snapshots.
  • Rationalise the role model Collapse duplicate or overly narrow roles so reviewers can assess business access patterns rather than thousands of individual permissions.
  • Measure recertification cycle time Track how long access reviews take from campaign start to sign-off, and treat delays as a governance control signal rather than a project metric.

Key takeaways

  • IAM hygiene issues often surface as slow recertification, but the underlying problem is stale access structures that no longer match the business.
  • The CSS Insurance example shows that structured role governance can reduce campaign duration materially when the role model is strong enough to absorb complexity.
  • Practitioners should focus on governance speed, role quality, and orphaned account cleanup together, because fixing only one of them leaves the backlog intact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle and stale access are central to the recertification backlog problem.
Recommendation — Use CIS-5 to tighten account review, removal, and ownership across the IAM lifecycle.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article is fundamentally about keeping permissions and entitlements aligned with business need.
Recommendation — Apply PR.AA-05 to keep entitlement reviews tied to current authorisation states.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeStatic permissions and excessive entitlements drive the governance backlog this article describes.
Recommendation — Enforce AC-6 so role design and certification reduce unnecessary access.
ISO/IEC 27001:2022A.5.15 — Access ControlThe article concerns governance over access decisions and review processes in an IAM programme.
Recommendation — Align access governance processes to A.5.15 and keep review evidence current.

Key terms

  • Recertification Backlog: A recertification backlog is the accumulation of access reviews that have not been completed on schedule. In IAM programmes it signals that governance is slower than identity change, which increases the chance that stale or excessive access remains in place.
  • Role Model: A role model is the set of roles, groups, or attributes that determine what access an identity receives. It is the hidden dependency inside automated provisioning because the automation engine does not invent policy. It only executes the access structure the organisation has already designed, approved, and maintained.
  • Orphaned Account: An orphaned account is an identity that remains active without a clear owner or business purpose. These accounts are dangerous because they often escape review, retain unnecessary access, and provide attackers with low-friction entry points into otherwise governed environments.
  • Governance Velocity: Governance velocity is the speed at which an identity programme can detect, review, and correct access changes before risk accumulates. It measures whether governance keeps pace with operational change, especially in hybrid estates where privileges drift between review cycles and static certifications become stale.

What's in the full analysis

Nexis's full article covers the operational detail this post intentionally leaves for the source:

  • The CSS Insurance success story with specific governance changes behind the move to 8-week recertification cycles
  • The practical quick wins for identifying and disabling orphaned accounts within days
  • The blog guidance on replacing spreadsheet-driven reviews with dynamic authorisation concepts
  • The webinar details on integrated IAM and GRC workflows for audit readiness and risk reporting

👉 The full Nexis article covers the CSS Insurance case study, IAM quick wins, and integrated governance examples.

Deepen your knowledge

NHI governance, identity lifecycle, and access management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM or identity governance programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org