TL;DR: Nexis says IAM programmes still struggle with orphaned accounts, static permission models, and recertification campaigns that can take up to five months, while one CSS Insurance case reduced recertification to eight weeks by shifting to role-based governance. Governance speed now matters as much as coverage when entitlements keep changing.
Editorial analysis by NHI Mgmt Group, based on content published by Nexis: “NEXIS Impulse July”.
Key questions
Q: What breaks when IAM recertification campaigns take months to finish?
A: When recertification campaigns drag on for months, reviewers are certifying access that may already be obsolete by the time decisions are made.
Q: Why do static permission models increase IAM governance risk?
A: Static permission models lock access into structures that do not adapt as job roles, applications, and business relationships change.
Q: How can security teams tell whether privileged access reviews are actually working?
A: They are working when every privileged entitlement is inventoried, every decision is traceable, and revoked access is removed from all connected systems without delay.
Practitioner guidance
- Audit orphaned accounts first Identify former employee accounts, stale service access, and dormant identities that still appear in certification scope, then remove them before the next review campaign starts.
- Replace spreadsheet recertification inputs Move certification inputs from exported lists to live entitlement data so reviewers work from current access states instead of outdated snapshots.
- Rationalise the role model Collapse duplicate or overly narrow roles so reviewers can assess business access patterns rather than thousands of individual permissions.
Bottom line: IAM hygiene issues often surface as slow recertification, but the underlying problem is stale access structures that no longer match the business.
What's in the full analysis
Nexis's full article covers the operational detail this post intentionally leaves for the source:
- The CSS Insurance success story with specific governance changes behind the move to 8-week recertification cycles
- The practical quick wins for identifying and disabling orphaned accounts within days
- The blog guidance on replacing spreadsheet-driven reviews with dynamic authorisation concepts
- The webinar details on integrated IAM and GRC workflows for audit readiness and risk reporting
👉 Read Nexis's analysis of IAM hygiene and recertification backlogs →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Governance velocity has become an IAM control objective, not an operational afterthought. When recertification takes months, the access model is already behind the business reality it is supposed to govern. That makes certification a lagging activity unless entitlement structures and review workflows are designed for current-state speed. Practitioners should measure governance latency, not just review completion.
A question worth separating out:
Q: Should organisations prioritise role modelling or recertification first?
A: Most organisations should stabilise the role model first if reviews are drowning in one-off entitlements, because better structure makes recertification faster and more accurate. If the role model is already mature, then improving review workflow and offboarding discipline may deliver quicker gains. The right sequence depends on whether the main problem is structure or throughput.
👉 Read our full editorial: IAM hygiene and recertification backlogs are still slowing governance