TL;DR: Access certification can confirm whether a user’s role justifies access, but it cannot prove that the customers whose data is being accessed consented to the processing, according to OpenIAM. In regulated environments, that creates an architectural accountability gap between IGA and CIAM that certification alone cannot close.
NHIMG editorial — based on content published by OpenIAM: Your Access Review Process Has a Consent-Shaped Hole in It and Auditors Are Starting to Notice
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, 46% confirmed, 26% suspected.
Questions worth separating out
Q: What breaks when access certification is used to prove consent authorization?
A: It breaks because certification and consent answer different questions.
Q: Why do separate IGA and CIAM platforms create audit risk for customer data access?
A: Because the records are split across two control planes.
Q: How do security teams know consent governance is actually working?
A: They should look for evidence that banner choices, tag behaviour, and audit records all align across every relevant flow.
Practitioner guidance
- Map every certification scope that touches customer data Identify where access reviews cover systems holding personal data and determine whether any review step can surface current consent scope alongside role entitlement.
- Test the audit question before the audit arrives Pick one user, one dataset, and one processing purpose, then verify whether your current IGA and CIAM records can prove that access was consent-authorized at the time of use.
- Move consent checks into the authorization layer Where customer personal data and internal access intersect, require the policy engine to evaluate consent status at the moment access is granted or used, not only during periodic review.
What's in the full article
OpenIAM's full article covers the operational detail this post intentionally leaves for the source:
- A step-by-step explanation of how a converged policy engine can evaluate consent state and access entitlement together.
- Sector-specific examples for regulated enterprises handling customer personal data under GDPR and financial services supervision.
- The governance logic behind the certification workflow and why separate IGA and CIAM platforms cannot natively produce the same audit trail.
- The article's self-assessment questions for spotting a consent gap before the next certification campaign.
👉 Read OpenIAM's analysis of the consent gap in access certification →
Access certification and consent: where governance breaks down?
Explore further
Access certification and consent governance are different control planes. Access certification is designed to answer whether a user’s entitlement still matches role and business need. Consent governance answers whether a particular use of customer data is legally and operationally authorized. When enterprises treat those as the same problem, they create a false sense of completeness in the certification record. Practitioners should read this as a control separation problem, not a process quality problem.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, 38% have no or low visibility, and a further 47% have only partial visibility, according to The State of Non-Human Identity Security.
- 1 in 4 organisations are already investing in dedicated NHI security capabilities, with an additional 60% planning to do so within the next twelve months.
A question worth separating out:
Q: Who is accountable when access reviews miss consent scope for customer data?
A: Accountability sits with the organisation that owns the processing decision and the identity architecture supporting it. Regulators will not treat separate systems as an excuse if the enterprise cannot demonstrate lawful access. The accountable teams usually span IAM, privacy, and application owners, because the gap is architectural rather than isolated to one function.
👉 Read our full editorial: Access review misses consent governance in regulated data access