Look at whether ownership, review status and retirement dates are current for every identity type, not just whether certifications were completed. If the programme cannot show timely removal of stale access or current accountability for machine identities, it is lagging behind actual identity movement.
How IGA Keeps Pace with Identity Change
IGA is keeping up only when it reflects the current state of identities, not the last completed campaign. That means ownership, entitlement review status, and retirement dates stay accurate across workforce, privileged, service, application, and machine identities, with stale access removed on time and accountable owners visible when changes happen.
A useful test is whether the programme can show that identity movement has been absorbed into the governance loop: new identities are registered, movers lose outdated access, leavers are deprovisioned, and non-human accounts are reviewed on the same timetable as people.
One practical signal is whether your IGA view still matches real operational reality after a change event. If the system says an owner, reviewer, or review outcome is current, but the underlying account, credential, or retirement date has drifted, then governance is lagging behind the identity estate rather than controlling it.
What Current State Looks Like Across Human and Machine Identities
The strongest IGA programmes treat identity state as a live inventory problem, not a periodic certification problem. They can answer who owns each identity, when it was last reviewed, whether the access is still needed, and when retirement or rotation is due. That matters most where accounts are long-lived, shared, or embedded in automation, because those are the cases where stale access quietly accumulates.
This is where IAM and IGA Basics helps frame the distinction between access governance and access administration, while Joiner-Mover-Leaver (JML) Guide shows why movers and leavers are the first place drift appears. If retirement dates and ownership fields are not updated when identity events occur, the governance record becomes historical documentation rather than operational control.
For non-human identities, the same question has to be asked more aggressively. NHI Lifecycle Management Guide and Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs both reinforce that lifecycle evidence, not just review completion, is what proves control over machine accounts, secrets, and rotation points.
Current state also depends on discovery. If the programme cannot inventory dormant, orphaned, or hidden accounts, then review completion will look healthy while the actual estate keeps growing underneath it. That is why effective governance ties certification to discovery, ownership, and decommissioning signals rather than to the campaign record alone.
What to Measure When You Want Proof, Not Paperwork
Measure whether identity records are current, not simply whether the review workflow was closed. The most useful indicators are stale-access aging, percentage of identities with named accountable owners, time from business change to access update, and the share of identities whose retirement dates are overdue or missing. Those signals show whether governance is following the identity lifecycle or merely documenting it after the fact.
It is also worth separating completion metrics from effectiveness metrics. A 100% certification completion rate can coexist with unresolved stale access if reviewers rubber-stamp or if remediation is not enforced. A better read is whether completed reviews actually lead to removals, entitlement reductions, credential rotation, or account retirement within a defined service window.
Access Reviews and Certification Guide is useful here because it focuses on closing the loop, while Identity Security Posture Management (ISPM) Guide gives a posture-based lens for spotting drift, stale accounts, and configuration gaps that a campaign report can miss. If the remediation backlog is growing faster than the change rate, the programme is no longer keeping pace.
Accountability is the second measurement dimension. Current ownership should exist for every identity type, including service and machine identities, because governance fails fastest when no one is clearly responsible for a dormant or overprivileged account. If ownership changes are slower than technical changes, the control is already behind.
Risk and Threat Considerations
When IGA lags identity change, the main risk is not missed paperwork, it is accumulated access that no longer matches business need. That creates stale permissions, orphaned identities, and unowned machine accounts that can be abused for persistence, lateral movement, or privilege escalation.
Failure mechanism: Identity lifecycle events are not propagated quickly enough into ownership, review, and retirement records, so access remains valid after the original business need has disappeared. Over time, certification becomes a retrospective activity that fails to remove real exposure.
Impact: The organisation inherits hidden attack paths, audit gaps, and accountability failures, especially where long-lived non-human credentials can keep operating even after the underlying service, pipeline, or application has changed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Identity change depends on timely credential retirement and rotation. |
| AC-2 — Account Management | IGA must keep account ownership, status, and lifecycle current across identity types. | |
| AU-6 — Audit Review, Analysis, and Reporting | Evidence of effective IGA comes from review and remediation reporting, not completion alone. | |
| Recommendation — Track credential lifecycle events and retire stale authenticators promptly. Maintain current account ownership, review status, and timely deprovisioning. Review audit evidence to confirm completed reviews led to actual access removal. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Current identity records and ownership are central to identity governance accuracy. |
| A.5.18 — Access rights | The question is about whether access removal keeps pace with identity change. | |
| Recommendation — Keep identity records and ownership assignments current across the lifecycle. Revoke or adjust access promptly when identity conditions change. | ||
Practitioner Guidance
What to verify: Confirm that every identity type has a current owner, a current review state, and a clear retirement or rotation date. If any of those fields depend on manual cleanup after the event, the process is already too slow for a changing estate.
Decision rule: If certification is succeeding but stale access is not shrinking, treat the programme as control theatre and inspect remediation enforcement, discovery coverage, and lifecycle integration before expanding review frequency.
What good looks like: New identities are assigned ownership at creation, movers lose outdated access promptly, leavers are removed on schedule, and machine identities are rotated or retired with the same discipline as human accounts.
Practitioner takeaway: IGA is keeping up only when identity state changes are reflected in governance records fast enough to remove exposure, not just fast enough to pass a review campaign.
Related resources from NHI Mgmt Group
- How do security teams know if testing is keeping up with production change?
- How do you know if an identity security programme is actually keeping up?
- How do teams know if identity security controls are actually working?
- How can organisations know whether identity controls are keeping up with change?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org