Quarterly certification should confirm management awareness and responsibility, while annual assessment should prove control design and operating effectiveness. Treat the quarterly process as an accountability checkpoint and the annual process as a verification checkpoint. When those rhythms are aligned, organisations can show both current leadership oversight and durable control assurance.
What quarterly certification should prove versus what annual control assessment should prove
quarterly certification and annual control assessment should not be treated as two versions of the same test. Quarterly certification is best used to confirm that control owners still understand their responsibilities, that access or control attestations are current, and that exceptions have been acknowledged. Annual assessment should go deeper and test whether the control itself is designed well and works consistently in practice.
That split matters because certification answers a governance question, while assessment answers a control assurance question. If you blur them, you can end up with frequent sign-off and still have no evidence that the control is effective, or you can have a strong annual test but stale ownership and weak accountability in between.
For organisations building IAM and IGA Basics, the useful pattern is to let the quarterly process validate who owns the control and the annual process validate whether the control achieves its intended outcome. That keeps certification focused on responsibility and keeps assurance focused on evidence.
How to align the two cadences without duplicating effort
The cleanest alignment is to use the quarterly cycle as a light, high-frequency checkpoint and the annual cycle as a structured deep dive. Quarterly certification should reuse the same control population, definitions, and ownership model as the annual assessment so the organisation is not reconciling two different views of the control universe.
When the two rhythms are aligned, each quarter can surface drift early, such as an owner change, an exception that has outlived its justification, or a control dependency that has shifted. The annual assessment then confirms whether those quarterly signals were resolved and whether the underlying control design still matches the business process, system boundary, and risk being managed.
Practitioners usually get better results when the quarterly certification evidence feeds the annual assessment pack rather than living in a separate workflow. An access review programme such as Access Reviews and Certification Guide helps show how certification can close the loop, while annual testing can use that same history to identify repeat exceptions, weak owners, and patterns of rubber-stamping.
If the control scope includes privileged access, SoD conflicts, or lifecycle-managed accounts, a quarterly review should also trigger remediation tracking, not just sign-off. The annual assessment can then verify whether those remediation actions actually reduced exposure, instead of merely documenting that issues were noted.
What good operating alignment looks like in practice
Good alignment produces one control story told at two different depths. Quarterly certification should show current accountability, complete ownership, and timely acknowledgment of exceptions. Annual control assessment should show whether the control design is appropriate, whether operating evidence is consistent, and whether the control still covers the right population and business process.
That means the annual assessment should not be forced to rediscover what the quarterly cycle already knows. For example, if a quarterly certification repeatedly flags stale ownership, recertification backlog, or unresolved exceptions, the annual review should treat those as indicators of a control design or governance weakness, not as isolated hygiene issues.
Where certification and assessment are aligned with lifecycle governance, teams can also use the annual cycle to validate whether provisioning, review, revocation, and offboarding controls still behave as intended. A lifecycle-oriented reference such as NHI Lifecycle Management Guide is useful because it reflects the same basic discipline: frequent accountability checks, deeper periodic validation, and evidence that the control continues to function over time.
Organisations should also make sure the annual assessment has enough independence to challenge the quarterly process. If the same team both certifies and assesses without any fresh evidence, the annual checkpoint can become a formalised replay of the quarterly one rather than a meaningful verification step.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | CA-2 — Control Assessments | Annual control assessment maps directly to periodic assessment of control design and effectiveness. |
| CA-7 — Continuous Monitoring | Quarterly certification supports ongoing oversight between deeper assessment cycles. | |
| Recommendation — Perform CA-2 assessments on the annual cycle to verify control design and operating effectiveness. Use CA-7 monitoring signals to drive quarterly certification and exception follow-up. | ||
| ISO/IEC 27001:2022 | A.5.36 — Compliance with policies, rules and standards for information security | Quarterly certification and annual assessment both support evidence of policy adherence and control assurance. |
| A.5.35 — Independent review of information security | Annual assessment needs independent verification rather than a repeat of the certification workflow. | |
| Recommendation — Review A.5.36 evidence to confirm controls remain aligned with internal security policy. Use A.5.35 to separate independent assessment from routine managerial certification. | ||
| CIS Controls v8 | CIS-5 — Account Management | Certification cycles are commonly used to validate account ownership, access, and cleanup. |
| Recommendation — Apply CIS-5 to keep account reviews, ownership, and revocation aligned across both cadences. | ||
Practitioner Guidance
What to prioritise: Define one control inventory, one ownership model, and one remediation workflow, then map quarterly certification and annual assessment to different evidence depths for the same control set.
What to verify: Check that quarterly certification is capturing accountable owners, unresolved exceptions, and overdue actions, while the annual assessment is testing design, evidence quality, and operating effectiveness against the same control objective.
Common mistake: Treating quarterly sign-off as proof that the control works. Certification is only credible when it feeds the annual assessment with issues that recur, age badly, or signal a design weakness.
Practitioner takeaway: The goal is not more review activity, but a single assurance model with two cadences, one for ownership and one for evidence.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org