Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should access reviews and SoD run before ownership…
Governance, Ownership & Risk

Should access reviews and SoD run before ownership is fully resolved?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

No. Reviews and SoD logic should not be treated as reliable until the ownership layer is complete, because both controls assume they are evaluating people rather than raw account names. If the resolution layer is weak, the control outcome may look formal while still missing the real conflict or access issue.

Why ownership has to come first

Access reviews and segregation of duties work best when the review target is a real accountable entity, not just a row in a directory. If ownership is still unresolved, the reviewer can approve, reject, or certify the wrong subject, and SoD rules can miss a conflict because they are attached to an incomplete picture of who actually controls the access.

That is why access review outcomes should be treated as provisional until the ownership layer is stable. The control is still useful for discovery, but the final judgement depends on knowing whether the account belongs to a person, a team, a shared function, or a non-human workflow.

A practical way to think about it is that ownership resolves the question “who is responsible for this access,” while review and SoD answer “should this access remain.” If you reverse that order, you create formal output without reliable accountability, which is exactly how rubber-stamped certifications and hidden conflicts persist.

How unresolved ownership weakens review and SoD logic

Review workflows usually depend on entity resolution, manager hierarchy, business ownership, or application ownership to route decisions correctly. When those inputs are missing or ambiguous, the same entitlement can be interpreted multiple ways, which makes certification results inconsistent and hard to defend.

SoD logic is even more sensitive because it depends on an accurate mapping between access paths and the functions they enable. A toxic combination can only be detected if the control knows which identity actually holds the privileges, which business process the access supports, and whether the access is direct, inherited, shared, or temporary.

For that reason, ownership is not just metadata. It is the control plane that makes downstream governance decisions meaningful, including recertification, exception handling, remediation assignment, and escalation when no valid approver exists.

What to do before treating the control as authoritative

Before relying on review or SoD results, establish a complete ownership record for each account, entitlement, and sensitive application path. NHIMG’s NHI Ownership and Accountability Guide is useful here because it frames ownership as the prerequisite for accountable control decisions rather than an afterthought.

Where the broader governance process is still being shaped, it helps to align the review model with lifecycle and certification practice. The Access Reviews and Certification Guide shows how to reduce review noise and keep attention on access that can actually be acted on, while the Segregation of Duties (SoD) Guide explains how conflicting permissions should be modelled once the identity or account owner is known.

If ownership is still partial, treat early review output as a data-quality signal, not as a control conclusion. Missing owners, duplicate owners, shared accounts, and orphaned entitlements are the conditions that should trigger cleanup before certification closes.

Risk and Threat Considerations

Unresolved ownership creates a control gap where access can appear governed even though no one can reliably attest to it. That makes it easier for stale access, shared access, and hidden privilege combinations to survive review cycles and for remediation to stall because no accountable owner is able to accept or reject the finding.

Failure mechanism: The review or SoD rule engine evaluates an account or entitlement before the true accountable owner is established, so the control may be routed, certified, or exceptioned against the wrong subject. In practice, that can convert an apparent governance control into a documentation exercise that misses the real conflict.

Impact: Organisations can retain excessive access, fail to detect conflicting duties, and create an audit trail that looks complete but does not reflect actual control over who can act on the system.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementOwnership resolution and review routing depend on accurate account governance.
AC-5 — Separation of DutiesThe question is about SoD reliability and conflict detection.
IA-5 — Authenticator ManagementOwnership gaps often surface through unmanaged credentials and stale access material.
Recommendation — Ensure each account has a named owner before certification and SoD decisions are finalized. Model conflicting access paths only after ownership mapping is complete. Tie credential lifecycle checks to the resolved owner before review closure.
ISO/IEC 27001:2022A.5.15 — Access controlAccess decisions depend on governance over who is allowed to review and approve access.
A.5.18 — Access rightsAccess rights reviews are central to the question and need reliable ownership.
Recommendation — Require complete ownership evidence before approving access control reviews. Verify each access right is linked to a responsible owner before recertification.

Practitioner Guidance

What to prioritise: Resolve ownership before you finalise review scope. If an account, entitlement, or application cannot be mapped to a responsible owner, flag it as a cleanup item rather than allowing it to pass through normal certification.

What to verify: Confirm that each reviewed item has a single accountable owner or a clearly defined ownership fallback, and that SoD rules are using the same resolved entity model as the review workflow.

Common mistake: Treating a completed certification campaign as proof that governance is working when the real issue is unresolved ownership upstream. A clean approval rate is not a strong signal if the review population was poorly resolved.

Practitioner takeaway: Review and SoD are decision controls, but ownership is the prerequisite for the decision to mean anything, so fix resolution first and then trust the outcome.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org