Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations prioritise role modelling or recertification first?
Governance, Ownership & Risk

Should organisations prioritise role modelling or recertification first?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Most organisations should stabilise the role model first if reviews are drowning in one-off entitlements, because better structure makes recertification faster and more accurate. If the role model is already mature, then improving review workflow and offboarding discipline may deliver quicker gains. The right sequence depends on whether the main problem is structure or throughput.

Why sequencing depends on whether the problem is structure or throughput

role modelling and recertification solve different bottlenecks, so the right sequence depends on what is breaking down first. If entitlement data is noisy, duplicated, or impossible to interpret, recertification becomes a sorting exercise instead of a control. If the role model is already coherent, the faster win is usually to improve review workflow, reviewer quality, and deprovisioning discipline.

A useful way to think about it is that role modelling reduces complexity before the review begins, while recertification validates or removes access after the fact. When organisations try to accelerate reviews without fixing a fragmented entitlement structure, they often just review bad data faster. When they redesign roles without a reliable review cycle, they can end up with a cleaner model that still does not get enforced.

For that reason, the first question is not “which control is better?” but “which one is currently constraining the other?” If one-off entitlements, inherited access, or inconsistent naming are dominating the estate, structure is the limiting factor. If roles are already stable and the issue is review fatigue, stale approvals, or slow removal of access, the review process is the higher-value target.

How a mature role model changes recertification quality

Well-designed roles make certification campaigns smaller, clearer, and easier to action. They give reviewers a sensible baseline, make exceptions easier to spot, and reduce the number of ad hoc entitlements that must be justified one by one. That is why role design often has an outsized effect on both accuracy and speed, even though the actual review control sits later in the lifecycle. See the Role Mining and Role Design Guide for a practical approach to building a manageable role model.

This is especially important where reviews are overloaded by entitlement noise. A role model that distinguishes business roles, application roles, and exception access helps reviewers decide whether an item is normal, temporary, or truly risky. It also makes it easier to separate access that should be absorbed into a role from access that should be removed outright.

Recertification, in turn, gives the role model feedback. If the same exceptions keep appearing in every campaign, that is a sign the role design is incomplete or outdated. Treat repeated exceptions as a design defect, not just a review nuisance.

When recertification should come first

There are cases where better review execution should come first. If the organisation already has a stable role catalogue but approvals are rubber-stamped, offboarding is inconsistent, or reviewers lack context, then the fastest reduction in exposure usually comes from fixing the review and removal process. A cleaner workflow can quickly reduce dormant access even before the role model is reworked.

That same logic applies when access reviews are meant to compensate for a weak operational discipline. If roles are broadly sound but stale access persists because reviews do not trigger action, then improving closure, escalation, and evidence of removal matters more than redesigning roles. In that situation, better recertification can produce immediate risk reduction while longer-term role rationalisation continues.

Access review and certification guidance is most useful here because it focuses on removing access, not just collecting approvals. The Access Reviews and Certification Guide is a good reference for campaigns that need to cut volume, add context, and close the loop on remediation.

Risk and Threat Considerations

Poor sequencing creates two common failure modes: overinvesting in role design while recertification remains ineffective, or scaling reviews over a chaotic entitlement base until fatigue makes the control meaningless. In both cases, the control can look mature on paper while excessive access, stale access, or repeated exceptions continue to accumulate.

Failure mechanism: Fragmented roles increase review volume and ambiguity, which encourages rubber-stamping; weak recertification then fails to remove unused or inappropriate access, allowing privilege creep to persist.

Impact: The organisation ends up with slower reviews, weaker accountability, and a larger attack surface, especially where excessive access can be used for fraud, lateral movement, or misuse of privileged accounts.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5, CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-05 — Overprivileged NHIRole and review sequencing directly affects excess entitlement risk.
NHI-01 — Improper OffboardingRecertification and offboarding discipline determine whether stale access is removed.
NHI-07 — Long-Lived SecretsLifecycle discipline matters when access persists beyond its intended review window.
Recommendation — Reduce overprivilege by removing ad hoc access before expanding the role model. Tighten offboarding and review closure so access is revoked promptly. Shorten credential lifetimes and tie renewal to explicit review.
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeRole modelling and recertification both enforce least privilege through entitlement control.
AC-2 — Account ManagementAccount lifecycle and review workflows are central to sequencing role and recertification work.
IA-5 — Authenticator ManagementAccess governance often depends on revoking or expiring authenticators and secrets during reviews.
Recommendation — Minimise standing access and remove permissions that are not routinely needed. Govern account changes and removals through a controlled lifecycle process. Track authenticator lifecycle and revoke credentials when access changes.
CIS Controls v8CIS-5 — Account ManagementThe question is about deciding where account and entitlement governance effort should start.
Recommendation — Prioritise account governance work where it most reduces review burden and excess access.
NIST CSF 2.0PR.AA-05 — Identity Management, Authentication, and Access ControlRole design and recertification both sit inside access control governance.
Recommendation — Align access control decisions with a clear role and entitlement structure.

Practitioner Guidance

What to prioritise: Start with the bottleneck that most directly increases review cost or control failure. If reviewers cannot tell what access is normal, stabilise the role model first; if they can tell, but nothing gets removed, fix the review and offboarding workflow first.

What to verify: Before changing sequence, check whether most exceptions are true business exceptions or artefacts of bad role structure. Also verify whether completed reviews actually result in removal, because a high completion rate without remediation is a weak signal.

Common mistake: Treating role modelling and recertification as separate programmes. In practice, each should feed the other, because recurring review exceptions are often the fastest way to find broken roles, and recurring role exceptions are often the fastest way to find weak governance.

Practitioner takeaway: Sequence should follow the dominant failure mode, not organisational preference: clean up structure first when review noise is the main problem, and strengthen review execution first when access is already understandable but not being removed.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org