Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations treat recertification as part of access…
Governance, Ownership & Risk

Should organisations treat recertification as part of access review governance?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Yes. Recertification depends on proving that the current access model still matches current business reality, not just the state of the organisation three years ago. Teams that fold certification evidence into their regular review cycle avoid rebuilding records under audit pressure and reduce the risk of finding gaps too late.

Should recertification live inside access review governance?

Yes, because recertification is not a separate paperwork exercise, it is the governance check that keeps access review evidence tied to current business reality. If teams treat it as part of the same control cycle, they can validate ownership, confirm continuing need, and avoid rebuilding stale evidence under audit pressure. That is true for people access and for machine and service access alike.

When organisations separate recertification from access review operations, they usually end up with two weak processes instead of one strong one: one that spots excess access too late, and another that cannot prove why access remained in place. Folding the activity into the regular review rhythm helps make revocation decisions, reviewer sign-off, and evidence retention part of one traceable workflow rather than an after-the-fact scramble.

What recertification adds to a normal access review

Access review governance asks whether access is appropriate today; recertification adds the formal confirmation that the current entitlement still matches the current role, project, system, or operational dependency. That matters because access often drifts as teams change, systems are retired, and temporary exceptions become permanent. The review is only complete when someone accountable can re-affirm, or remove, the access based on present facts.

In practice, recertification is strongest when it is evidence-backed rather than opinion-backed. Reviewers should not be asked to guess from memory. They need context such as business owner, last-use signals, role history, system criticality, and exception rationale so they can make a current decision instead of rubber-stamping yesterday’s state. Access Reviews and Certification Guide is a useful reference for designing reviews that remove access rather than just record it.

For identity governance programmes, the practical test is simple: if recertification does not change the decision quality, reduce stale access, or strengthen audit evidence, it is not functioning as governance. That is why mature teams connect recertification to the access review calendar, not to a one-off annual cleanup.

How to operate it without creating audit theatre

The best operating model is to make recertification part of a repeatable review cadence with clear ownership, scoped access populations, and a defined revocation path. Separate “review completed” from “risk accepted” and from “exception approved”, because each has different accountability and different follow-up. If you cannot show who approved continued access, when they approved it, and what evidence they used, the control is incomplete.

Coverage should include access that carries business, privileged, or machine-to-machine consequences, not just user entitlements. NHIMG’s IAM and IGA Basics explains how access governance spans people and machines, and NHI Lifecycle Management Guide shows why lifecycle events, ownership, and recertification belong together. When service access is excluded, the organisation usually preserves the highest-risk blind spot while believing the review was complete.

That is also why role design and removal discipline matter. If roles are overloaded or access is inherited through layers of groups and exceptions, recertification becomes slow and low-confidence. A cleaner entitlement model makes the review easier to approve, easier to revoke, and easier to evidence.

Risk and Threat Considerations

Separating recertification from access review governance creates a control gap: access can remain active long after the business reason has changed, and reviewers may never see the drift until an audit or incident exposes it. The risk grows when entitlements are broad, long-lived, or tied to privileged or non-human access paths.

Failure mechanism: Ownership becomes unclear, review evidence fragments across cycles, and stale access is repeatedly re-approved because the control tests historic records instead of current need.

Impact: Excess privilege persists, revocation happens too late, audit evidence becomes fragile, and an attacker or insider has a longer window to abuse standing access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementRecertification validates continued access need and drives revocation decisions.
AC-6 — Least PrivilegeRecertification should confirm access still aligns with least-privilege intent.
AU-6 — Audit Record Review, Analysis, and ReportingAccess review governance relies on reviewable evidence and traceable approval history.
Recommendation — Review accounts on a recurring basis and revoke access that no longer has a current business need. Reassess entitlements periodically and remove permissions that exceed current job or operational need. Retain and review access decision evidence so each recertification action is auditable.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights must be reviewed, adjusted and removed as business need changes.
Recommendation — Periodically review access rights and remove or adjust them when they no longer match business need.
CIS Controls v8CIS-5 — Account ManagementRecertification supports ongoing account and entitlement governance across the environment.
Recommendation — Establish recurring account reviews and promptly remove access that is no longer required.

Practitioner Guidance

What to prioritise: Put recertification on the same operating calendar as access review, with the same owner, evidence standard, and revocation workflow. If a reviewer cannot make a current decision without extra investigation, the scope is too broad or the entitlement data is too weak.

What to verify: Confirm that each recertification decision is tied to a named business owner, a current access purpose, and a documented outcome, remove, retain with rationale, or escalate. If those three items are missing, the review is not governance-grade evidence.

Practitioner takeaway: Treat recertification as the decision-quality layer of access review governance, not as a separate administrative task, because governance only works when current need, ownership, and revocation are managed in one closed loop.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org