Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What are the signs that access certification is…
Governance, Ownership & Risk

What are the signs that access certification is becoming a paperwork exercise?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Warning signs include high numbers of pending reviews, repeated approvals with no entitlement changes, vague reviewer ownership, and no evidence that rejected access was actually removed. If the audit trail looks complete but permissions keep drifting, the control is producing records, not governance.

When access certification is working, what changes in the evidence trail?

Healthy access certification leaves a visible decision trail that changes access outcomes, not just audit folders. You should see reviewers making specific approvals, removals, and exceptions based on current business need, with enough context to tell why each entitlement stayed or went. The control should close the loop on access drift, not merely document that a review happened.

That distinction matters because certification is supposed to validate whether access still fits the role, task, or risk posture at the point of review. If the process is only collecting sign-offs, the organisation gets compliance theatre instead of governance, and stale or excessive access can survive from one cycle to the next.

One practical test is whether the review output would change system permissions the same day it is approved. If approvals are not tied to downstream deprovisioning, ticket closure, or entitlement updates, the review is informational rather than controlling. A certification programme that cannot demonstrate removal decisions has already lost most of its security value.

Which operating patterns usually show the review has turned into box-ticking?

Paperwork behaviour tends to show up as repetition and weak ownership. Common patterns include blanket approvals, reviewers signing off on access they do not understand, and review queues that stay open so long that approvers stop treating them as meaningful. Another warning sign is when the same permissions are approved cycle after cycle without any challenge, even after role changes or project exits.

Equally telling is the quality of the reviewer assignment itself. If ownership is vague, delegated too broadly, or disconnected from actual application knowledge, the review becomes a routing exercise. A reviewer who cannot explain why an entitlement exists is not exercising governance, even if the workflow produced a completed record.

Access certification also weakens when the process tolerates unreviewed exceptions. If high-risk entitlements, privileged roles, or dormant accounts are routinely pushed through with generic comments, the campaign may still be “complete” while the control is functionally hollow. The issue is not just volume, it is whether the review mechanism can still distinguish warranted access from inherited access.

What do practitioners need to check before calling a certification programme effective?

First, check whether the process removes access as reliably as it records review decisions. A control that produces evidence but leaves permissions unchanged is not governing access, it is cataloguing it. Second, confirm that reviewers have the context needed to make informed decisions, including entitlement meaning, usage history, and business ownership.

The most useful quality signal is not whether every item was reviewed, but whether the review produced defensible action. That means rejections lead to revocation, exceptions are time bound, and approvals are narrow enough to survive scrutiny. Access Reviews and Certification Guide is useful here because it focuses on designing reviews that actually remove access and close the loop.

Practitioners should also verify that certification is aligned with the identity lifecycle, not operating in isolation. If joiner, mover, and leaver events are creating access drift faster than the campaign can correct it, the review is compensating for broken upstream governance rather than validating access on its own. Joiner-Mover-Leaver (JML) Guide helps frame that lifecycle connection, and IAM and IGA Basics is a good anchor for distinguishing access management from access governance.

Risk and Threat Considerations

When certification becomes a paperwork exercise, the main risk is accumulated access that looks approved but is no longer justified. That creates privilege creep, weak accountability, and a false sense of control. In larger environments, the problem scales quickly because each “rubber-stamped” campaign leaves more inherited access in place for the next review cycle.

Failure mechanism: Reviewers approve access without meaningful evaluation, rejected items are not actually removed, and entitlement drift continues between campaigns. The workflow produces evidence of participation, but it does not enforce access reduction.

Impact: Excess permissions, stale access, and unowned exceptions remain available for misuse, audit findings become harder to dispute, and the organisation may not notice that its access model is decoupled from actual business need.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeCertification should drive removal of excess access and preserve least privilege.
AU-6 — Audit Record Review, Analysis, and ReportingA review process needs usable evidence and follow-through, not just completed records.
IA-5 — Authenticator ManagementCertification often exposes stale credentials and access material that must be revoked alongside access.
Recommendation — Use AC-6 to remove entitlements that reviews show are no longer justified. Use AU-6 to validate that review evidence supports action, not just documentation. Use IA-5 to ensure expired or unnecessary authenticators are removed with the access decision.
ISO/IEC 27001:2022A.5.15 — Access controlAccess certification is a core access control governance activity under Annex A.
A.5.18 — Access rightsThe question is specifically about whether access rights are actually being governed.
Recommendation — Apply A.5.15 to require periodic access review and removal of unjustified access. Apply A.5.18 to ensure access rights are reviewed, adjusted and revoked when no longer needed.
CIS Controls v8CIS-5 — Account ManagementCertification is an account and entitlement governance control tied to access review.
CIS-6 — Access Control ManagementThe issue is whether reviews change effective access and enforce least privilege.
Recommendation — Use CIS-5 to review accounts and remove access that campaigns do not justify. Use CIS-6 to enforce least privilege and act on review outcomes promptly.

Practitioner Guidance

What to prioritise: Focus first on whether every review decision can be traced to an actual entitlement change. If the campaign cannot prove removal, exception expiry, or escalation for unresolved high-risk access, treat it as a control design issue rather than a reviewer-training issue.

What to verify: Check a sample of rejected items end to end, from reviewer decision to system revocation. Also verify that reviewers have enough role and usage context to distinguish legitimate standing access from inherited or obsolete access.

Common mistake: Measuring completion rate as though it were control effectiveness. A 100% closed campaign with no access change is often a weaker outcome than a smaller campaign that removes genuinely risky access.

Practitioner takeaway: Access certification is only governance when review decisions change real access, otherwise the organisation is just producing evidence that its drift is still there.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org