The clearest signs are repeated approvals of access with no usage context, heavy reliance on manager memory, and widespread reluctance to revoke access because no one can judge the productivity impact. When reviews preserve old entitlements instead of testing current need, certification has become a ritual rather than a control.
How to Spot an Evidence-Based Certification Campaign
Evidence-based certification starts with current facts, not memory. The campaign should ask whether the access is still needed, whether the entitlement is actually used, and whether the reviewer can point to a current business reason. When a review process cannot answer those questions, it is operating as a paper exercise rather than a control.
A strong signal of weakness is that reviewers are asked to approve large lists of access with little or no context. That usually means the campaign is optimised for speed and completion, not for deciding whether the access still matches the role, task, or system exposure. For practitioner teams, the tell is not whether reviews are happening, but whether the review output changes anything meaningful.
Another sign is when certification depends on manager memory instead of usage evidence, owner context, or system telemetry. Managers often know the person, but not the real permission set, the current application state, or whether the access is inherited from an old project. If the process cannot surface current evidence, it will preserve historical access and quietly normalise entitlement drift.
What Failure Looks Like in the Review Workflow
Campaigns become non-evidence-based when they reward quick approval over informed decision-making. That usually shows up as repeated recertification of the same access, rubber-stamping across cycles, and little attempt to challenge dormant or excessive entitlements. The review may be formally complete while the access posture stays unchanged.
A second failure mode is poor context at the point of decision. Reviewers may see a name and a role label, but not last-use data, entitlement lineage, privileged scope, or dependency on a sensitive system. Without that context, the reviewer is effectively guessing. Good certification work makes the decision auditable because the evidence needed to justify approval or removal is already present.
This is where Access Reviews and Certification Guide is useful: it frames certification as a risk-based decision process, not a volume exercise. When the campaign does not remove access, narrow scope, or trigger follow-up action, the organisation should treat that as a sign that the review design is too weak to influence actual entitlements.
Why Stale Entitlements Keep Surviving
Stale access survives when the campaign is built around convenience and organisational discomfort instead of current need. People hesitate to revoke access because they do not want to interrupt productivity, expose unclear ownership, or trigger disputes about whether the entitlement is still important. That creates a bias toward preservation, especially in environments where managers are overloaded and application owners are not engaged.
Widespread reluctance to revoke access is especially revealing because it means the campaign is not testing necessity, it is negotiating inertia. If every review defaults to “keep” unless there is a clear objection, the process will keep old access alive long after the original justification has disappeared. Over time, the campaign becomes a record-keeping ritual that protects legacy access rather than a control that reduces it.
IAM and IGA Basics helps place this problem in the broader governance model: certification only works when it sits inside a lifecycle that includes ownership, entitlement clarity, and revocation authority. Where that lifecycle is missing, campaigns tend to approve what already exists instead of testing whether the access should still be there.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Certification campaigns are part of account and entitlement lifecycle control. |
| AC-6 — Least Privilege | Reviews should remove access that is no longer necessary for current duties. | |
| Recommendation — Require periodic access reviews that support timely removal of unused or excessive access. Use least privilege to drive removal of access that lacks a current business need. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Access recertification must verify and adjust rights rather than rubber-stamp them. |
| Recommendation — Review access rights at defined intervals and revoke what is no longer justified. | ||
| CIS Controls v8 | CIS-5 — Account Management | Campaigns are an account governance control and should enforce current access need. |
| Recommendation — Audit accounts and access regularly, then remove privileges that no longer match need. | ||
Practitioner Guidance
What to verify: Each certification item should carry enough evidence to support a current decision, such as last use, application scope, owner, and business justification. If reviewers cannot see those signals, treat the campaign as low-confidence and redesign the evidence presented before increasing volume.
What good looks like: The review produces observable change, for example revoked dormant access, narrowed privileged scope, or documented exceptions with expiry. A campaign that ends with almost universal approval and few removals usually indicates weak challenge quality rather than healthy entitlement hygiene.
Decision rule: If the reviewer cannot explain why the access is still needed today, default to follow-up or removal rather than approval. If the organisation cannot tolerate that rule, it should admit the campaign is a governance checkpoint, not a control.
Practitioner takeaway: Evidence-based certification is judged by whether it can justify a current access decision with facts, not by whether it can process every entitlement on time.
Related resources from NHI Mgmt Group
- What is the difference between role-based access and API key governance for NHI security?
- What are the signs that email protections are missing loader-based ransomware campaigns?
- What are the signs that celebrity-based phishing campaigns are working against an organisation?
- What is the difference between policy compliance and evidence-based compliance for AI systems?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org