Certification breaks when the review queue becomes too large, too ambiguous, or too poorly described for humans to make informed decisions. At that point, reviewers begin to rely on default approvals, weak context, and shortcuts. The governance failure is not the existence of certification, but the loss of decision quality under scale.
When the review queue outgrows human judgment
access review campaigns fail first as a decision-quality problem, not a workflow problem. Once certifiers are forced to process too many items, too little context, or too many near-duplicate entitlements, the review stops being an informed control and becomes an administrative exercise. At that point, the campaign still exists, but its governance value collapses.
Large queues also change the psychology of the reviewer. People rationally save time by accepting the default, trusting the prior reviewer, or approving items they do not fully understand. That creates the familiar pattern of rubber-stamping, where the control measures activity but no longer measures risk.
Scale becomes especially damaging when the certification scope mixes routine access with privileged roles, shared accounts, service accounts, or other high-impact access paths. Guidance that helps reduce volume and improve context, such as Access Reviews and Certification Guide, matters because the review itself must stay narrow enough for a human to decide carefully.
Why ambiguity matters more than raw volume
A large campaign is not automatically broken if the entitlements are cleanly described and the reviewer can tell why each one exists. The real failure begins when the queue is both large and ambiguous: vague application names, inherited roles, stale ownership data, or descriptions that do not reveal business function. Then the reviewer cannot tell whether an access item is legitimate, excessive, or merely unfamiliar.
That is why campaign design and identity hygiene are linked. If the underlying inventory is incomplete, or if access paths were never rationalized, certification becomes the place where upstream governance defects are rediscovered under time pressure. Reviews then expose problems that should have been resolved earlier in the lifecycle, which is why lifecycle controls such as the NHI Lifecycle Management Guide are relevant to keeping the review population intelligible.
In practice, the most reviewable campaign is one where each item answers a simple question: who has it, why do they have it, and what breaks if it remains. When that question cannot be answered quickly, reviewers are pushed toward approximation rather than verification.
For teams managing broader identity governance, the same problem shows up in controls that combine access review with role and entitlement design. A foundational reference like IAM and IGA Basics is useful because the quality of certification depends on whether the access model is understandable before the campaign starts.
What a broken certification campaign actually changes
When certification quality drops, the governance outcome changes in a few predictable ways. Excess access remains in place longer, reviewers stop challenging risky assignments, and remediation becomes slower because the campaign produces less trustworthy decisions. Over time, the control may still report completion, but it no longer produces confidence.
The deeper issue is that access review is supposed to be a decision control, not a logging exercise. If the population is too large for careful judgment, the campaign no longer creates meaningful evidence of informed approval or denial. In that state, organizations often need to redesign the review model rather than simply ask reviewers to work harder.
That redesign usually means using smaller review scopes, stronger grouping, clearer ownership, and better entitlement descriptions. It can also mean moving some access into role-based structures or governance patterns that make the review population more stable and reviewable. Where access is privileged or high impact, the control should be even tighter, which is why Privileged Access Management Guide is a useful companion for deciding what should never be buried inside a giant certification wave.
Risk and Threat Considerations
Large certification queues create control failure, but they also create exposure. If approvers default to yes, excessive privileges, stale access, and unused entitlements survive longer, which increases the blast radius of any later compromise or misuse. The threat is not the campaign itself, but the predictable human shortcut it induces under scale.
Failure mechanism: Reviewers lose the ability to distinguish normal, excessive, and risky access when the queue is too large or poorly described, so they approve by habit instead of by judgment.
Impact: Weak certification allows privilege creep to persist, reduces the value of the audit trail, and can leave high-risk access unchallenged long enough to become an incident path.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access review quality depends on accurate entitlement lifecycle governance. |
| AC-6 — Least Privilege | Broken certifications preserve excess access and undermine least privilege. | |
| AU-6 — Audit Record Review, Analysis, and Reporting | Certification needs usable evidence and reviewable context to support informed decisions. | |
| Recommendation — Limit account scope and review intervals so certifiers can make informed access decisions. Review and remove entitlements that exceed business need. Use review evidence that supports timely analysis of access changes and exceptions. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Certification campaigns are an access-control governance mechanism requiring clear rules and scope. |
| A.5.18 — Access rights | The subject concerns granting, reviewing and removing rights when they become excessive. | |
| Recommendation — Define access review scope and ownership so approvals remain decision-quality controls. Recertify rights on a schedule that supports removal of stale or unjustified access. | ||
Practitioner Guidance
What to prioritise: Reduce the decision burden before the next campaign runs. Shrink the review set, split privileged from routine access, and make sure each item carries enough context for a reviewer to decide without opening other systems.
What to verify: Check whether certifiers can explain the access from the campaign record alone. If they need outside knowledge to decide, the campaign is too broad or the entitlement data is too weak to trust.
Common mistake: Treating completion rate as success. A 100% completed campaign is not a strong control if most approvals were effectively defaults.
Practitioner takeaway: The threshold for redesign is not when reviewers complain, but when the campaign becomes too large for informed refusal as well as informed approval.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org