They prove that controls exist and have been assessed, but they do not prove that identity access, telemetry, and revocation still work correctly in live environments. The failure is assuming attestation equals operational resilience. Identity teams still need to test entitlement drift, audit completeness, and offboarding effectiveness in production.
Why Attestation Does Not Prove Live Identity Security
ISO 27001 and SOC 2 are evidence that a control environment exists, has been defined, and has been assessed against a standard or trust criterion. They are not evidence that identity access still behaves correctly after configuration drift, staffing changes, vendor changes, or incident response. For that, teams need production validation of access paths, logs, and revocation behavior, not just audit-ready paperwork.
A useful way to think about the gap is that attestation is historical and bounded, while identity failure is often operational and continuous. A report can show that access control, logging, and offboarding were designed and sampled; it cannot by itself prove that entitlements are still accurate, telemetry still captures every administrative action, or deprovisioning still closes all access paths in the current environment.
That distinction matters most in live identity systems, where small mismatches create real exposure. If joiner-mover-leaver flows lag, privileged access is not fully removed, or service credentials outlive their intended use, the organisation can remain “compliant” on paper while still being one missed rotation, one orphaned account, or one incomplete audit trail away from an exposure.
What Identity Teams Must Validate Beyond the Certificate
The operational questions are narrower and more demanding than the audit question. Teams should test whether access reviews actually remove stale entitlements, whether offboarding revokes every active session and token, and whether logs are complete enough to reconstruct who did what, when, and from where. NHIMG’s NHI Lifecycle Management Guide is useful here because the same lifecycle failure modes, provisioning, rotation, and offboarding, are where assurance often diverges from reality.
It also helps to separate control existence from control effectiveness. A control can be described in policy, but still fail under scale, exception handling, or cross-system dependencies. That is why entitlement drift, dormant access, and incomplete revocation need recurring production checks rather than annual evidence collection alone.
For teams mapping where the risk concentrates, the most useful lens is not “Did we pass audit?” but “Can we prove the identity control works against current systems and current accounts?” NHIMG’s Identity Security Programme Guide and Identity Security Posture Management (ISPM) Guide both support that operational view, especially where governance needs to be tied to measurable drift, not static documentation.
How to Read ISO 27001 and SOC 2 Without Overstating Them
These frameworks are still valuable, just for a different purpose. They tell you that a provider or internal function has operating controls, governance, and review discipline. They do not certify that every identity edge case has been exercised, that every integration revokes access reliably, or that telemetry remains complete when systems fail, accounts are merged, or administrators bypass standard workflows.
That is why auditors, security leaders, and identity engineers should treat attestation as an input to assurance, not the assurance itself. If a control is critical to preventing account takeover, privilege persistence, or undetected access, it needs direct evidence from logs, test accounts, revocation drills, and sampled production validation. NHIMG’s Identity Security Regulatory Map is a practical reminder that compliance obligations often overlap with identity controls, but overlap is not proof of live effectiveness.
When teams need to explain the boundary cleanly, the simplest statement is this: certification can tell you that the control exists; it cannot tell you whether the control is currently working on the identities and systems that matter most.
Risk and Threat Considerations
Over-relying on ISO 27001 or SOC 2 as evidence of identity security creates a blind spot in exactly the areas attackers and operational failures exploit: stale access, incomplete revocation, weak telemetry, and privilege that outlives its business need. The risk is not the certificate itself, but the false conclusion that audited design guarantees current control effectiveness.
Failure mechanism: configuration drift, exception paths, integration gaps, and offboarding delays can leave active access in place even when the control environment looks sound in review evidence. An attacker or insider benefits when a provisioned account, token, or entitlement remains usable after the business believes it has been removed.
Impact: the organisation can miss account takeover, unauthorized privilege retention, and audit-trail gaps until after data exposure, fraud, or lateral movement has already occurred. In practice, the failure shows up as unrevoked access, incomplete logs, or identity records that no longer match the real state of production.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 and SOC 2 (AICPA) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access control is central to the gap between attested controls and live identity security. |
| A.8.2 — Privileged access rights | Privileged access is where stale or excessive permissions most often defeat audit assurance. | |
| Recommendation — Validate that access rules still enforce current production entitlements and revocation. Review privileged access continuously and confirm removals take effect in production. | ||
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | SOC 2 access criteria are relevant because the question asks about over-reading attestation as identity proof. |
| CC7.2 — Monitoring for security events | Monitoring completeness determines whether identity failures are actually visible in live systems. | |
| Recommendation — Use operating evidence to confirm logical access controls still function as designed. Verify that identity events are logged and monitored in production, not just documented. | ||
Practitioner Guidance
What to verify: test the controls that prove identity security is live, not merely documented. Prioritise entitlement recertification outcomes, offboarding completion, session and token revocation, and whether the audit trail can reconstruct administrative actions without gaps.
Decision rule: if the evidence comes only from policy, screenshots, or periodic audit samples, treat it as assurance of design, not assurance of operational resilience. If the control protects production access, require a production test or monitored drill before you rely on it.
Common mistake: teams often use certification status as a proxy for current identity hygiene. That shortcut is especially risky where access spans multiple systems, because a single missed revocation can survive long after the audit evidence was collected.
Practitioner takeaway: the right question is not whether the control was audited, but whether it still works against today’s identities, today’s systems, and today’s revocation paths.
Related resources from NHI Mgmt Group
- How should security teams govern non-human identities for ISO 27001?
- How should security teams use ISO 27001 and SOC 2 when evaluating cloud identity providers?
- How should security teams govern non-human identities for SOC 2 compliance?
- What breaks when identity governance is treated as admin work instead of security work?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org