Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do compliance teams get wrong about periodic…
Governance, Ownership & Risk

What do compliance teams get wrong about periodic access certification in GLBA programs?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Governance, Ownership & Risk

A common mistake is treating access certification as an annual checkbox instead of a continuous governance process. That approach misses changes in role, privilege, usage, and business need over time. Teams also struggle when they review standard and privileged access in separate campaigns, or when they lack fine-grained visibility into who has edit or read access across different applications.

Why periodic certification breaks down in GLBA programs

Periodic access certification fails when teams treat it as a point-in-time attestation instead of a governance signal. In GLBA environments, that creates blind spots around role drift, privilege creep, dormant access, and exceptions that survive far past their business justification. The review is only useful when it reflects current entitlement reality, not last quarter’s org chart.

A second failure is fragmentation. If standard user access, privileged access, and application or service access are reviewed in different silos, reviewers often miss the combined risk picture. That is especially true when evidence is spread across multiple applications and the reviewer cannot see whether access is read-only, edit-capable, or able to change controls and records.

Periodic review also loses value when the underlying inventory is weak. If the team cannot reliably enumerate who has access, what type of access it is, and which business function depends on it, the certification becomes a formality. The control should validate necessity, not merely collect approvals.

What GLBA review teams need to verify, not just approve

The core question is whether access is still justified for the current role, process, and data sensitivity. Reviews should test for changes in job function, manager relationship, business ownership, and actual usage patterns. A signer who sees a name on a list but not the entitlement context is making a cosmetic decision, not a governance decision.

Teams should also verify that privileged access is separated from ordinary business access in the evidence set, but not isolated from it in the analysis. The reviewer needs to understand whether a user can simply view records, alter customer data, approve changes, or administer the system. That distinction matters because GLBA programs are protecting financial information, not just application logins.

When the certification scope includes broader access hygiene, the supporting control set should include discovery, ownership, and timely removal. NHIMG’s Ultimate Guide to NHIs and Lifecycle Processes for Managing NHIs are useful references for the governance pattern here, especially where machine, service, or application access is part of the entitlement estate. For broader programme context, Regulatory and Audit Perspectives shows how access review evidence fits compliance obligations.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0 and NIST SP 800-63 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v86 — Access Control ManagementPeriodic access certification is an access governance control concern.
Recommendation — Review and remove access that no longer matches business need or least-privilege requirements.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlAccess certification depends on current entitlement visibility and access enforcement.
GV.OV — OversightGLBA access certification is a governance oversight activity that needs recurring review.
Recommendation — Maintain accurate access records and enforce access decisions based on current role and need. Track certification outcomes and escalate unresolved access exceptions through governance oversight.
ISO/IEC 42001:2023A.3 — Internal organizationAccess review programmes need clear accountability and ownership to stay effective.
Recommendation — Assign clear ownership for access certification decisions and exception handling.
NIST SP 800-63IAL — Identity Assurance LevelReview quality depends on trustworthy identity records behind access decisions.
Recommendation — Use reliable identity assurance and evidence before approving access changes.

Practitioner Guidance

What to prioritise: Start by collapsing duplicated review streams into one evidence model that shows identity, role, entitlement, privilege level, and last-use context together. If a reviewer cannot see the access path end to end, the certification outcome will be unreliable even when every attestation is signed on time.

What to verify: Confirm that review samples include high-risk exceptions, dormant accounts, elevated roles, and access that spans multiple applications. If a user has edit authority in one system and read access in another, the real question is whether that combined access still matches the job, not whether each individual grant looks acceptable in isolation.

Common mistake: Treating annual certification as the control objective instead of the evidence checkpoint. In a healthy programme, certification should confirm that continuous access governance is working, and exceptions should trigger removal, re-approval, or escalation rather than being carried into the next cycle.

Practitioner takeaway: The best GLBA access review programmes are less about collecting approvals and more about proving that access is current, explainable, and removable when the business need changes.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org