Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What is the difference between human access reviews…
Governance, Ownership & Risk

What is the difference between human access reviews and NHI access reviews in PCI programmes?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Human reviews focus on role, business need, and employment status. NHI reviews must also cover credential type, technical dependency, rotation or expiry behaviour, and whether the identity is still required by the workload or integration that created it in the first place.

Why PCI access reviews must treat humans and NHIs differently

PCI programmes are not just checking whether access is still appropriate, they are checking whether the access path itself still makes sense. Human access can usually be judged against job function and employment status, but NHI access has to be reviewed against a live technical dependency, a credential form, and the way the workload or integration actually uses that identity.

That difference matters because a human may leave a role cleanly, while an NHI may still be embedded in a payment flow, batch job, API call, or certificate-based trust chain. The review must therefore confirm both who should have access and whether the consuming system still legitimately needs that identity to exist.

For PCI teams, the practical difference is that human reviews are primarily an entitlement governance exercise, while NHI reviews are also a dependency and lifecycle exercise. A human entitlement can often be removed once the business need ends; an NHI entitlement often cannot be removed until the underlying integration, rotation pattern, expiry state, or replacement path is understood.

What changes in the review criteria

Human reviews usually ask whether the person still has the right role, manager approval, and business justification. NHI reviews add questions that are specific to the credential and its operating context: what type of secret or certificate it is, whether it is long lived or ephemeral, whether it rotates automatically, and whether it has a hard expiry or renewal path.

The identity itself is only part of the control. For an NHI, you also need to know whether the workload, service, or integration still depends on it, whether there is a current owner, and whether the credential is shared across systems or reused in ways that make a simple approval check misleading. That is why the same review cadence produces different evidence for humans and NHIs.

In a PCI programme, the review outcome should be more specific for NHIs than for users. A valid conclusion is not only “approved” or “revoked”, but also “approved until the integration is retired”, “approved only if rotation remains automated”, or “revocation deferred until a replacement credential is live”.

How to structure the review so it is defensible

Strong PCI reviews separate ownership, entitlement, and dependency. For humans, ownership usually maps to the manager or application owner. For NHIs, ownership should map to the technical owner of the workload or integration, because that person can explain why the identity exists, what breaks if it is removed, and what compensating control exists if the credential is changed.

A review pack for NHIs should include the credential type, last rotation date, expiry or renewal behaviour, systems that call it, and whether the identity is bound to a specific environment. Where that information is missing, the review is weaker than it looks, because the approver is being asked to certify access without seeing the operational dependency behind it.

That is also why NHI reviews should be closed-loop. If a service account or API credential is no longer needed, the review should trigger retirement, not just a note in a spreadsheet. If it is still needed, the review should confirm the control that keeps it bounded, such as rotation, scope restriction, or an expiry mechanism tied to the workflow.

Risk and Threat Considerations

NHI reviews fail when teams treat credentials as static entitlements rather than active operational dependencies. That creates exposure to orphaned access, overprivileged integrations, and long-lived secrets that remain valid after the business or technical need has changed.

Failure mechanism: A reviewer approves the identity because the integration still exists, but does not verify whether the credential is still necessary, scoped correctly, or tied to a current owner. That allows stale NHIs, shared credentials, or dormant automation to remain in PCI environments long after their original purpose has ended.

Impact: The result is unnecessary payment-system exposure, harder incident scoping, and a larger blast radius if a machine credential is stolen or misused. In practice, the review becomes a paper control instead of a control that removes access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while PCI DSS v4.0 and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
PCI DSS v4.07.2 — Access Assignment and ManagementPCI reviews must confirm access remains appropriate and limited to business need.
8.6 — System and Application Accounts and Associated Authentication FactorsNHI reviews hinge on system account and credential handling, including lifecycle and authentication factors.
7.3 — Role-Based Access ControlHuman reviews in PCI commonly validate access against job role and role assignment.
Recommendation — Review each entitlement against current business need and remove access that is no longer justified. Track system and application accounts separately and verify their authentication factors, rotation, and continued necessity. Map human access to approved roles and recertify assignments when roles change.
NIST SP 800-53 Rev 5AC-2 — Account ManagementThe question concerns periodic review, ownership, and removal of human and non-human accounts.
IA-5 — Authenticator ManagementNHI reviews must assess credential type, rotation, and expiry behaviour.
AC-6 — Least PrivilegeBoth human and NHI reviews should test whether access is more permissive than the subject needs.
Recommendation — Recertify accounts on a defined cadence and revoke accounts that no longer have a valid business purpose. Verify authenticator lifecycle, rotation, and storage controls for each non-human identity. Reduce each identity to the minimum privileges needed for its current function.
ISO/IEC 27001:2022A.5.15 — Access controlThe question is about how access is reviewed and governed differently across identity types.
Recommendation — Define review rules that distinguish user access from system access and require periodic recertification.

Practitioner Guidance

What to verify: For human reviews, verify current role, manager attestation, and business need. For NHI reviews, verify the credential type, whether it rotates or expires, who owns the workload, and what dependency will fail if the identity is removed.

Decision rule: If the access is human, decisioning should centre on role and employment status. If the access is non-human, do not approve it unless the technical owner can explain why the identity is still needed and how its credential lifecycle is controlled.

What good looks like: The review outcome should leave you with a clean list of removed human access, a separate inventory of NHIs with explicit owners, and no unexplained long-lived credentials surviving simply because they were hard to classify.

Practitioner takeaway: In PCI programmes, human reviews are about entitlement legitimacy, but NHI reviews are about entitlement plus operational necessity; if you do not test the dependency, you are only certifying that a credential exists, not that it should.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org