Identity lifecycle management controls the full journey of an identity, from creation through modification and removal. Access certification reviews focus on checking whether existing entitlements are still justified and revoking access that is no longer needed. Lifecycle management prevents accumulation, while certification reviews clean up drift. Both are needed because one governs change and the other validates current access.
Where identity lifecycle management starts and ends
Identity lifecycle management is the upstream control plane for an identity’s existence. It covers how the identity is created, named, approved, changed, suspended, and ultimately removed, so the organisation can keep ownership, status, and authority in sync with the real-world role or system it represents. In practice, it is about preventing stale identities and unmanaged changes from accumulating over time.
That makes lifecycle management broader than periodic review. It usually touches onboarding, transfers, role changes, deprovisioning, expiration, credential issuance, and ownership updates. When it is done well, the access state follows the lifecycle event automatically or through a defined workflow, rather than depending on a later manual cleanup exercise.
The strongest lifecycle programmes also need visibility into what exists, because you cannot govern what you cannot enumerate. NHIMG’s Ultimate Guide to NHIs, Lifecycle Processes for Managing NHIs is a useful reference point for the lifecycle side of the problem, especially where provisioning and offboarding must be kept tightly controlled.
What access certification reviews are designed to prove
Access certification reviews, sometimes called access recertification or attestation, are a validation mechanism rather than a lifecycle mechanism. Their job is to test whether existing access is still justified at a point in time, based on current business need, ownership, and privilege level. The review does not create the entitlement; it challenges whether the entitlement should still remain.
That distinction matters because certification is inherently retrospective and periodic. A review can remove access that has drifted beyond need, but it does not by itself prevent future over-assignment, and it does not replace joiner-mover-leaver controls. If the baseline provisioning process is weak, certification may expose the problem, but it will not stop the same pattern from reappearing in the next cycle.
For readers looking at the governance angle, NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives aligns closely with the evidence and audit expectations that usually drive review programmes, while the broad lifecycle guide helps distinguish certification from entitlement administration.
How the two controls work together in practice
The cleanest way to think about the difference is this: lifecycle management governs change, certification reviews validate current state. Lifecycle controls answer “should this identity exist, and what should it be allowed to do as its status changes?” Certification reviews answer “does this access still need to exist right now?” Those are complementary questions, not competing ones.
A mature programme uses both because each closes a different failure mode. Lifecycle management reduces the creation of unnecessary access in the first place, while certification helps catch residual excess, inherited permissions, and organisational drift. Where both are missing, access tends to persist far longer than intended, especially when identities are numerous, ownership is unclear, or the environment changes faster than manual administration can keep up.
From a lifecycle perspective, the evidence of control is clean provisioning and prompt removal when the identity changes state. From a certification perspective, the evidence is documented review decisions, timely revocation, and defensible exceptions for the access that remains.
Risk and Threat Considerations
The main risk is treating certification as a substitute for lifecycle control, or treating lifecycle automation as if it eliminates the need for review. In both cases, excess access can persist, and stale entitlements become easier to exploit, especially when ownership is unclear or the review cadence is too slow for the rate of change.
Failure mechanism: Identities are created or modified without tight upstream governance, then retain rights after the business need changes. Reviews may eventually remove some access, but the window between drift and cleanup is enough for misuse, lateral movement, or policy violations to occur.
Impact: Organisations get accumulation from weak lifecycle handling and delayed cleanup from weak certification, which increases the chance of excessive privilege, audit findings, and avoidable exposure from dormant or unjustified access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | 6 — Access Control Management | Lifecycle and certification both depend on disciplined account and entitlement management. |
| 8 — Audit Log Management | Certification reviews rely on evidence of who approved, changed, and revoked access. | |
| Recommendation — Enforce account ownership, least privilege, and timely removal of unused access. Log access changes and review outcomes so recertification decisions are auditable. | ||
| NIST CSF 2.0 | PR.AC — Access Control | The question contrasts ongoing access governance with periodic entitlement validation. |
| GV.RM — Risk Management Strategy | Choosing both controls reflects a governance decision about residual access risk. | |
| Recommendation — Apply access control governance to provision, review, and revoke access consistently. Set a governance cadence that combines lifecycle controls with recurring access attestation. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Identity Lifecycle and Ownership | Identity lifecycle management is central to preventing unmanaged, stale non-human identities. |
| NHI-02 — Secrets and Credential Management | Lifecycle and review decisions often hinge on removing or revalidating credential-bearing access. | |
| NHI-07 — Access Review and Least Privilege | Access certification reviews directly test whether entitlements remain justified. | |
| Recommendation — Define ownership, provisioning, and offboarding triggers for every identity. Rotate or revoke credentials when identity state or access justification changes. Recertify entitlements regularly and remove access that lacks current business need. | ||
Practitioner Guidance
What to prioritise: Use lifecycle management for state changes, and use certification reviews for periodic verification. If you have to choose where to strengthen first, fix provisioning and deprovisioning paths before adding more review cycles, because reviews cannot reliably compensate for broken joiner-mover-leaver controls.
What to verify: Check that every entitlement has an owner, a clear business justification, and a defined removal trigger. If a review process exists but the system cannot cleanly remove access after approval, the control is only partially effective.
Practitioner takeaway: Lifecycle management prevents access from becoming stale in the first place, while certification reviews prove that current access still deserves to exist, so mature programmes need both.
Related resources from NHI Mgmt Group
- What is the difference between runtime protection and NHI lifecycle management?
- What is the difference between access reviews and identity posture management?
- What is the difference between access modelling and lifecycle management in identity security programmes?
- What is the difference between privileged access management and identity lifecycle management in cloud security?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 18, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org