They usually fail where approvals, ownership, and evidence are split across different teams or tools. COSO assumes control components reinforce one another, so an access review without clear accountability or timely remediation becomes documentation, not control. IAM and NHI teams should look for gaps where one process exists in isolation and cannot prove who acted, why they acted, and what happened next.
Where COSO breaks down in identity governance
COSO control failures in identity governance are usually not caused by a missing policy. They happen when control design, execution, and evidence are split across different teams or tools, so no one owns the full control outcome. That is why an access review can look complete on paper while remediation, approvals, and audit evidence never converge into a single accountable control.
When that split exists, COSO’s interrelated control components stop reinforcing one another. The governance layer may define the rule, IAM may execute the task, and the business may approve access, but if those steps do not close the loop, the control is only a record of activity. Identity governance and administration works best when the control owner can show who decided, who implemented, and what changed.
That failure mode is especially common in programmes that treat access certification as an isolated event. Reviews without timely revocation, clear ownership, or follow-up evidence create the appearance of monitoring without the substance of control. In practice, the strongest signal is whether the review result actually changes entitlements, roles, or NHI access in a traceable way.
Why control ownership and evidence drift apart
COSO depends on control environment, risk assessment, control activities, information and communication, and monitoring moving together. In identity governance, those elements drift apart when approvers sit in the business, remediation sits in operations, and evidence sits in a separate GRC or ticketing workflow. The result is a fragmented control chain that may satisfy a document request but not demonstrate sustained control operation.
This is where teams often confuse completion with effectiveness. A reviewer can approve a certification campaign, but if the underlying access model is stale, the role owner is unclear, or the remediation ticket is never closed, the evidence describes intent rather than enforcement. IAM and IGA basics matter here because the control must link authorization, ownership, and lifecycle action into one accountable process.
For NHI-heavy environments, the same split appears when machine access is managed by one team and secrets or keys are managed by another. The control fails if ownership of the identity, the credential, and the review process are all different, because nobody can prove end-to-end remediation. NHI lifecycle management is the practical test: if the identity can be provisioned, reviewed, and deprovisioned by separate systems with no shared evidence trail, COSO assurance weakens fast.
What good control design looks like in practice
The control should be designed around a single accountable outcome, not separate administrative tasks. That means the approver, owner, reviewer, and remediator all understand which evidence proves the control worked, and the system records the handoff between each step. Access reviews and certification only become meaningful when they close the loop on removal, not when they merely generate a sign-off report.
Control design also has to handle segregation of duties and role ownership explicitly. If the same process lets one team approve access, another team implement it, and a third team attest to the result without a shared source of truth, then errors and exceptions will be hidden inside process boundaries. Segregation of duties is therefore not only a fraud-control concept, it is a way to keep identity governance from becoming self-certified paperwork.
In mature programmes, the strongest evidence is not the approval artifact itself, but the remediation trail. The control should show the original entitlement, the review decision, the implementation action, and the post-change state. That is why role design and ownership matter, because poorly managed roles create recurring exceptions that drown the review process in exceptions instead of decisions. Role mining and role design helps reduce that structural drift.
Risk and Threat Considerations
When approvals, ownership, and evidence are separated, the main risk is not just audit weakness, it is persistent excess access. Attackers and insiders benefit from controls that document review activity without enforcing timely removal, because stale permissions, shared accounts, and unmanaged non-human access can remain active long after they should have been revoked.
Failure mechanism: The control is approved in one workflow, remediated in another, and evidenced in a third, so no single owner can prove that access was actually removed or constrained. That gap creates opportunities for privilege creep, delayed offboarding, and hidden exceptions that survive repeated review cycles.
Impact: The programme can look compliant while the environment remains exposed, which increases the likelihood of unauthorized access, weak accountability, and failed audit support. Over time, repeated control fragmentation also makes it harder to detect whether a control failure is a one-off process miss or a systemic governance defect.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Identity governance needs auditable approval and remediation trails. |
| AC-2 — Account Management | Access reviews and removals are core to identity governance control operation. | |
| AU-6 — Audit Review, Analysis, and Reporting | COSO evidence fails when review results are not reconciled and acted on. | |
| Recommendation — Log access decisions and remediation actions in a retrievable audit trail. Enforce account lifecycle actions through defined account management controls. Review audit evidence for unresolved access decisions and closure gaps. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Identity governance failures often stem from weak access control ownership and enforcement. |
| A.5.18 — Access rights | The issue centers on proving access rights are approved, changed, and removed correctly. | |
| Recommendation — Assign and enforce access control responsibilities across the full lifecycle. Track, review, and revoke access rights with clear ownership and evidence. | ||
Practitioner Guidance
What to verify: Confirm that every access review has one named owner, one remediation path, and one evidence source that can show the final entitlement state, not just the decision. If any of those three sit in different tools with no reconciled record, treat the control as incomplete.
Decision rule: If a review campaign cannot prove who approved, who removed access, and when the removal took effect, downgrade the control to a monitoring activity and fix the workflow before relying on it for assurance. Do not accept “review completed” as equivalent to “control operating effectively.”
What practitioners underestimate: The biggest failure is usually not a missing control, but a control split across teams that each believe someone else owns closure. Identity security programme design should therefore make accountability, remediation, and evidence collection part of the same operating model.
Practitioner takeaway: COSO in identity governance fails when responsibility is distributed more widely than accountability, so the remedy is to make every access decision traceable from approval to removal to proof.
Related resources from NHI Mgmt Group
- Why do identity governance programmes often fail when teams keep too much in house?
- Why do identity and access governance programmes often fail to keep pace with enterprise risk?
- Where does partner identity governance fail most often in IAM programmes?
- Why is it important to integrate identity and data governance?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org