Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who is accountable when contractor access is not…
Governance, Ownership & Risk

Who is accountable when contractor access is not revoked on time?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Governance, Ownership & Risk

Accountability should rest with the organisation that owns the access process, not the contractor. Security, identity, and business approvers each need clear responsibility for granting, reviewing, and removing access. If revocation is delayed, the control failure is usually a governance problem as much as an operational one, because no one owned the full lifecycle.

Why This Matters for Security Teams

Delayed contractor offboarding is not just an HR cleanup issue. It is a control failure across identity, access governance, and business ownership. When contractor access remains active after the work ends, the organisation is still accountable for whatever those credentials can reach, especially if the access includes privileged NHI or shared tooling. NHI Mgmt Group notes that only 20% of organisations have formal processes for offboarding and revoking API keys, which is why revocation failures are so common.

The practical risk is that access often spans systems that no single team watches end to end. Security may provision controls, IT may execute removals, and the business may approve the engagement, but no one tracks the full lifecycle. That gap becomes dangerous when the contractor had access to secrets, CI/CD systems, or production tooling. Guidance in the OWASP Non-Human Identity Top 10 and Ultimate Guide to NHIs both point to lifecycle control as a core defence, not an afterthought.

In practice, many security teams discover the gap only after a contractor account is reused, a secret is leaked, or an audit asks who owned the deprovisioning step.

How It Works in Practice

Accountability should be assigned to the organisation function that owns the access lifecycle, but operational responsibility is usually shared. A sound model separates three duties: the business owner approves the need, identity or IT executes the removal, and security defines the control and verifies completion. For contractor access, that means revocation should be triggered by a formal offboarding event, not by memory, email, or a calendar reminder.

For NHI-related access, current guidance suggests treating credentials as assets with explicit expiry, review, and revocation steps. The NHI Lifecycle Management Guide and Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs emphasise that lifecycle ownership matters as much as initial issuance. In practice, this means:

  • Defining a named access owner for every contractor account, token, API key, or service credential.
  • Using JIT or time-bound access where possible so access expires automatically if offboarding is delayed.
  • Recording revocation SLAs, approval timestamps, and evidence of completion for audits.
  • Linking identity systems, ticketing, and HR or vendor management so termination events trigger deprovisioning.
  • Validating that secrets, not just user accounts, are rotated or invalidated after access ends.

Security should also map the control to baseline expectations in NIST SP 800-53 Rev. 5, especially where access enforcement, account management, and auditability intersect. These controls tend to break down when contractor access is provisioned outside the normal IAM workflow because no system generates the revocation trigger.

Common Variations and Edge Cases

Tighter offboarding controls often increase administrative overhead, so organisations have to balance speed against assurance. That tradeoff becomes sharper when contractors support production, incident response, or multi-vendor environments where access is intentionally broad and time pressure is high. Best practice is evolving, but the direction is clear: make access short-lived by default and make exceptions explicit.

There is no universal standard for who must sign off in every case. In some organisations, the hiring manager owns contractor exit coordination; in others, platform security or IAM operations owns final revocation; in regulated environments, the control owner may also need compliance sign-off. What matters is that the accountability chain is written down and testable. The Top 10 NHI Issues and Guide to the Secret Sprawl Challenge both highlight how unfinished lifecycle work leaves standing access behind.

Edge cases also matter. Third-party contractors may keep access to shared vaults, CI/CD runners, or delegated admin tools long after their contract ends. If those credentials are embedded in scripts or shared repositories, revoking only the human account does not solve the problem. In those environments, accountability must extend to secret rotation, key invalidation, and evidence that downstream tokens were also removed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-06Covers offboarding and lifecycle revocation for non-human access.
NIST CSF 2.0PR.AC-1Access provisioning and removal must be traceable to accountable owners.
NIST AI RMFGOVERNAccountability for autonomous or delegated access requires explicit governance.
CSA MAESTROLifecycle controls and trust boundaries matter for delegated agent and contractor access.

Assign an owner for every contractor credential and prove revocation on termination.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org