Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who should be accountable when identity security findings…
Governance, Ownership & Risk

Who should be accountable when identity security findings are repeatedly marked as won’t fix?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 20, 2026 Domain: Governance, Ownership & Risk

Accountability should sit with the product and security leadership that decides whether a finding is accepted, remediated, or deferred. Repeated won’t fix decisions need governance, because they are not technical neutral acts. They shape exposure, customer trust, and regulatory risk. If the issue affects privileged identity paths, accountable owners should document the rationale and track compensating controls until closure.

Who Owns a Repeated Won’t Fix Decision

Repeated won’t fix findings should not float between teams without explicit ownership. The accountable party is the leader who can accept the risk, fund the fix, or approve the exception, usually product leadership in partnership with security leadership. If the finding affects overprivileged or poorly governed identity paths, that owner must treat the decision as a control choice, not a backlog preference.

Accountability matters because a won’t fix is a durable posture decision. It says the organisation has chosen to live with the exposure for now, so the decision needs a named owner, a review cadence, and a documented rationale that survives personnel changes. Without that, the same unresolved finding can be repeatedly rediscovered without any real governance movement.

Where the issue touches identity governance, the ownership question is broader than the ticket. You are accountable for the exposure created by credential lifecycle, visibility, and access governance, not just for closing an individual report. That includes deciding whether the finding should be fixed, accepted with conditions, or escalated because it affects privileged access paths.

What Repeated Deferrals Mean for Security and Governance

When the same identity finding keeps returning, the organisation is usually signalling one of three things: the risk is underestimated, the remediation path is blocked, or leadership has tacitly accepted the exposure without formal review. Any of those outcomes can widen customer, operational, and regulatory risk, especially when the issue involves secrets, service accounts, or privileged access.

Repeated deferral also weakens assurance. If a team can mark a finding won’t fix indefinitely, then the control is not really closed, it is only parked. That creates a gap between what the security programme reports and what the environment actually allows, which is why these decisions need governance instead of informal consensus.

For identity-heavy environments, the practical danger is that unresolved findings often sit on the same paths attackers prize: standing privilege, stale credentials, weak rotation, or poor inventory. NHIMG’s key NHI risk summary is useful here because it frames the underlying exposure pattern, while the OWASP Non-Human Identity Top 10 reinforces that overprivilege and secret sprawl are not cosmetic issues, they are common failure modes.

Risk and Threat Considerations

Repeated won’t fix decisions create a governance risk because they normalise unresolved exposure. If the finding involves identity security, the risk becomes operationally material quickly, since stale access, excessive privilege, or unmanaged secrets can persist long enough for misuse, lateral movement, or unauthorised access to occur.

Failure mechanism: The organisation treats a recurring security issue as an exception without tightening the approval path, so the same weakness remains in place, and the control owner loses visibility into whether compensating measures still exist or still work.

Impact: Exposure compounds over time. A repeated won’t fix on identity findings can preserve high-risk access paths, reduce trust in remediation reporting, and leave the business carrying unresolved customer, audit, and regulatory consequences.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-03 — Overprivileged Non-Human IdentitiesRepeated won’t fix on identity findings often preserves excessive access paths.
NHI-05 — Secret Sprawl and Credential HygieneWon’t fix findings often leave stale secrets or unmanaged credentials in place.
NHI-08 — Visibility, Inventory, and OwnershipRepeated deferrals fail when no owner can explain or close the exposure.
Recommendation — Reduce standing privilege and reapprove any accepted exception on a fixed review cycle. Track unresolved secret findings to expiry and rotate exposed credentials before accepting risk. Assign a named owner for every unresolved identity finding and keep the exception register current.
NIST CSF 2.0GV.RM-01 — Risk Management StrategyRepeated won’t fix decisions require explicit risk acceptance and oversight.
ID.IM-01 — Improvements Are Identified and PrioritisedA recurring won’t fix finding shows that remediation priorities and blockers are not being governed.
PR.AA-02 — Identity Management, Authentication, and Access ControlIdentity security findings affect access paths, privilege, and control effectiveness.
Recommendation — Document who accepts the risk, why it is accepted, and when it must be reviewed again. Use recurring findings as input to remediation prioritisation and leadership review. Validate that accepted identity exceptions do not leave unauthorised access paths or standing privilege.
CIS Controls v86.3 — Require MFA for Externally-Exposed ApplicationsIdentity findings often involve access paths that need stronger control if left unresolved.
5.3 — Account MaintenanceRepeated deferrals can leave stale accounts and access paths active.
Recommendation — Escalate unresolved access findings when compensating controls depend on weaker authentication. Review unresolved account findings on a fixed cadence and remove or justify access promptly.
NIST SP 800-635.2.5 — Authenticators and VerifiersIf the finding concerns identity assurance or authenticator handling, the acceptance decision affects trust in authentication.
Recommendation — Reassess authenticator strength before accepting recurring identity exceptions.

Practitioner Guidance

What to prioritise: Assign a single accountable owner who can approve risk acceptance, not just a ticket resolver. If the finding affects privileged identity paths, require a named business owner and a security owner to sign off on the same decision.

What to verify: Confirm that each won’t fix has a current rationale, an expiry or review date, and a compensating control that is actually operating. If any of those are missing, the decision is effectively unmanaged and should be escalated.

Decision rule: If the finding can enable unauthorised access, privilege abuse, or secret reuse, treat it as a governance exception with time bounds. If it cannot be time-bounded or measured, it should not be considered an acceptable permanent state.

Practitioner takeaway: The main risk is not that a finding remains open, it is that repeated won’t fix decisions become invisible policy by habit. Accountability must sit with the leader who is consciously accepting the exposure and willing to defend that choice later.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 20, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org