Because access changes continuously and audit standards expect periodic proof that controls still operate. A single certification cannot demonstrate ongoing appropriateness when users move roles, leave, or accumulate permissions. Recertification gives auditors evidence that the programme is checking current access, documenting changes, and remediating violations on a repeated basis.
Why recertification exists after the first approval
Initial approval only answers whether access was justified at one point in time. Recertification answers a different question: does that access still fit the person, role, and business need today? That distinction matters because entitlements drift as jobs, projects, vendors, and systems change, and because audit evidence must show an access control is operating over time, not just at onboarding.
In practice, recertification closes the gap between identity governance basics and actual access hygiene. A role that made sense at creation can become excessive after a move, promotion, leave of absence, or project exit. Periodic review creates a controlled opportunity to confirm ownership, challenge stale exceptions, and remove access that no longer matches the current business state.
That is why many programmes treat recertification as part of the control, not an administrative follow-up. It produces dated evidence that approvals, entitlements, and exceptions are being revalidated, which is especially important where access can accumulate silently over time. The control is less about repeating paperwork and more about proving that access decisions remain current, accountable, and reversible.
What auditors and compliance teams are actually testing
Compliance teams are usually not looking for a one-time sign-off. They want to see that the organisation can demonstrate periodic review, remediation, and traceability. Recertification shows who reviewed the access, what was approved or removed, when the review occurred, and whether exceptions were accepted with a real owner.
That maps directly to access reviews and certification because the objective is not just to ask for approval again, but to create a repeatable governance loop. A strong process includes evidence of scope, reviewer assignment, remediation closure, and follow-through on overdue items. Without that loop, an organisation may have good initial provisioning but poor ongoing control.
In mature programmes, the most important evidence is not the email or workflow alone. It is the combination of review cadence, exception handling, and removal of access that no longer has a current business justification. That is what proves the control is operating, rather than existing only as a policy statement.
The same logic is reinforced by joiner, mover and leaver processes, because people and machines do not stay static after initial approval. Access review catches the cases where the lifecycle event happened but the entitlement did not get cleaned up, which is one of the main reasons auditors ask for recurring certification in the first place.
How recertification reduces access creep and weak accountability
Recertification is also a practical defence against access creep. Over time, users accumulate permissions from temporary projects, emergency access, inherited roles, or manual exceptions. If those grants are never revisited, the organisation ends up with standing access that outlives the original need and weakens least privilege.
That is why a governance view of recertification usually focuses on the relationship between role, entitlement, and business need. Role design and role mining matter here because recertification is easier to trust when the role model is clear and reviewers can tell what access should exist by default. If the role structure is messy, reviewers tend to rubber-stamp rather than challenge.
For organisations with segregation requirements, recurring review is even more important. Segregation of duties checks are not a one-time design exercise if access changes continuously. Recertification is one of the few practical ways to keep toxic combinations, compensating controls, and approved exceptions visible as the environment evolves.
When teams skip recertification and rely on initial approval only, accountability becomes weak fast. Nobody can easily prove who still needs what, who accepted the exception, or whether the approval still reflects the current operating model. That is exactly the kind of gap auditors and internal control teams are trying to avoid.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CSA Cloud Controls Matrix, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Recertification is an IAM governance control over access review and removal. |
| Recommendation — Review IAM entitlements on a recurring basis and remove access that no longer has a current business need. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Recurring certification supports account review, authorization and removal of stale access. |
| AC-6 — Least Privilege | Recertification helps prevent permission accumulation beyond current job need. | |
| IA-5 — Authenticator Management | Access recertification often exposes stale credentials and lifecycle gaps tied to active accounts. | |
| Recommendation — Require periodic account review and disable or remove accounts that no longer need access. Revalidate privileges regularly and reduce any access that exceeds current least-privilege needs. Track authenticators through their lifecycle and revoke stale or unused credentials promptly. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Periodic review of access rights is directly relevant to recertification and approval freshness. |
| Recommendation — Review access rights at planned intervals and revoke rights that are no longer justified. | ||
| CIS Controls v8 | CIS-5 — Account Management | Recurring certification is a core account management safeguard against access creep. |
| Recommendation — Audit accounts regularly and remove unnecessary access as part of account lifecycle control. | ||
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | Recurring access review supports SOC 2 assurance over logical access governance. |
| Recommendation — Operate recurring access reviews and document evidence that access remains appropriate. | ||
Practitioner Guidance
What to prioritise: Prioritise review frequency and reviewer quality before you obsess over campaign volume. A smaller, risk-based recertification cycle that removes real excess access is more defensible than a broad campaign that produces rubber-stamped approvals.
What to verify: Verify that each review has a named owner, a clear scope, and a remediation path. If the reviewer cannot distinguish current business need from inherited access, the certification result is weak even if it was completed on time.
Common mistake: The usual failure is treating recertification as a compliance calendar event. That creates paperwork without control value, especially when movers, contractors, and privileged access are allowed to age out without prompt removal.
Practitioner takeaway: Initial approval establishes intent, but recertification proves ongoing legitimacy. If your process cannot remove access that no longer belongs, it is not a control, it is only a record.
Related resources from NHI Mgmt Group
- How should security teams govern non-human identities for compliance?
- How should security teams govern non-human identities for SOC 2 compliance?
- When should teams require a digital signature certificate instead of relying on scanned signatures or email approval?
- How should security teams prioritise NHI remediation in cloud environments?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org