Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why does automated access review still fail if…
Governance, Ownership & Risk

Why does automated access review still fail if approvals do not change live permissions?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Because certification only proves that someone looked at access, not that the access state was corrected. If review results stay in a report while the entitlement remains active, the organisation gets audit evidence without risk reduction. The live permission state must change or the review has no governance value.

Why certification can fail when it does not touch the live entitlement

access review only has governance value when the review outcome changes the authoritative permission state. If reviewers approve, reject, or comment, but the entitlement stays active in the target system, the process produces evidence without correction. That leaves the organisation with a paper trail, not risk reduction, because the exposure remains exactly where it was.

In practice, the failure is usually a workflow design problem. The review campaign is separated from remediation, so the approval record is treated as the finish line instead of the trigger for change. A proper closed-loop design connects certification to provisioning, deprovisioning, or privilege adjustment so the entitlement state matches the decision.

Why “looked at” is not the same as “fixed”

Certification is an assurance control, not a control outcome by itself. It tells you that an owner or manager acknowledged the access, but it does not prove the access was removed, reduced, or re-scoped. If the live system is not updated, stale access, excess privilege, and orphaned entitlements continue to exist after the review closes.

That gap matters even more when access is recertified on a schedule. Repeating a review campaign against unchanged entitlements can create confidence that the estate is being governed, while the actual blast radius stays untouched. For that reason, the question is not whether the review was completed, but whether the entitlement state changed because of it.

What closes the loop on access governance

The control needs an explicit handoff from certification to enforcement. The approval result should either update the entitlement automatically or raise a tracked remediation task with ownership, due date, and verification. In other words, the review must be connected to the system that grants access, not just the reporting layer that describes it.

For machine, service, and other non-human access, that connection is especially important because the same identity can be reused across systems and environments. If a review flags excessive privilege but nothing revokes the credential, key, token, or role, the risky access remains usable. Access Reviews and Certification Guide is useful here because it focuses on closed-loop remediation rather than review activity alone. IAM and IGA Basics helps frame why access review is part of a broader governance lifecycle, not a standalone event.

Risk and Threat Considerations

When approval does not change live permissions, the organisation gets false assurance. Attackers, insiders, and simple operational drift all benefit from the same failure mode: the review says “approved” or “resolved,” but the access path remains open.

Failure mechanism: The certification workflow records a decision in one system while the entitlement remains active in another, so review outcomes do not propagate to the authoritative access control point.

Impact: Excess privilege, stale access, and compromised accounts continue to be usable, which preserves exposure, weakens audit defensibility, and can support later abuse of the same entitlement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Improper OffboardingStale access that stays active after review is a lifecycle failure.
NHI-05 — Overprivileged NHIReviews that do not reduce live permissions leave excess privilege intact.
Recommendation — Tie certification outcomes to deprovisioning so removed access actually disappears. Reduce standing privilege when a review identifies excessive access.
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccount changes and revocation must follow access decisions to be effective.
AU-6 — Audit Record Review, Analysis, and ReportingAudit evidence only helps if it reflects corrected access state.
Recommendation — Automate account and entitlement updates when review decisions require removal. Use audit outputs to confirm review actions were executed, not just recorded.
ISO/IEC 27001:2022A.5.18 — Access rightsAccess rights must be reviewed and updated when governance decisions change them.
Recommendation — Revoke or adjust access rights after each completed certification decision.

Practitioner Guidance

What to verify: Test a sample of review outcomes end to end. For every revoked or reduced entitlement, confirm the live permission, group membership, role assignment, token scope, or credential state actually changed in the target system.

Common mistake: Treating “review completed” as evidence of control effectiveness. A completed certification campaign is only a control input unless you can show the entitlement was corrected and the correction was verified.

Practitioner takeaway: If the review does not force a state change, it is governance theatre. The control only becomes meaningful when the approval result updates the live access model and you can prove that it did.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org