Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Amortisation

← Back to Glossary
By NHI Mgmt Group Updated August 28, 2026 Domain: Governance, Ownership & Risk

Amortisation is the systematic spreading of a contract cost across the period it benefits the organisation. In software and SaaS management, it supports cleaner financial reporting and audit readiness by matching expense recognition to the contract term rather than booking the full cost in one period.

Expanded Definition

Amortisation is the disciplined allocation of a contract or licence cost over the period that the service delivers value. In NHI and SaaS governance, the term matters because many identity-related subscriptions, vault licences, and security platforms are purchased for multi-month or multi-year terms, then recognised incrementally rather than as a single upfront expense.

In practice, amortisation is a financial control, not an access control. It helps finance, procurement, and security operations keep reporting aligned with the actual benefit period, which is especially important when software supports service accounts, secrets management, or agentic workflows. Usage in the industry is fairly consistent in accounting, but implementation details vary across vendors and ERPs, so the operational model should be documented rather than assumed. For control context, the NIST Cybersecurity Framework 2.0 is relevant where spend, asset visibility, and governance evidence need to support resilience reporting.

The most common misapplication is treating amortisation as a generic budgeting label, which occurs when teams spread costs informally without tying recognition to the actual contract term.

Examples and Use Cases

Implementing amortisation rigorously often introduces accounting and procurement coordination overhead, requiring organisations to balance cleaner period reporting against faster purchasing and renewal decisions.

  • A security team buys a 24-month secrets management platform, and finance recognises the expense monthly so the cost matches the coverage period.
  • A procurement team amortises an enterprise licence for NHI discovery tooling across the subscription term, helping internal chargeback stay consistent.
  • An organisation renewing a privileged access platform uses amortisation schedules to show the remaining unrecognised cost during an audit review.
  • During a vendor transition, finance compares the remaining amortised balance of the old control stack against the new deployment timeline to avoid double-counting spend.
  • A governance team uses amortised cost views to explain why a partially used security contract still appears on the books after a mid-year architecture change.

For identity-heavy environments, cost visibility becomes more useful when paired with risk visibility. NHIMG notes that Ultimate Guide to NHIs shows how NHIs outnumber human identities by 25x to 50x in modern enterprises, which helps explain why recurring platform costs often need disciplined allocation. That same budgeting discipline complements broader control mapping in the NIST Cybersecurity Framework 2.0.

Why It Matters in NHI Security

Amortisation matters because NHI programmes often combine recurring software costs, contract renewals, and audit obligations. If those costs are misallocated, security leaders can misread the real cost of service account governance, secrets management, and rotation tooling, which weakens planning for the controls that actually reduce exposure. NHIMG research shows that 79% of organisations have experienced secrets leaks, with 77% of those incidents causing tangible damage, underscoring that identity tooling is not just an expense line but part of operational risk reduction. The same body of research also reports that 68% of organisations do not know how to fully address NHI risks, which makes transparent cost recognition useful when justifying remediation programmes.

Used well, amortisation helps demonstrate that security investments are sustained over the life of the control, not just at purchase time. It also improves audit readiness when teams need to show how spend maps to active protections, including the control lifecycle around service accounts and secret custody. See Ultimate Guide to NHIs for the operational context behind those risks. Organisations typically encounter the need to reconcile amortised security spend only after an audit, budget overrun, or control failure, at which point the term becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST AI RMF and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01Amortisation supports cost visibility tied to governance and operational objectives.
OWASP Non-Human Identity Top 10NHI-07Control investments in lifecycle management often rely on predictable contract recognition.
NIST AI RMFCost traceability helps govern AI-enabled identity tooling and its ongoing risk treatment.
NIST Zero Trust (SP 800-207)SC-7Funding recurring security controls supports continuous Zero Trust enforcement around identities.

Budget identity security controls as recurring protections, not one-time purchases, to sustain Zero Trust operations.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org