Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Annual Certification
Governance, Ownership & Risk

Annual Certification

← Back to Glossary
By NHI Mgmt Group Updated October 6, 2026 Domain: Governance, Ownership & Risk

Annual certification is the formal process of attesting that security controls meet regulatory requirements based on supporting evidence. For identity programmes, it depends on logs, policies, and access records that show authentication and entitlement controls were actually enforced throughout the year.

What Annual Certification Measures

Annual certification is not just a checkbox exercise. It is the formal evidence-backed attestation that controls were operating as required over a defined period, with emphasis on whether access, authentication, and entitlement decisions were actually enforced rather than merely documented.

For identity programmes, that means the certification has to be grounded in records that show who had access, when it changed, why it was approved, and whether the control owner could defend the outcome under audit. NHIMG’s IAM and IGA Basics is the clearest starting point for the control relationships that sit behind that evidence.

Why Annual Certification Exists

The purpose is assurance. Annual certification gives an organisation a structured way to confirm that control operation, evidence quality, and accountable ownership align with regulatory expectations and internal policy. It is especially important where access decisions have to be defensible months after the fact.

In practice, certification sits at the intersection of governance and control validation, because it asks not only whether a control exists, but whether it was applied consistently. That is why annual reviews often depend on access records, policy history, and exception handling, not just a manager’s signature.

What Evidence It Should Rely On

A credible certification is evidence-led. Logs, access review results, entitlement inventories, policy records, and remediation history should collectively show that the relevant controls were working throughout the year and that exceptions were identified and handled.

Where entitlement review is part of the process, the strongest evidence is usually closed-loop rather than static. NHIMG’s Access Reviews and Certification Guide explains how certification becomes more reliable when reviews remove access, capture context, and confirm remediation.

For programmes that include machine, service, or automation accounts, evidence should also show lifecycle control, ownership, and rotation discipline. NHIMG’s NHI Lifecycle Management Guide is useful where the annual attestation has to cover non-human accounts and their ongoing governance.

How Annual Certification Supports Governance

Annual certification is ultimately a governance mechanism, not just a reporting milestone. It supports accountability by forcing a named owner to stand behind the current state of controls, access, and exceptions at a point in time.

That governance role becomes more important as scope expands from individual users to roles, service accounts, and other non-human actors. NHIMG’s IGA Buyer's Guide is relevant because certification depends on the surrounding identity governance process, including reviews, connectors, and ownership.

Risk and Threat Considerations

Annual certification can fail quietly when it becomes a rubber-stamping exercise. The main risk is false assurance: a control may appear compliant on paper while stale access, excessive privilege, or undocumented exceptions persist in the environment.

Failure mechanism: weak evidence, broad reviewer scope, or poor ownership can allow dormant access, overprivileged accounts, and unremediated exceptions to survive the review cycle undetected.

Impact: the organisation may carry hidden exposure into the next audit period, including unauthorized access, privilege creep, and a weaker position if an incident or regulatory challenge later asks for proof of control effectiveness.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5CA-2 — Control AssessmentsAnnual certification is an assessment of control effectiveness and evidence
AC-2 — Account ManagementCertification commonly validates account and entitlement ownership over time
IA-5 — Authenticator ManagementCertification may need evidence that authenticators and related access material were controlled
Recommendation — Use CA-2 to assess whether controls operated effectively and retain evidence for certification. Use AC-2 to review and remove unauthorized or stale accounts during certification. Use IA-5 to verify authenticator lifecycle controls during annual certification.
ISO/IEC 27001:2022A.5.36 — Compliance with policies, rules and standards for information securityAnnual certification attests that required security policies and controls were followed
A.8.15 — LoggingCertification for identity programmes depends on logs that evidence access enforcement
Recommendation — Use A.5.36 to confirm that policies and security rules were observed throughout the certification period. Use A.8.15 to retain logs that prove access and authentication controls were operating.
NIST CSF 2.0GV.OV-01 — Oversight of Cybersecurity Risk ManagementAnnual certification is an oversight activity that checks control performance and accountability
PR.AA-05 — AuthorizationCertification often validates that access entitlements matched approved authorization
ID.AM-01 — Physical devices and systems within the organization are inventoriedCertification depends on knowing the assets and identities covered by the review population
Recommendation — Use GV.OV-01 to oversee control evidence and confirm certification reflects actual control operation. Use PR.AA-05 to verify that access was authorized and remained appropriate over time. Use ID.AM-01 to maintain an accurate inventory of assets and identities in scope for certification.

Practitioner Guidance

What to watch for: treat certification quality as the issue, not just certification completion. Reviews that lack context, ignore non-human accounts, or fail to track remediation usually indicate that the process is measuring activity rather than control effectiveness.

Practitioner takeaway: the annual sign-off should prove that access and entitlement controls were enforced, reviewed, and remediated, not merely that someone acknowledged them once a year.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org