Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Certification Review
Governance, Ownership & Risk

Certification Review

← Back to Glossary
By NHI Mgmt Group Updated August 28, 2026 Domain: Governance, Ownership & Risk

A certification review is a formal access attestation process where a manager or resource owner confirms whether a user should keep specific access. It is a core identity governance control because it helps detect excess, stale, or inappropriate entitlements and supports timely revocation decisions with an auditable record.

Expanded Definition

Certification review is an identity governance control that asks a resource owner, manager, or delegated approver to confirm whether a user should retain specific access. In NHI environments, the same concept is often applied to service accounts, API keys, and agent-linked entitlements, although definitions vary across vendors and no single standard governs this yet. The operational goal is not simply approval, but documented accountability for continued access, especially where access paths are persistent or high impact.

Certification review differs from joiner-mover-leaver workflows because it is periodic and validation-oriented rather than event-driven. It also differs from technical privilege enforcement: a review identifies whether access should remain, while systems such as NIST Cybersecurity Framework 2.0 guide the broader governance and access control context that makes review outcomes actionable. In NHI programs, this matters when machine identities inherit permissions from human-managed processes or when ownership is unclear after application changes.

The most common misapplication is treating certification review as a checkbox exercise, which occurs when approvers lack usage context and simply reapprove stale access by default.

Examples and Use Cases

Implementing certification review rigorously often introduces administrative overhead and decision fatigue, requiring organisations to weigh faster operations against stronger access assurance.

  • A platform owner reviews quarterly access for a production service account and revokes permissions that are no longer needed after a deployment redesign.
  • A security team uses certification review to validate whether an AI agent still needs access to a secrets manager before its workflow is expanded.
  • An application owner confirms ownership of an API key after a team reorganisation, then updates the approver chain to reflect the new operating model.
  • An auditor samples completed reviews to verify that revocation decisions were documented and tied to an accountable approver.
  • A governance team compares certification outcomes with breach lessons from the Sisense breach and the broader guidance in Ultimate Guide to NHIs — What are Non-Human Identities to prioritise the accounts most likely to be overprivileged.

For review design, NIST Cybersecurity Framework 2.0 is useful for mapping governance responsibilities, while identity teams can apply the same process to both human and non-human access where ownership is clearly assigned.

Why It Matters in NHI Security

Certification review is one of the few controls that can surface access drift before it becomes an incident. It is especially important in NHI security because service accounts, integrations, and agent identities often accumulate privileges over time, and those entitlements are rarely challenged unless a review process forces explicit decisions. NHIMG reporting shows that 97% of NHIs carry excessive privileges, which means review outcomes directly affect the blast radius of compromised credentials and the feasibility of Zero Trust enforcement.

This control also creates an auditable record that supports incident response, compliance, and offboarding. If review cycles are too long, approvers lack system context, or ownership is ambiguous, stale access remains active and becomes part of the attack surface. That is why certification review should be paired with inventory accuracy, clear ownership, and timely remediation of denied items. Organisations typically encounter the business impact after an access-related incident or audit finding, at which point certification review becomes operationally unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-02Access review helps detect and remove overprivileged non-human identities.
NIST CSF 2.0PR.AC-4Certification review supports permission management and least-privilege enforcement.
NIST SP 800-63Identity assurance guidance informs how access decisions are authenticated and governed.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous validation of access rather than permanent trust.
OWASP Agentic AI Top 10Agentic systems need periodic checks on tool and data access as authority changes.

Use periodic reviews to validate access, document decisions, and remove unnecessary entitlements.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org