The process of identifying, validating, and assigning accountability for service accounts, tokens, keys, and other machine identities before an acquisition is completed. In M&A, it extends beyond inventory to ownership transfer, lifecycle control, and proof that inherited access can be revoked or rotated safely.
What Non-Human Identity Due Diligence Covers
Non-human identity due diligence is the pre-close assessment of the machine identities a business will inherit, including what they are, who owns them, how they authenticate, and whether they can be safely transferred, rotated, or revoked after acquisition.
It is broader than a simple inventory. The due diligence question is not just “what exists,” but “what access does it carry, how durable is that access, and what would break if the seller’s environment disappeared on close?”
In practice, that means service accounts, API keys, OAuth tokens, certificates, workload identities, automation accounts, and related secrets all need to be treated as part of the target’s operational perimeter. NHIMG’s Ultimate Guide to NHIs is useful background for the identity types and lifecycle issues that typically show up in this review.
Why This Matters in M&A
M&A often compresses years of weak identity hygiene into a short integration window. A target may have orphaned service accounts, shared credentials, hardcoded secrets, stale tokens, or certificates that continue to work long after the teams that created them have changed.
That creates a hidden continuity problem: inherited access can survive the transaction unless someone proves ownership, renewal paths, rotation paths, and revocation paths before the deal closes. The review should therefore focus on access continuity, not just asset count. NHIMG’s Top 10 NHI Issues is a strong companion for understanding the most common failure patterns.
Due diligence also helps separate benign automation from high-risk privilege. Some machine identities are narrow and easy to migrate; others are embedded in finance, production, or third-party integrations and can become acquisition blockers if they cannot be governed cleanly.
What a Complete Review Needs to Establish
A defensible assessment answers five questions for each meaningful non-human identity: what it is, what it accesses, who owns it, how it authenticates, and how it will be controlled after transfer. Without all five, the buyer is accepting unknown operational and security debt.
The review should also check whether the identity is reusable across systems, whether its credentials are long-lived, whether the secret material is recoverable, and whether offboarding can be executed without breaking production dependencies. NHIMG’s NHI Ownership and Accountability Guide and NHI Lifecycle Management Guide both map directly to these questions.
Certificates, tokens, and keys deserve special attention because they can look like simple technical artifacts while actually functioning as live access paths. If they are not mapped to an owner and a rotation plan, they become the fastest route for post-close access loss or compromise.
What Good Due Diligence Outputs
The useful output is not a spreadsheet of names. It is a decision set that tells the buyer which identities can be inherited, which must be remediated before close, which require immediate rotation, and which should be removed or isolated as part of integration.
That output should also identify dependencies that will matter on day one: applications that fail if a token is rotated too early, certificates that expire before migration, accounts that belong to vendors rather than the target, and identities that need coordinated cutover. NHIMG’s Service Account Security Guide and Joiner-Mover-Leaver (JML) Guide are both relevant because acquisition is, functionally, a large-scale ownership and lifecycle transition.
When the review is done well, it gives transaction teams a practical answer to a hard question: can the inherited non-human access be governed safely on day two, or does it need to be rebuilt before the business can trust it?
Risk and Threat Considerations
Inherited machine identities can preserve attacker access, even after corporate control changes. If service accounts, tokens, or keys are missed in diligence, the buyer may inherit silent access paths that still authenticate successfully after the deal closes.
Failure mechanism: Weak inventory, unclear ownership, and long-lived credentials let orphaned identities survive the transaction and continue to authorize access across environments.
Impact: That can lead to unauthorized persistence, lateral movement, failed revocation, production disruption during rushed cleanup, or a breach that is discovered only after the acquisition is complete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Machine identities in due diligence hinge on credential lifecycle, rotation, and revocation. |
| IA-9 — Service Identification and Authentication | Service accounts, APIs, and workload identities must be validated as real access paths before transfer. | |
| AC-6 — Least Privilege | Due diligence must expose excessive inherited access so it can be reduced before or during integration. | |
| Recommendation — Track and rotate inherited authenticators before close, and revoke any credentials that cannot be controlled. Verify how each inherited service identity authenticates and confirm it can be reestablished safely after acquisition. Review inherited entitlements and reduce every machine identity to the minimum access it actually needs. | ||
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Acquisition due diligence must prove inherited identities can be removed or disabled safely. |
| NHI-02 — Secret Leakage | Due diligence must find exposed keys, tokens, and credentials that could survive the transaction. | |
| NHI-05 — Overprivileged NHI | Inherited access often includes excessive permissions that increase acquisition risk. | |
| Recommendation — Validate offboarding and revocation paths for every inherited non-human identity before close. Locate leaked or embedded secrets and require remediation before the deal closes. Identify overprivileged machine identities and trim their access before integration. | ||
| CIS Controls v8 | CIS-5 — Account Management | Due diligence needs account inventory, ownership, and remediation of stale access paths. |
| CIS-6 — Access Control Management | The review must confirm inherited access can be governed, restricted, and revoked. | |
| Recommendation — Use account management controls to find, own, and remove inherited machine accounts and secrets. Apply access control management to reduce inherited permissions and block unnecessary access paths. | ||
Practitioner Guidance
Why practitioners should care: This term sits at the point where security, operations, and transaction risk meet. If the buyer cannot prove control over inherited non-human identities, it cannot reliably prove control over the systems those identities can reach.
What to watch for: Focus on undocumented ownership, shared or embedded credentials, credentials without clear expiry, and identities tied to third parties or build pipelines. Those are the cases most likely to create post-close surprises.
Practitioner takeaway: Treat non-human identity due diligence as a control-transfer exercise, not an inventory exercise, and insist on a clear disposition for every inherited access path.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org