Join our Newsletter — 33% off our NHI Course
Home› Glossary› Governance, Ownership & Risk› Presumption of Adequacy
Governance, Ownership & Risk

Presumption of Adequacy

← Back to Glossary
By NHI Mgmt Group Updated October 11, 2026 Domain: Governance, Ownership & Risk

A governance principle that accepts a baseline security assessment as sufficient unless there is a documented reason to impose additional requirements. In FedRAMP 20x, it helps prevent continuous monitoring from becoming a vehicle for informal re-scoping or repeated bespoke demands.

What Presumption of Adequacy Means in Governance

Presumption of adequacy is a decision rule that starts from an accepted baseline and treats it as sufficient unless someone can show a documented reason to add more requirements. It shifts the burden away from endless re-review and toward justifying exceptions.

In governance settings, that approach matters because it creates a default state for acceptance, rather than forcing every review cycle to reopen settled decisions. It is especially useful where the goal is consistency, speed, and restraint in oversight.

How It Changes Review and Escalation Behavior

The practical effect is to separate ordinary monitoring from true exception handling. If a control set, assessment, or baseline has already been accepted, later reviewers should not use informal preference or local habit to reintroduce new demands.

This makes the term more than a general “good governance” idea. It establishes a threshold test, additional requirements need a documented rationale, not just a stronger opinion or a different reviewer. That helps keep oversight from becoming open-ended scope drift.

Why It Matters in FedRAMP 20x

In FedRAMP 20x, presumption of adequacy helps preserve the point of baseline authorization and continuous monitoring. The model depends on stable expectations, so routine oversight does not turn into repeated bespoke re-scoping for the same underlying system.

That does not mean new issues are ignored. It means new requirements should be tied to a specific change in risk, evidence, or control gap, rather than a generic desire to make the review stricter. The principle supports reuse, comparability, and predictable governance.

As a result, the concept sits at the intersection of authorization governance and change control. It is a way to keep the control bar meaningful without letting every operational touchpoint become a fresh negotiation.

Common Misreadings and Boundary Conditions

Presumption of adequacy is not a guarantee that a baseline is perfect, and it is not a prohibition on added safeguards. It simply says that extra requirements should be exceptional and documented, not automatic.

It also does not remove accountability from reviewers. If there is evidence of a material gap, a changed threat posture, or a new compliance condition, the presumption can be overcome. The point is that the exception must be visible and defensible.

Used well, the principle prevents governance from becoming arbitrary. Used poorly, it can be mistaken for a reason to stop questioning weak evidence, which is why the documentation threshold matters.

Risk and Threat Considerations

When this principle is too loose, it can be used to justify accepting an inadequate baseline simply because it was previously accepted. The main risk is not that governance becomes stricter than necessary, but that it becomes harder to distinguish genuine exceptions from routine requests.

Failure mechanism: Reviewers rely on prior acceptance as a shortcut and fail to require a documented rationale for new requirements, allowing scope creep in one direction or missed control gaps in the other.

Impact: Organisations can end up with inconsistent oversight, under-addressed risk, and a control process that either quietly expands without justification or loses credibility when exceptions are not handled rigorously.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OV-01 — Oversight and AccountabilityPresumption of adequacy is a governance rule for oversight and exception handling.
GV.RM-02 — Risk StrategyIt ties added requirements to documented risk rather than informal preference.
Recommendation — Define oversight rules that require documented justification before adding new requirements. Require risk-based justification before re-scoping an already accepted baseline.
ISO/IEC 27001:2022A.5.35 — Independent review of information securityThe principle supports consistent review rather than repeated ad hoc demands.
Recommendation — Use independent review criteria to separate baseline acceptance from justified exceptions.

Practitioner Guidance

Governance implication: Treat presumption of adequacy as a rule for exception handling, not as a substitute for evidence. The key practitioner judgment is whether a proposed additional requirement is actually tied to a documented change in risk, scope, or control failure.

Practitioner takeaway: The value of the principle depends on disciplined documentation, otherwise it becomes either a rubber stamp or a loophole.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org