Join our Newsletter — 33% off our NHI Course
Home› Glossary› NHI Lifecycle Management› Reauthorisation
NHI Lifecycle Management

Reauthorisation

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: NHI Lifecycle Management

Reauthorisation is the periodic revalidation of whether an entity should keep its existing access. It is used to confirm that permissions still match duties, risk, and organisational need. In mature IAM programmes, reauthorisation is not a one-time event but a recurring control tied to the lifecycle of the entity.

What Reauthorisation Means in IAM

Reauthorisation is the recurring check that an entity should still have the access it already holds. It turns access review from a one-time approval into a lifecycle control that can reflect changing duties, risk, business need, and employment status.

Its value is practical rather than ceremonial. Access that was correct at onboarding can become excessive after a role change, project exit, vendor transition, or organisational restructuring. Reauthorisation is the mechanism that keeps permissions aligned to reality instead of historical approval.

How Reauthorisation Works as a Control

In practice, reauthorisation sits between access assignment and access removal. It asks whether the original reason for access still exists, whether the level of access is still justified, and whether the reviewer has enough current context to make that decision.

Because the control is periodic, it is only effective when the review scope is meaningful. A reauthorisation that simply rubber-stamps prior approval adds little value; one that is tied to current role, asset ownership, and privilege sensitivity can surface access drift before it becomes a larger governance problem.

Reauthorisation is often associated with the same control family as least-privilege enforcement. For a broader control perspective, the NIST SP 800-53 Rev 5 Security and Privacy Controls catalog is the usual anchor for access control and review-related safeguards, while NIST Cybersecurity Framework 2.0 frames the governance and risk-management context in which recurring access decisions are maintained.

Why Reauthorisation Matters for Access Governance

Reauthorisation is one of the few controls that can reveal whether access is still aligned to purpose, not just whether it was once approved. That matters in mature IAM programmes because permissions tend to accumulate over time, especially where review processes are inconsistent or ownership is unclear.

It is also a useful bridge between identity governance and operational reality. A periodic review can expose orphaned access, stale entitlements, hidden privilege growth, and access inherited from temporary exceptions that were never removed. In that sense, reauthorisation is a corrective control for privilege drift.

Where access is mediated through federated or strongly authenticated identities, the control still focuses on authorisation, not the login itself. NIST SP 800-63 Digital Identity Guidelines is useful for understanding the authentication side of the trust chain, but reauthorisation decides whether that trusted identity should continue to retain access after initial proofing.

Common Failure Modes and Practical Interpretation

The most common failure mode is treating reauthorisation as a paperwork exercise. If managers approve access without current knowledge of duties, system sensitivity, or business change, the control becomes a compliance ritual rather than a risk-reduction mechanism.

Another failure mode is using the wrong review owner. The right reviewer is usually the person or role that can judge ongoing need, not simply the person with authority to click approve. When ownership is vague, reviews drift toward speed instead of accuracy.

Reauthorisation is also weaker when it is not connected to clear revocation paths. A review that identifies excess access but does not reliably trigger removal leaves the organisation with visibility but not control. That is why periodic revalidation is most effective when it is integrated with lifecycle and entitlement management.

Risk and Threat Considerations

Reauthorisation reduces the risk that stale or excessive access remains in place long after the original business justification has changed. Without it, organisations can accumulate dormant entitlements, overbroad privileges, and access retained after role changes or departures.

Failure mechanism: Reviews become infrequent, superficial, or detached from current business context, so excessive access survives because no one revalidates whether it is still needed.

Impact: Excess access increases the chance of unauthorized action, privilege abuse, and broader blast radius if an account is misused or compromised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementReauthorisation is a recurring account and access review activity.
AC-6 — Least PrivilegeReauthorisation helps ensure access remains limited to what is currently required.
IA-5 — Authenticator ManagementOngoing access decisions depend on the lifecycle of authenticators and related credential material.
Recommendation — Review accounts periodically and remove access that no longer has a current business need. Revalidate entitlements against least-privilege needs and revoke excess permissions. Track authenticator and credential lifecycle so stale access can be removed during review.
NIST CSF 2.0PR.AA-05 — Identity and access are managed, authenticated, and authorizedReauthorisation is part of keeping access authorized over time.
GV.RM-01 — Risk management strategy is established and communicatedPeriodic reauthorisation supports ongoing risk-based access decisions.
Recommendation — Reassess whether identities remain authorized for the access they hold. Use risk criteria to decide which access requires recurring revalidation.

Practitioner Guidance

Governance implication: Treat reauthorisation as a decision about ongoing necessity, not a simple confirmation that access once made sense. The review should be anchored to current role, asset criticality, and privilege level so the approver is judging present-day need.

What to watch for: The control is weak when approvals are consistently fast, undocumented, or based on stale assumptions. That pattern usually signals that access reviews are not challenging entitlement drift and are unlikely to catch unnecessary privilege.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org