Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

Run Spend

← Back to Glossary
By NHI Mgmt Group Updated October 8, 2026 Domain: Governance, Ownership & Risk

Run spend is the budget needed to keep existing operations functioning day to day. In identity programmes, it covers recurring control work such as access reviews, renewals and administrative maintenance that must continue even when no new technology is being introduced.

What Run Spend Means in Practice

Run spend is the recurring budget that keeps current operations functioning. It is the cost of steady-state work, not new investment, and in identity programmes it often includes the ongoing effort needed to keep access controls accurate and usable.

How Run Spend Differs from Change Spend

Run spend supports continuity: keeping the lights on, preserving service quality, and maintaining controls that must be repeated over time. Change spend funds new capabilities, transformations, or redesigns. The distinction matters because organisations often understate run spend while still expecting the same control coverage and operational reliability.

In security and identity operations, the line between the two can blur. A one-time system rollout may create a lasting obligation for reviews, renewals, exception handling, and administrative upkeep, so the budget impact does not stop when implementation ends.

Why Run Spend Matters for Control Maintenance

Recurring control work is often the least visible part of a security programme, but it is what makes governance sustainable. Access recertification, account renewal, credential upkeep, policy exceptions, and administrative overhead all consume run spend because they must happen continuously rather than only during a project.

When run spend is not explicitly planned, controls tend to degrade into manual shortcuts, deferred reviews, or incomplete ownership. That creates a gap between the written control design and the actual operating model, which is where many programmes lose effectiveness.

Budgeting Run Spend for Operational Stability

A useful way to think about run spend is to treat it as the cost of preserving a known security baseline. That includes the people, process, and tooling needed to operate existing controls at their expected cadence, absorb normal exceptions, and keep administrative work from becoming backlog.

For identity-heavy environments, run spend is not optional overhead. It is part of the control architecture itself, because ongoing maintenance is what keeps entitlements current, access decisions defensible, and recurring administrative work from accumulating into operational risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.PO-01 — Cybersecurity PolicyRun spend is a budgeting and governance issue for sustaining ongoing security operations.
Recommendation — Budget recurring control operations as a governed part of the cybersecurity programme.
NIST SP 800-53 Rev 5PM-3 — Information Security ResourcesRun spend directly concerns the resources required to operate and maintain security controls over time.
Recommendation — Allocate recurring resources to sustain control operation and maintenance.
ISO/IEC 27001:2022A.5.36 — Compliance with policies, rules and standards for information securityRun spend supports the continuing effort needed to keep controls aligned with policy and standards.
Recommendation — Fund the ongoing work needed to keep security controls operating in line with policy.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org