Access Certification Reviews: Best Practices
Best practices for designing, executing, and auditing periodic user access certification (recertification) campaigns.
Access certification, also called access recertification or user access review, is the periodic process by which managers or data owners confirm that the access rights held by users remain appropriate for their current job responsibilities. It is a detective control designed to catch access creep, orphaned accounts, and privilege accumulation that preventive provisioning controls may have missed.
Why Access Certification Matters
Over time, employees change roles, take on temporary assignments, or move between departments, often accumulating new access rights without having old ones removed. This phenomenon, known as access creep or privilege creep, gradually erodes the segregation of duties designed into the original access model. Access certification campaigns are the primary control most organizations rely on to catch and correct this drift before it becomes a material control weakness.
Key Elements of an Effective Certification Program
- Clear ownership: every entitlement or role must have a designated business owner responsible for certifying it, not just an IT administrator
- Complete population: the certification must cover all in-scope systems, accounts, and privileged access, including service accounts and third-party access
- Meaningful context: reviewers need to see role descriptions, last login dates, and peer comparisons, not just a raw list of system entitlements
- Defined frequency: high-risk systems and privileged accounts should be certified more frequently (quarterly or more) than low-risk systems (semi-annually or annually)
- Enforced remediation: revoked access identified during certification must actually be removed within a defined SLA, and evidence of removal retained
Auditing the Certification Process
When auditing an access certification program, the CISA should first confirm that the certification population is complete and accurate. A common finding is that certification campaigns exclude certain systems, contractors, or service accounts, creating blind spots. The auditor should reconcile the certification scope against a full inventory of in-scope applications and the organization's HR or contractor management system.
Testing Certification Quality
Beyond confirming that certifications occurred, auditors should assess the quality of the review itself. A 'rubber stamp' certification, where managers approve all access without genuine scrutiny, provides little real assurance. Indicators of rubber-stamping include unusually fast completion times, unusually high approval rates with no revocations, and interviews revealing that managers do not understand what they are certifying. Auditors can also select a sample of certified users and independently assess whether their access aligns with their job function, comparing certification outcomes against this independent judgment.
Timeliness of Remediation
A certification that identifies inappropriate access but is never acted upon provides false assurance. Auditors should trace a sample of revocation decisions from the certification campaign through to actual system changes, verifying the access was removed within the organization's defined SLA. Persistent delays in remediation, or access flagged for removal that remains active months later, represent a significant control deficiency that should be escalated.
Integrating Certification with Broader IAM
Mature organizations integrate access certification with identity governance and administration (IGA) tooling, automating population extraction, reviewer notification, escalation of overdue reviews, and automatic access revocation upon a denied certification. CISA candidates should understand that certification is a compensating and detective control that works best alongside strong preventive controls like role-based access control and joiner-mover-leaver process automation, not as a replacement for them.