Access Recertification
Access recertification is the periodic review of the permissions granted to users or accounts to confirm that each person still needs the access they have. Designated reviewers check whether access remains appropriate to a person's role and revoke rights that are no longer justified. The practice helps organizations reduce excessive or outdated permissions and lower related security risks.
Access recertification is a recurring control within identity governance in which designated reviewers validate and confirm the access rights assigned to users or accounts across enterprise systems, verifying that each entitlement remains necessary and appropriate to the subject's current job function. It is distinct from initial access provisioning: recertification is the ongoing revalidation of previously granted access, with the goal of identifying and remediating excessive, stale, or unwarranted permissions. In some evidence the process is described as involving an independent auditor, while in others reviews are performed by designated internal reviewers; the reviewer model and cadence vary by organization and implementation. Access recertification is commonly cited as supporting obligations under compliance frameworks (the evidence references ISO); note that whether such a framework is binding depends on legal or contractual incorporation, and readers should verify applicability and specific requirements against the current authoritative text of any framework or regulation in scope. This entry does not cover implementation-specific procedures, tooling, or the precise review frequency, which are fact- and context-dependent.
Why it matters
Over time, users accumulate access rights that outlast the roles or projects that justified them. Employees change teams, take on temporary responsibilities, or leave the organization, yet the permissions granted along the way often persist. This accumulation—sometimes called privilege creep—expands the attack surface and increases the risk that stale or excessive entitlements will be exploited, whether by a malicious insider, a compromised account, or an external attacker who gains a foothold. Access recertification exists to counter this drift by periodically forcing a deliberate confirmation that each entitlement still corresponds to a genuine business need.
Beyond risk reduction, access recertification is commonly cited as supporting obligations under compliance frameworks. The evidence references ISO in this context; readers should note that whether such a framework is binding on a given organization depends on legal or contractual incorporation rather than on the framework existing in the abstract. Where recertification is described as "mandatory," that characterization typically reflects the requirements of a specific framework, contractual commitment, or internal policy in scope, and the precise obligation should be verified against the current authoritative text.
The practical value of recertification lies in producing a documented, defensible record that access was reviewed and either reaffirmed or revoked. This supports both security risk management and the ability to demonstrate control to auditors. The specifics—who reviews, how often, and against what criteria—vary by organization and implementation, and this entry does not prescribe those details, which are fact- and context-dependent.
Who it's relevant to
Inside Access Recertification
Common questions
Answers to the questions practitioners most commonly ask about Access Recertification.

