Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Identity & Access

Access Recertification

Also known as: Access Re-Certification, Access Certification
Simply put

Access recertification is the periodic review of the permissions granted to users or accounts to confirm that each person still needs the access they have. Designated reviewers check whether access remains appropriate to a person's role and revoke rights that are no longer justified. The practice helps organizations reduce excessive or outdated permissions and lower related security risks.

Formal definition

Access recertification is a recurring control within identity governance in which designated reviewers validate and confirm the access rights assigned to users or accounts across enterprise systems, verifying that each entitlement remains necessary and appropriate to the subject's current job function. It is distinct from initial access provisioning: recertification is the ongoing revalidation of previously granted access, with the goal of identifying and remediating excessive, stale, or unwarranted permissions. In some evidence the process is described as involving an independent auditor, while in others reviews are performed by designated internal reviewers; the reviewer model and cadence vary by organization and implementation. Access recertification is commonly cited as supporting obligations under compliance frameworks (the evidence references ISO); note that whether such a framework is binding depends on legal or contractual incorporation, and readers should verify applicability and specific requirements against the current authoritative text of any framework or regulation in scope. This entry does not cover implementation-specific procedures, tooling, or the precise review frequency, which are fact- and context-dependent.

Why it matters

Over time, users accumulate access rights that outlast the roles or projects that justified them. Employees change teams, take on temporary responsibilities, or leave the organization, yet the permissions granted along the way often persist. This accumulation—sometimes called privilege creep—expands the attack surface and increases the risk that stale or excessive entitlements will be exploited, whether by a malicious insider, a compromised account, or an external attacker who gains a foothold. Access recertification exists to counter this drift by periodically forcing a deliberate confirmation that each entitlement still corresponds to a genuine business need.

Beyond risk reduction, access recertification is commonly cited as supporting obligations under compliance frameworks. The evidence references ISO in this context; readers should note that whether such a framework is binding on a given organization depends on legal or contractual incorporation rather than on the framework existing in the abstract. Where recertification is described as "mandatory," that characterization typically reflects the requirements of a specific framework, contractual commitment, or internal policy in scope, and the precise obligation should be verified against the current authoritative text.

The practical value of recertification lies in producing a documented, defensible record that access was reviewed and either reaffirmed or revoked. This supports both security risk management and the ability to demonstrate control to auditors. The specifics—who reviews, how often, and against what criteria—vary by organization and implementation, and this entry does not prescribe those details, which are fact- and context-dependent.

Who it's relevant to

IAM and identity governance teams
Teams responsible for identity and access management design and operate recertification as a recurring control. They define review cycles, route entitlements to the appropriate reviewers, and remediate access that is no longer justified. The reviewer model and cadence they adopt depend on organizational context and the frameworks in scope.
Business managers and application owners acting as reviewers
Because recertification depends on confirming that access matches a person's current job function, the designated reviewers are often those with direct knowledge of a user's role. They validate or revoke entitlements during each cycle. In some implementations this function is instead performed by an independent auditor; the appropriate model varies by organization.
Compliance officers and auditors
Recertification is commonly cited as supporting compliance obligations, with the evidence referencing ISO. Compliance and audit professionals rely on recertification records to demonstrate that access is periodically reviewed. They should confirm whether any given framework is binding through legal or contractual incorporation and verify specific requirements against the current authoritative text.
Information security teams
Security functions benefit from recertification because reducing excessive or stale permissions lowers the attack surface and related security risks. Recertification supports broader risk management by ensuring that access rights remain aligned with legitimate need over time.

Inside Access Recertification

Periodic Review Cycle
The scheduled cadence at which access rights are re-examined, commonly quarterly, semi-annually, or annually. The appropriate frequency generally depends on the sensitivity of the resources, the risk profile of the roles involved, and any applicable regulatory or contractual expectations. Higher-risk or privileged access is typically reviewed more often.
Reviewer or Attester
The accountable individual, often a line manager, resource owner, or system owner, who confirms whether each user's access remains appropriate. This role is distinct from the identity administrator who provisions or removes access; the reviewer makes the business decision, while the administrator executes the resulting change.
Entitlement Inventory
The set of access rights, group memberships, roles, and permissions being reviewed. Accurate recertification depends on a complete and current inventory; gaps in what is presented for review can leave orphaned or excess access undetected.
Attestation Decision
The recorded outcome for each reviewed entitlement, typically to approve (retain), revoke (remove), or flag for further investigation. The decision and its rationale form part of the evidentiary trail.
Remediation Workflow
The process by which revocation or modification decisions are actioned and verified. A recertification that identifies excess access but does not follow through on removal generally does not achieve its control objective.
Evidence and Audit Trail
The retained records showing who reviewed what, when, what decision was made, and how it was implemented. This documentation is frequently what auditors examine when assessing access governance against control frameworks such as SOC 2 or ISO/IEC 27001, or when demonstrating diligence relevant to data protection obligations.

Common questions

Answers to the questions practitioners most commonly ask about Access Recertification.

Is access recertification the same as an access review or an audit?
Not exactly. Access recertification is a specific, periodic process in which designated reviewers formally attest that a user's or account's current access rights remain appropriate and necessary. A general access review may be a broader or more informal examination of entitlements without the formal attestation and sign-off that characterizes recertification. An audit, by contrast, is typically an independent evaluation—often by internal audit or an external party—that may assess whether recertification is being performed correctly, but is itself a distinct activity. In short, recertification is an operational control; an audit is an assurance activity that may test that control. Terminology varies between organizations and frameworks, so verify how each term is defined in your own policies and in any applicable standard.
Does performing access recertification make an organization compliant with a specific regulation or certification?
No single control confers compliance or certification on its own. Access recertification is one access-governance practice that can support obligations relating to access control and least privilege, which appear in various regulatory expectations and voluntary frameworks. However, whether it is required, how often, and in what form depends on the specific regime, the sector, the data categories involved, and the organization's risk profile. Some voluntary standards address access review as part of their control sets, while regulatory expectations are generally stated at a higher level and are fact-specific. Recertification may contribute evidence toward meeting such expectations, but readers should not treat it as a standalone guarantee of compliance and should verify requirements against the current authoritative text or scheme documentation.
How often should access recertification be performed?
There is no universal frequency that applies across all organizations or regimes. Frequency is generally determined by risk: high-privilege, privileged, or sensitive-data access is often recertified more frequently than standard access, while lower-risk entitlements may be reviewed less often. Organizations commonly set cadences in internal policy and may also trigger event-based recertification—for example following a role change, a merger, or an identified control gap. Any applicable standard or contractual requirement may specify or influence intervals, so confirm expectations against the relevant framework, agreement, or regulatory guidance and align the cadence with your documented risk assessment rather than a fixed default.
Who should act as the reviewer in an access recertification campaign?
Reviewer assignment depends on the access being certified and the organization's governance model. Common approaches assign review to the individual accountable for the resource or the business context—such as a line manager for a user's role-based access, or a system or data owner for entitlements to a specific application or dataset. The general principle is that the reviewer should have enough knowledge to judge whether access remains necessary and appropriate. Assigning review to someone without that context can undermine the value of the exercise. The specific roles and separation-of-duties expectations may be shaped by internal policy and by any applicable framework, so define reviewer responsibilities clearly in your access-governance documentation.
What evidence should be retained from a recertification campaign?
Retained evidence generally aims to demonstrate that the process occurred, who reviewed what, what decisions were made, and that any required changes were carried out. This can include records of the entitlements presented, reviewer attestations (approve or revoke decisions), timestamps, and confirmation that revocations were actioned by the relevant team. Retaining evidence of remediation—not just the review decision—is often important, because an approved revocation that is never implemented leaves a residual risk. Retention periods and evidentiary formats may be shaped by internal policy, contractual terms, or applicable frameworks, so align documentation practices with those sources and confirm what auditors or assessors in your context expect to see.
How should exceptions and incomplete reviews be handled?
Recertification campaigns commonly encounter cases where a reviewer is unavailable, disputes an entitlement, or requests to retain access that appears anomalous. A defined exception process helps ensure such cases are escalated, documented, and resolved rather than left ambiguous. Incomplete reviews—where entitlements are never attested by the deadline—generally warrant a documented handling rule, which may range from escalation to a default-deny posture depending on risk appetite and policy. The appropriate treatment is organization-specific and should balance operational continuity against access risk. Define these procedures in policy in advance, and note that practice may diverge from intent, so periodic evaluation of how exceptions are actually handled is advisable.

Common misconceptions

Access recertification is required by a specific law with a mandated review frequency.
Recertification is generally described as a control expectation within voluntary frameworks (such as ISO/IEC 27001 or SOC 2) and as a practice supporting broader legal obligations, rather than as a standalone statutory requirement with a fixed interval. Where laws such as the GDPR or HIPAA are relevant, they impose principles like access limitation or minimum necessary access without prescribing a universal recertification schedule. Frequency is typically risk-based, and readers should verify against the applicable framework version or regulatory text and any contractual commitments.
Completing the review (attestation) is the same as remediating access.
Attestation is only the decision step. Access is not actually corrected until the revocation or modification is executed and confirmed. A review that records decisions but leaves excess access in place generally fails to meet its control objective, and auditors commonly test whether flagged access was in fact removed.
Access recertification and initial access provisioning are interchangeable controls.
Provisioning grants access at a point in time based on a request or role assignment, while recertification periodically re-validates that previously granted access is still appropriate. They serve different purposes across the access lifecycle, and a strong provisioning process does not remove the need for ongoing recertification, since roles, responsibilities, and business needs change over time.

Best practices

Set review frequency according to risk, reviewing privileged, high-sensitivity, and high-impact access more often than routine access, and document the rationale for the cadence chosen.
Assign attestation to reviewers with genuine business knowledge of the user and resource, such as line managers or resource owners, rather than to identity administrators who lack context to judge appropriateness.
Present reviewers with a complete and current entitlement inventory, and reconcile it against source systems so orphaned accounts and excess permissions are surfaced rather than hidden.
Close the loop on decisions by tracking each revocation or modification through to confirmed implementation, and verify that flagged items were actioned.
Retain a defensible audit trail capturing who reviewed what, the decision made, the rationale, and the remediation outcome, in a form suitable for examination under frameworks such as SOC 2 or ISO/IEC 27001.
Periodically re-verify the process itself against the current version of any applicable framework, regulatory text, and contractual obligations, since standards and interpretations are amended over time.
Promotional banner for the Pentest Readiness checklist download