Access Certification Effectiveness
100% Completion Rate. 11.7 Seconds Per Account. The Review Was a Checkbox.
6 min read · 11 September 2026 · Security
A financial services vendor ran quarterly access certifications through their IGA platform , all account managers received certification tasks for accounts in their portfolio, completed the certifications within the required window, and the platform reported one hundred percent completion for each cycle. During an internal audit, analysts examined the certification logs and found that a particular manager responsible for two hundred and thirty accounts had completed their entire certification in forty-seven minutes , an average of twelve seconds per account. Analysis of their certification decisions showed that all two hundred and thirty accounts had been approved with zero revocations over four consecutive quarters. Further investigation found that the manager's approach was to select all accounts and click bulk-approve , the platform did not prevent this, the workflow did not require per-account justification, and the completion was technically valid. The certification metrics showed one hundred percent completion. The certification process had produced zero security value. The accounts that should have been revoked in the previous year , three former employees, two accounts for concluded projects , were still active. They had passed four certifications without any individual review.
What is Access Certification Effectiveness, Really?
Access certification is the periodic process of reviewing active accounts and their permissions and making deliberate decisions about whether each account should retain its current access , confirming that access is still appropriate, reducing scope where it has become disproportionate, and revoking access that is no longer needed. When executed effectively, access certification is a genuine review process that produces access decisions based on actual assessment of current need. When executed as a compliance checkbox, it is a form submission that produces approval records without corresponding access decisions.
The rubber-stamp problem is the most common failure mode of access certification programs. Managers who are responsible for reviewing hundreds of accounts with no per-account information beyond account name and access level, no time allocated for meaningful review, and no accountability for approval decisions that are later found to be incorrect will consistently take the path of least resistance , approving everything quickly to clear the certification task from their queue. The IGA platform records the completion. The security value of the completion depends on the quality of the decisions made, which the platform cannot distinguish from bulk approval.
The detection challenge is what makes rubber-stamp certification particularly difficult to govern. A certification that was completed by genuine individual review and a certification that was completed by bulk approval produce identical platform records , both show the manager, the timestamp, and a completion status. Only the time elapsed and the decision distribution (what percentage of accounts were revoked or modified versus simply approved) reveal whether genuine review occurred. These secondary metrics are rarely tracked or reported alongside the primary completion metric that organizations use to demonstrate certification program maturity.
- Bulk approval capability without prevention , platform allows selecting all accounts and approving simultaneously without per-account review requirement
- No per-account justification requirement , certifications accepted without requiring reviewers to provide reasoning for approval decisions
- No review time adequacy monitoring , certification timing not assessed against the minimum time required for genuine review
- No revocation rate tracking , certification quality not assessed through the percentage of accounts revoked or modified
- Completion rate as the only success metric , platform reports completion without reporting decision quality indicators
Why this matters
Access certification effectiveness matters for TPRM because access certifications are frequently cited as a primary governance control for vendor access management , evidence that access is periodically reviewed and confirmed as appropriate. A certification program that consistently produces one hundred percent completion with zero revocations is not demonstrating strong access governance; it is demonstrating consistent rubber-stamping. The control that was supposed to catch excess access, orphaned accounts, and inappropriate permissions is producing approvals that protect none of those risks.
The audit evidence dimension is significant. SOC 2 assessments, regulatory examinations, and TPRM reviews accept access certification completion records as evidence of access governance maturity. Those records accurately describe that certifications were completed. They do not reveal whether the certifications produced genuine review. An auditor who accepts completion records without examining revocation rates, review time adequacy, and certification quality indicators has accepted form-completion evidence as substance-governance evidence , a distinction that matters when the same certification failed to catch the three former employees whose accounts were active for four consecutive certified quarters.
Where most teams get this wrong
The most consistent failure is tracking certification completion as the primary success metric without tracking certification quality indicators. Completion confirms the form was submitted. Quality indicators , revocation rate, average review time per account, per-account justification rate , describe whether the form submission represented genuine review. Both metrics are necessary. The first without the second confirms activity without confirming value.
- Tracking completion rate without quality indicators
- No revocation rate tracking , percentage of accounts modified or revoked
- Bulk approval not prevented , platform capability allowing rubber-stamp certification
- No per-account justification requirement
- No review time adequacy assessment
What good looks like
Mature certification programs design the certification process to require genuine review , preventing bulk approval, requiring per-account justification, setting minimum review time expectations, and tracking quality indicators alongside completion rates. Certifications that show zero revocations trigger quality review rather than acceptance as evidence of a well-managed access environment.
- Bulk approval prevention , platform requires per-account decision rather than group approval
- Per-account justification requirement , reviewers must provide brief justification for continuation decisions
- Revocation rate tracking , percentage of accounts revoked or modified tracked as a quality metric
- Review time adequacy monitoring , certifications completed significantly faster than the minimum review time flagged for quality review
- No-response equals revocation , accounts not certified within the window automatically revoked rather than defaulting to approved
Tooling
Identity Governance , SailPoint, Saviynt
Enterprise IGA platforms provide certification workflow configuration , enabling organizations to require per-account decisions, prevent bulk approval, set justification requirements, and track certification quality metrics. SailPoint IdentityAI provides analytics on certification patterns , identifying managers whose certification behavior suggests rubber-stamping through review time and decision distribution analysis. For TPRM practitioners, asking whether the vendor's certification platform prevents bulk approval and requires per-account justification provides specific certification design questions.
Access Analytics , Veza, Varonis
Access analytics platforms provide the decision quality context that certification platforms typically do not , showing which permissions are actually used versus which are assigned, enabling certifiers to make informed decisions based on usage data rather than account existence alone. For TPRM practitioners, asking whether access usage data is provided to certifiers during the certification process provides a specific review quality enhancement question.
Governance challenges
The governance challenge with certification effectiveness is the scale and time problem. Organizations certify hundreds of accounts per reviewer per cycle. Genuine per-account review at scale requires either reducing the number of accounts per reviewer, providing certifiers with information that enables faster genuine review (usage data, risk signals), or automating the easy decisions (accounts with no recent use are recommended for revocation) and concentrating human review on the cases that require judgment. The design choice that produces bulk approval is the design choice that makes genuine review impractical at the scale the process requires.
- Track revocation rates alongside completion rates , quality indicator alongside completion metric
- Monitor review time adequacy , certifications completed too quickly flagged for quality review
- Require per-account justification for continuation decisions
- Prevent bulk approval in certification platform configuration
- Include certification quality in vendor governance assessment , not just completion confirmation
If you are a small team
Ask your highest-risk vendors for two certification metrics rather than one: their most recent certification completion rate and their most recent certification revocation rate. The completion rate describes whether the form was submitted. The revocation rate describes whether the review produced decisions. A vendor who reports one hundred percent completion and zero revocations over multiple consecutive cycles has a certification process that is reliably rubber-stamping rather than reviewing. Ask what percentage of accounts were modified or revoked in the last certification cycle. The answer is the quality signal the completion rate cannot provide.
- Ask for revocation rate alongside completion rate for the most recent certification
- Ask whether the certification platform prevents bulk approval
- Ask whether per-account justification is required
- Ask whether certifications completed significantly faster than expected trigger quality review
What to require
Ask directly:
"In your most recent access certification cycle, what percentage of accounts were revoked or had their access modified , and does your certification platform require per-account decisions or allow bulk approval of all accounts simultaneously?"
"Do you track certification quality metrics beyond completion rate , specifically, do you monitor review time per account and flag certifications where the review time suggests bulk approval rather than individual review?"
Expect as evidence
- Most recent certification revocation rate , not just completion rate
- Bulk approval prevention confirmation in certification platform
- Per-account justification requirement confirmation
- Certification quality monitoring description , review time adequacy and decision distribution
A vendor who reports one hundred percent certification completion should be asked what percentage of accounts were revoked or modified in the same cycle. One hundred percent completion with zero revocations across multiple cycles is not a strong access governance signal , it is a consistent rubber-stamp signal. The completion describes the activity. The revocation rate describes the value.
How to evidence it
- Certification revocation rate records alongside completion rates
- Bulk approval prevention configuration confirmation
- Per-account justification requirement documentation
- Certification quality monitoring records
Key Takeaway
The certification was completed in forty-seven minutes. Two hundred and thirty accounts at eleven point seven seconds each. Every account approved. Four consecutive quarters of one hundred percent completion and zero revocations. The three former employees who should have been revoked are still active. They passed four certifications that never looked at them. Completion measures whether the form was submitted. Revocation rate measures whether review happened. No revocations is not evidence of a well-managed access environment , it is evidence of a certification process that produces approvals without decisions. Track the revocation rate. Prevent bulk approval. Require per-account justification. A certification that produces no revocations over multiple cycles is not demonstrating clean access. It is demonstrating that the review is a checkbox.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association