Access Certification for Regulated Entitlements

“Who has access to what, and should they?” is a question every regulated firm has to answer, repeatedly, to auditors and supervisors — and most answer it badly. Access certification, the periodic review and attestation of entitlements, is the control that is supposed to keep access appropriate over time. In practice it is often a mass of spreadsheets that managers rubber-stamp without reading, producing a certification that satisfies the letter of the requirement and none of its purpose. As DORA and NIS2 raise the bar on access governance, the gap between doing access certification and doing it meaningfully becomes a real exposure.

Why access certification usually fails

The failure is structural. Firms accumulate entitlements across many systems, granted over years, rarely revoked, and when the periodic review comes, the reviewer faces a long list of cryptic access rights with no context — no clear picture of what each entitlement actually allows, whether the person still needs it, or what risk it carries. Faced with that, managers do the rational thing under time pressure: they approve everything, because understanding each line is impossible in the time available. The result is a certification that has occurred, on paper, while access has not actually been reviewed — the entitlement creep the control was meant to catch sails straight through. A supervisor who probes will find approvals with no evidence of judgement behind them.

What meaningful certification requires

  • Context the reviewer can act on. The reviewer needs to understand what an entitlement actually grants and why the person has it, or the review is theatre. Presenting access in business terms, with risk context, is what makes judgement possible.
  • Risk-based focus. Not all access is equal; concentrating scrutiny on the high-risk, privileged and sensitive entitlements — rather than reviewing everything with equal, shallow attention — is what makes the effort meaningful within the time available.
  • Real revocation. Certification only works if “this access is not needed” actually removes it, promptly and evidenced. A review that identifies excess access but does not remove it has failed at the last step.
  • Evidence of judgement. The output has to show that access was genuinely reviewed — who decided, on what basis — because a supervisor treats rubber-stamped approvals as no control at all.

Making it work

  • Give reviewers business context, not raw entitlements. Translate technical access into what it means and why it exists, so managers can actually decide.
  • Prioritise by risk. Focus real scrutiny where the exposure is — privileged, sensitive and toxic-combination access — rather than diluting attention across everything.
  • Close the loop on revocation. Ensure that identified excess access is removed promptly and provably; this is where certification either delivers or does not.
  • Automate the mechanics, keep the judgement human. Tooling can gather, present and track the certification; the value is in enabling real human judgement, not replacing it with a faster rubber stamp.

Access certification is one of those controls that is easy to perform and hard to perform meaningfully, and regulators increasingly know the difference. The firms that do it well turn it from a spreadsheet ritual into a genuine periodic pruning of access — focused by risk, informed by context, closed by real revocation, and evidenced by actual judgement. That is what keeps entitlements appropriate over time and what answers the supervisor’s question with something better than a pile of approvals no one actually made.

Free · 4 minutes

Do you actually know what you are running — and what it is about to cost you?

Fourteen questions on the systems you depend on, the ones nobody owns, and the support dates that turn a routine upgrade into a forced re-platform. Banded finding on screen, full sheet by email.

Who this is for

This reading is for:

  • CISOs and IAM leads facing access-review obligations
  • Compliance leads who own “who has access to what” for the auditor
  • Firms drowning in manual, rubber-stamped access reviews
  • Boards accountable for access governance under DORA and NIS2

Sixteen Pillars turns access certification from a spreadsheet ritual into a genuine periodic pruning of access – focused by risk, informed by context, closed by real revocation. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming