IT Glossary

Access Recertification

Access recertification is the recurring re-approval of existing entitlements. Learn how it differs from certification and what the revocation rate reveals.

August 7, 2026

What is access recertification?

Access recertification is the recurring exercise in which entitlements that were already approved are examined again and confirmed or revoked, on a fixed cycle. Where a first certification establishes that access was correct at a point in time, recertification tests whether it is still correct now. It is the control that catches drift between two audits.

How access recertification works

  • A cycle is defined per system, commonly quarterly for regulated data and annually elsewhere.
  • Entitlements are collected from each application and grouped by reviewer.
  • The accountable manager or application owner confirms, modifies, or revokes each line.
  • Revocations are pushed back into the target system and the result is verified, not assumed.
  • The full cycle is archived with dates, decisions, and names, which becomes the audit evidence.

The revocation rate is the real signal

A recertification campaign that revokes almost nothing is usually not a sign of clean access. It is a sign of rubber-stamping, with reviewers approving long lists they lack the context to judge. A campaign revoking somewhere between 5 and 15 percent of lines is behaving normally. Anything close to zero should prompt a hard look at how the lists are built and whether the right people are reviewing them.

Examples and use cases

A company runs its first campaign and revokes 12 percent of entitlements, mostly leftovers from internal moves and closed projects. The following quarter it revokes 4 percent, which is the healthy steady state. By the third cycle reviewers receive only the lines that changed since the previous campaign, which takes each of them minutes instead of an afternoon. Apgar built its automated IAM on that principle, and Corma runs the delta-based campaigns that keep recurring recertification sustainable.

Related concepts

FAQ

What is the difference between certification and recertification?

Certification is the formal approval of access at a given moment. Recertification is the same exercise repeated on a cycle, testing whether previously approved access is still justified.

How often should access recertification run?

Quarterly for systems holding financial, health, or regulated personal data, and annually for lower-risk applications. Role changes and departures trigger an out-of-cycle check.

Who should be the reviewer?

The person who understands what the entitlement actually allows, usually the direct manager or the application owner. IT can prepare the list but should not be approving it.

What makes recertification campaigns fail?

Lists that are too long, reviewers without context, and no verification that the revocations decided were actually applied in the target system.

Request a demo