What is an access certification?
ILM Reference editors · Last reviewed September 2026
SUMMARYREV. 2026-09
An access certification, also called an access review, is a scheduled campaign in which managers or application owners confirm or revoke each person's access to systems. It produces the review evidence auditors ask for under SOX testing, NIST SP 800-53 AC-2 (j) and DORA. It only covers accounts the review tool can see, so disconnected applications must be loaded in first.
What types of campaigns exist?
| Campaign type | Reviewer | Example source |
|---|---|---|
| Manager | The person's manager | SailPoint Manager campaign |
| Source or app owner | The owner of an application | SailPoint Source Owner campaign |
| Search or targeted | Whoever the query defines | SailPoint Search campaign |
| Role composition | Role owner reviews what a role contains | SailPoint role composition (legacy campaigns) |
How often should certifications run?
Your policy sets it; quarterly for high-risk and financial systems is common. DORA's technical standard sets a floor of at least once a year for staff with access to ICT assets supporting critical or important functions (EU 2024/1774, Article 21).
What makes a certification credible?
- Complete account lists, including disconnected apps.
- Plain-language entitlements reviewers understand.
- Revocations actually executed and recorded.
- No rubber-stamping: low-risk items auto-certified so reviewers focus on exceptions (SailPoint and Saviynt both describe AI assistance for this).
Sources
Reviewed Sep 2026
Related
PROFILEREV. 2026-09
GUIDEREV. 2026-09