REGISTER REVISED SEPTEMBER 2026

What is an access certification?

ILM Reference editors · Last reviewed September 2026

SUMMARYREV. 2026-09

An access certification, also called an access review, is a scheduled campaign in which managers or application owners confirm or revoke each person's access to systems. It produces the review evidence auditors ask for under SOX testing, NIST SP 800-53 AC-2 (j) and DORA. It only covers accounts the review tool can see, so disconnected applications must be loaded in first.

What types of campaigns exist?

Access certification campaign types.
Campaign typeReviewerExample source
ManagerThe person's managerSailPoint Manager campaign
Source or app ownerThe owner of an applicationSailPoint Source Owner campaign
Search or targetedWhoever the query definesSailPoint Search campaign
Role compositionRole owner reviews what a role containsSailPoint role composition (legacy campaigns)

How often should certifications run?

Your policy sets it; quarterly for high-risk and financial systems is common. DORA's technical standard sets a floor of at least once a year for staff with access to ICT assets supporting critical or important functions (EU 2024/1774, Article 21).

What makes a certification credible?

  • Complete account lists, including disconnected apps.
  • Plain-language entitlements reviewers understand.
  • Revocations actually executed and recorded.
  • No rubber-stamping: low-risk items auto-certified so reviewers focus on exceptions (SailPoint and Saviynt both describe AI assistance for this).

Sources

Reviewed Sep 2026

Related

GUIDEREV. 2026-09