Skip to main content
Category: Policy Management

Attestation Campaign

Also known as: Certification Campaign, Access Certification Campaign
Simply put

An attestation campaign is an organized process in which designated reviewers formally confirm, on record, that certain information is accurate and appropriate, such as who has access to which systems or that staff acknowledge specific policies. Organizations run these campaigns on a recurring basis to gather and document these confirmations in a structured way. The output is a set of reviewer decisions that can serve as evidence for audit and compliance purposes.

Formal definition

An attestation campaign is a structured, workflow-driven process used to collect and record formal declarations (attestations) from designated reviewers or stakeholders confirming the accuracy, completeness, or appropriateness of a defined scope of items. In identity and access management contexts, such campaigns are commonly used to review and certify user access rights and permissions across applications and identities, capturing reviewer decisions (for example, confirm or revoke) as auditable records. The term also spans policy attestation, where staff confirm on record that they are aware of, understand, and agree to follow specified policies. Terminology varies across vendors and frameworks, with 'attestation campaign' and 'certification campaign' often used interchangeably; the specific scope, review cadence, and reviewer roles depend on the organization's governance and compliance requirements. This entry does not cover tooling-specific implementation details or jurisdiction-specific regulatory mandates.

Why it matters

Attestation campaigns provide documented evidence that designated reviewers have examined and confirmed the accuracy or appropriateness of a defined scope of items, most commonly user access rights or acknowledgment of policies. In access management contexts, entitlements tend to accumulate over time as staff change roles, join projects, or leave the organization, and periodic certification is one of the mechanisms by which organizations seek to detect and remediate inappropriate or excessive access. The recorded reviewer decisions can serve as auditable artifacts supporting internal control assurance and compliance obligations.

Beyond access, policy attestation campaigns capture confirmations from staff that they are aware of, understand, and agree to follow specified policies. This creates a defensible record that expectations were communicated and acknowledged, which can be relevant when demonstrating the operation of a compliance program. It is important to note, however, that an attestation records a reviewer's declaration at a point in time; it does not by itself guarantee that access is correct or that policies are followed in practice. The quality of a campaign depends on the diligence of reviewers and the accuracy of the underlying data presented to them.

Because specific review cadence, reviewer roles, and scope depend on an organization's governance and compliance requirements, and because regulatory expectations vary by jurisdiction and sector, attestation campaigns should be understood as a control activity whose value rests on how well it is designed and executed rather than on the existence of the campaign alone.

Who it's relevant to

Compliance officers
Attestation campaigns produce documented confirmations that can support demonstration of a compliance program, including staff acknowledgment that they are aware of, understand, and agree to follow specified policies. Compliance officers are typically concerned with ensuring the scope and cadence align with applicable obligations, which vary by jurisdiction and sector.
Internal auditors
The reviewer decisions captured during a campaign serve as auditable records that auditors may examine as evidence of control operation. Auditors assess campaigns as a control activity rather than perform them; they evaluate whether the process was designed and executed with sufficient rigor, including the reliability of the data presented to reviewers.
Identity and access management teams
In access contexts, these teams commonly operate the structured workflows that route user access rights and permissions across applications and identities to reviewers, capturing confirm or revoke decisions. They are responsible for the accuracy of the underlying entitlement data that reviewers rely upon.
Governance and risk professionals
Attestation and certification campaigns are one mechanism for periodically confirming that access and policy expectations remain appropriate. Governance and risk professionals typically define reviewer roles, scope, and review cadence in line with the organization's governance and compliance requirements.

Inside Attestation Campaign

Scope Definition
The set of access rights, entitlements, roles, policies, or records subject to review within the campaign, typically bounded by system, business unit, risk tier, or regulatory driver.
Reviewers (Attestors)
The designated individuals, commonly line managers, application or data owners, or entitlement owners, who are asked to confirm, modify, or revoke the items assigned to them. These are generally first line management activities rather than assurance activities.
Attestation Population
The specific items requiring a decision, such as user-to-entitlement assignments or acknowledgments of a policy, mapped to the responsible reviewer.
Decision Actions
The permitted responses per item, typically certify (approve), revoke, or delegate, often accompanied by a justification or comment field to support an audit trail.
Timeframe and Cadence
The defined start and end dates and the recurrence, which may be periodic (for example, quarterly or annually) or event-driven, such as after a role change. Specific frequencies commonly depend on internal policy, risk, and applicable regulatory expectations.
Evidence and Audit Trail
The recorded outcomes, reviewer identities, timestamps, and justifications retained to demonstrate that the review occurred and to support subsequent assurance or examination.
Remediation and Follow-up
The process by which revocations or flagged exceptions are actioned, tracked to closure, and verified, since an attestation decision does not by itself change the underlying access unless downstream fulfillment occurs.

Common questions

Answers to the questions practitioners most commonly ask about Attestation Campaign.

Does completing an attestation campaign prove that access rights or controls are actually correct?
No. An attestation campaign records that a designated reviewer has asserted, at a point in time, that certain access, entitlements, or control conditions are appropriate. It does not independently verify that the underlying state is correct. The reliability of an attestation depends on the reviewer's knowledge, diligence, and the quality of the information presented to them. Rubber-stamping, where reviewers approve without meaningful examination, is a common weakness. Attestations are typically management assertions rather than independent assurance, and they should not be treated as equivalent to testing or audit evidence.
Is an attestation campaign the same as an audit?
No, and conflating the two blurs an important independence distinction. An attestation campaign is generally a management or first-line/second-line activity in which accountable parties confirm the appropriateness of a condition. An audit is an assurance activity, commonly performed by an independent function such as internal audit, that objectively evaluates evidence. Auditors may examine attestation records as part of their work, but the act of attesting is not itself an audit. Treating self-attestation as independent assurance undermines the objectivity that assurance functions are designed to provide.
How often should attestation campaigns be run?
Frequency commonly depends on the risk associated with the items being reviewed, applicable regulatory or contractual expectations, and organizational policy. Higher-risk access, such as privileged accounts or access to sensitive data, is often reviewed more frequently than lower-risk access. Some obligations may prescribe periodic reviews, and cadences differ across jurisdictions, sectors, and organization size. Many organizations also trigger event-based attestations, for example upon a role change or transfer, in addition to scheduled cycles. This entry does not prescribe a specific interval.
Who should be assigned as the reviewer in an attestation campaign?
The reviewer is typically the party who is both accountable for and knowledgeable about the condition being attested, such as a line manager for their team's access or an application owner for entitlements within a system. Assigning reviewers who lack the context to make an informed judgment is a common source of low-quality attestations. Some designs separate the requesting, approving, and reviewing roles to reduce conflicts of interest. Reviewer assignment should align with the organization's defined roles and decision rights rather than defaulting to convenience.
What should happen when a reviewer flags access or a condition as inappropriate?
A flagged item generally initiates a defined remediation or revocation workflow, and the campaign design should specify how such exceptions are tracked to closure. Without a mechanism to act on rejections, the campaign captures assertions but does not reduce risk. Practices commonly include recording the decision, routing it to the responsible party, confirming that the change was implemented, and retaining evidence. This entry does not cover specific tooling or configuration for implementing these workflows.
What records should an attestation campaign retain?
Organizations commonly retain evidence of who reviewed what, the decision made, the date, and the disposition of any exceptions, so that the campaign's completeness and outcomes can be demonstrated later. Such records may support internal monitoring and may be examined by assurance functions or, where relevant, regulators. Retention periods and evidentiary expectations vary by jurisdiction, sector, and applicable obligations, so specific requirements should be confirmed against the organization's policies and legal context. This entry does not constitute legal advice on retention.

Common misconceptions

An attestation campaign is an assurance or audit activity that provides independent verification of access.
An attestation campaign is typically a management (first line) control in which owners confirm the appropriateness of access or acknowledge policies. It is distinct from independent assurance performed by internal audit (third line), which may test whether the campaign itself operates effectively.
Completing a campaign means all inappropriate access has been removed.
Certification of an item records a reviewer's decision but does not guarantee correct outcomes. Revocations only take effect if downstream remediation and fulfillment occur, and 'rubber-stamping' can leave inappropriate access in place. The campaign reduces, but does not eliminate, residual risk.
One universal attestation frequency applies to all organizations.
Cadence and scope commonly vary by jurisdiction, sector, system criticality, and internal policy. There is no single mandated frequency across all contexts; requirements should be determined against applicable obligations and risk.

Best practices

Define scope by risk, prioritizing high-privilege, sensitive, or regulated access so reviewer effort is concentrated where residual risk is greatest.
Assign reviewers who have direct knowledge of the resource or user, such as the relevant line manager or data owner, to reduce uninformed or reflexive certifications.
Require justifications for certify and revoke decisions and retain reviewer identity, timestamps, and outcomes to preserve a defensible audit trail.
Track revocations and flagged exceptions through to verified remediation, rather than treating the reviewer's decision as the end of the process.
Set cadence and triggers based on applicable regulatory expectations, system criticality, and internal policy, and document the rationale where practices differ across jurisdictions or business units.
Keep the campaign (a management control) separate from independent testing of its design and operating effectiveness by an assurance function, to preserve objectivity.
Promotional banner for the Penetration Report Template Kit