Attestation Campaign
An attestation campaign is an organized process in which designated reviewers formally confirm, on record, that certain information is accurate and appropriate, such as who has access to which systems or that staff acknowledge specific policies. Organizations run these campaigns on a recurring basis to gather and document these confirmations in a structured way. The output is a set of reviewer decisions that can serve as evidence for audit and compliance purposes.
An attestation campaign is a structured, workflow-driven process used to collect and record formal declarations (attestations) from designated reviewers or stakeholders confirming the accuracy, completeness, or appropriateness of a defined scope of items. In identity and access management contexts, such campaigns are commonly used to review and certify user access rights and permissions across applications and identities, capturing reviewer decisions (for example, confirm or revoke) as auditable records. The term also spans policy attestation, where staff confirm on record that they are aware of, understand, and agree to follow specified policies. Terminology varies across vendors and frameworks, with 'attestation campaign' and 'certification campaign' often used interchangeably; the specific scope, review cadence, and reviewer roles depend on the organization's governance and compliance requirements. This entry does not cover tooling-specific implementation details or jurisdiction-specific regulatory mandates.
Why it matters
Attestation campaigns provide documented evidence that designated reviewers have examined and confirmed the accuracy or appropriateness of a defined scope of items, most commonly user access rights or acknowledgment of policies. In access management contexts, entitlements tend to accumulate over time as staff change roles, join projects, or leave the organization, and periodic certification is one of the mechanisms by which organizations seek to detect and remediate inappropriate or excessive access. The recorded reviewer decisions can serve as auditable artifacts supporting internal control assurance and compliance obligations.
Beyond access, policy attestation campaigns capture confirmations from staff that they are aware of, understand, and agree to follow specified policies. This creates a defensible record that expectations were communicated and acknowledged, which can be relevant when demonstrating the operation of a compliance program. It is important to note, however, that an attestation records a reviewer's declaration at a point in time; it does not by itself guarantee that access is correct or that policies are followed in practice. The quality of a campaign depends on the diligence of reviewers and the accuracy of the underlying data presented to them.
Because specific review cadence, reviewer roles, and scope depend on an organization's governance and compliance requirements, and because regulatory expectations vary by jurisdiction and sector, attestation campaigns should be understood as a control activity whose value rests on how well it is designed and executed rather than on the existence of the campaign alone.
Who it's relevant to
Inside Attestation Campaign
Common questions
Answers to the questions practitioners most commonly ask about Attestation Campaign.