Campaign Name:
Campaign Type: ☐ Periodic ☐ Event-Driven ☐ Risk-Triggered
Scope: ☐ All NHIs ☐ Privileged Only ☐ High-Risk Only
Review Window: Start Date → End Date
Reviewer SLA: ☐ 7 days ☐ 14 days ☐ 30 days
Approving Authority: Identity Governance / Security / IT / Engineering / App Owners
Audit Period Covered:
Objective:
Certify that all in-scope Non-Human Identities (NHIs) have valid ownership, justified access, least privilege, and compliant credential lifecycle controls.
☐ Ownership confirmed
☐ Purpose still valid
☐ NHI still required
Reviewer: App Owner / System Owner / IT / Engineering
☐ Least privilege validated
☐ No unused high-risk permissions
☐ No standing admin without justification
Reviewer: Security / App Owner / IT / Engineering
☐ Rotation compliant
☐ Expiry enforced
☐ No orphaned credentials
Reviewer: Platform / Cloud Security
☐ Usage aligns with purpose
☐ No unexplained anomalies
Reviewer: SecOps / Identity Security
☐ Privileged access in production
☐ No assigned owner
☐ Unused for >90 days
☐ Static credentials
☐ Missing or overdue rotation
☐ External / public exposure
☐ AI agent with broad scopes
Risk Score: ☐ Low ☐ Medium ☐ High ☐ Critical
Priority Queue: ☐ Immediate ☐ This Cycle ☐ Defer with Justification
Certification Decision:
Reviewer Comments:
Decision Date:
☐ Decision recorded
☐ Evidence attached
☐ Remediation completed
☐ Evidence captured
Applies if NHI Type = AI / LLM Agent
☐ Scoped access validated
☐ HITL enforced where required
☐ Agent logs retained
☐ Evidence exportable
☐ Reviewer decisions traceable
☐ Remediation auditable
Campaign Owner Sign-Off:
Date:
Book a Demo with BalkanID today and see how effortless compliance can be.
