If your automation has good logging and you have good alerting on logs, isn't it much better to see the automated process fail as a notification it needs to be done manually rather than relying on it being remembered?
(Ideally, you'd remember and never set the alert off, but still great to have that extra layer.
It's not much different from a notification telling you the activity is due. The difference is mostly a matter of what kind of notifications your organization ignores, and well, I've seen both cases.
Anyway, the best is to shorten the certificates validity. The way Letsencrypt recommends is perfect, run it often and require several failures before anything breaks.
(Ideally, you'd remember and never set the alert off, but still great to have that extra layer.