Join our Newsletter — 33% off our NHI Course

What breaks when an IGA implementation team does not include strong project management and change management skills?

Delivery breaks down when workstreams are not coordinated, dependencies are missed, and affected teams are not prepared for process changes. IGA programmes touch HR, business owners, managers, and end users, so weak project discipline quickly leads to confusion, slow adoption, and scope drift. Change management matters because even good technical design fails if users and approvers do not understand their roles.

Why This Matters for Security Teams

IGA programmes are not just technical rollouts. They rewire how HR, managers, application owners, and approvers handle access requests, certifications, joiner-mover-leaver events, and exceptions. When project management is weak, dependencies slip, scope changes are not controlled, and teams receive conflicting instructions. When change management is weak, users keep old habits, approvers delay action, and the new process exists on paper only.

This becomes especially risky because identity failures rarely stay contained. NHIMG notes that the Ultimate Guide to NHIs reports 80% of identity breaches involved compromised non-human identities, which shows how quickly weak identity operations can become a security event. NIST also treats governance and continuous improvement as core to identity and security management in the NIST Cybersecurity Framework 2.0.

In practice, many IGA teams only discover the lack of coordination after provisioning backlogs, audit issues, and business frustration have already accumulated.

How It Works in Practice

Strong IGA delivery needs two disciplines working together. Project management keeps the rollout sequenced, tracked, and aligned to business dependencies. Change management makes sure the new operating model is understood, accepted, and actually used. Without both, even a well-designed governance model fails when it meets real workflows.

At the delivery level, project management should define clear scope, milestone gates, RACI ownership, issue escalation paths, and dependency tracking across HR systems, directories, applications, and approvers. Change management should identify impacted personas, explain what changes for each group, train managers and reviewers, and prepare communications for exceptions and policy enforcement. That includes role-based outreach for approvers, job aids for service desk staff, and readiness checks before each phase goes live.

Practical controls usually include:

  • Signed business ownership for each access process and application integration
  • Change impact assessments before workflow redesign or policy enforcement
  • Pilot groups for joiner-mover-leaver and access review processes
  • Training and communications tailored to approvers, managers, and requesters
  • Go-live criteria tied to adoption, not just technical completion

NHIMG’s NHI Lifecycle Management Guide and Top 10 NHI Issues are useful reminders that lifecycle discipline and operational visibility are what keep identity control from degrading after implementation. These controls tend to break down in large federated enterprises where multiple business units insist on local variations because standardisation is politically harder than technical configuration.

Common Variations and Edge Cases

Tighter project control often increases coordination overhead, requiring organisations to balance speed against adoption quality. That tradeoff is real during IGA programmes, especially when leadership wants rapid audit results while the operating model is still changing.

There is no universal standard for change management depth in IGA, but current guidance suggests the approach should scale with process impact. A small entitlement cleanup may only need targeted communications, while a full access recertification redesign usually needs formal stakeholder mapping, training, and phased rollout. Mature teams also treat business readiness as a deliverable, not an informal check-in.

Edge cases are common. Mergers, decentralised business units, and highly regulated environments can make governance harder because each group has different approval chains and tolerance for process change. In those cases, project managers must manage scope creep aggressively and change leads must translate policy into role-specific workflows. The most common failure mode is not a broken connector or a missing control. It is a rollout that technically succeeds but is bypassed because users and approvers were never brought along.

For audit-heavy environments, the Ultimate Guide to NHIs — Regulatory and Audit Perspectives is a helpful reference for showing how operational discipline supports evidence quality and repeatability.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, CSA MAESTRO and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM Governance and risk management depend on coordinated delivery and ownership.
OWASP Non-Human Identity Top 10 NHI-01 Weak rollout discipline often leaves NHI lifecycle controls inconsistently applied.
CSA MAESTRO GOV-01 Agentic governance patterns also rely on clear ownership, change control, and operational readiness.
NIST AI RMF AI RMF governance principles map to disciplined change oversight and accountability.
OWASP Agentic AI Top 10 A01 Autonomous systems need strong rollout controls to avoid uncontrolled access and workflow drift.

Assign accountable owners, track delivery risks, and review identity process changes through governance gates.