Join our Newsletter — 33% off our NHI Course

What breaks when identity governance is fragmented under DORA?

Fragmented identity governance breaks the ability to prove who had access, why they had it, and whether that access still matched policy. Under DORA, that means resilience evidence becomes incomplete, lifecycle actions are harder to justify, and audit response becomes reconstruction instead of verification.

Where fragmentation breaks the identity governance chain

Fragmentation usually does not fail at a single control. It fails when request, approval, provisioning, review, and revocation live in separate tools or teams, so no one can show a continuous control story. That is why an identity and access governance baseline matters: it links entitlements, ownership, and review evidence into one accountable record.

When that chain is broken, the practical loss is traceability. You may still have logs, tickets, and spreadsheets, but they no longer prove that access was approved for the right reason, by the right owner, for the right period. Under DORA, that weakens the organisation’s ability to show operational control over identity-related changes during normal operations and during incidents.

Why DORA makes disconnected identity evidence a resilience problem

DORA is not only about having controls, it is about demonstrating that critical ICT risk is governed consistently and can be evidenced under stress. A fragmented model turns resilience evidence into a reconstruction exercise, because teams must stitch together who approved access, which system created it, and whether the entitlement still matched the policy when the issue occurred. The governance problem becomes more visible when identity controls are mapped to DORA as part of the broader regulatory control set.

That matters most when access decisions cross operational, outsourced, or regulated boundaries. If the identity owner, the application owner, and the compliance reviewer all hold partial context, the organisation can end up with policy intent on one side and operational reality on the other. DORA amplifies that gap because evidence quality itself becomes part of operational resilience, not just an audit convenience.

What fragmented governance prevents you from proving

Fragmentation most often breaks three proofs: who had access, why they had it, and whether it was still justified at the point of use. Without a single governance view, recertification can miss stale entitlements, revocation can lag behind role change, and exceptions can survive past their intended expiry. An access model that keeps reviews, roles, and joiner-mover-leaver actions aligned with the access review and certification process gives you a cleaner evidentiary trail.

Fragmented control also weakens ownership. If no system clearly assigns accountability for a user, service account, or third-party access path, then remediation becomes ad hoc and review outcomes become hard to defend. That is why lifecycle governance is not a side issue here, and why the joiner-mover-leaver process is often where proof either holds together or falls apart.

Risk and Threat Considerations

Fragmented identity governance creates a soft target for both control failure and abuse. Stale or overbroad access can survive because no single team sees the full path from entitlement creation to revocation, and that creates opportunity for privilege creep, orphaned access, and delayed response when something looks wrong.

Failure mechanism: Control breaks occur when approval, provisioning, attestation, and offboarding are distributed across disconnected records or teams, so policy exceptions are not reconciled back to live access.

Impact: Attackers or insiders can exploit the resulting uncertainty to retain access longer, move laterally, or hide unauthorized use inside incomplete evidence, while defenders lose the ability to verify control effectiveness quickly.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy Fragmented identity governance is a risk-management issue needing enterprise control ownership.
Recommendation — Define a governance strategy that assigns ownership for access approvals, reviews, and revocation evidence.
NIST SP 800-53 Rev 5 AC-2 — Account Management Fragmentation breaks the lifecycle tracking of accounts and entitlements.
AU-2 — Audit Events DORA evidence depends on reconstructable records of access changes and review actions.
IA-5 — Authenticator Management Fragmented governance often leaves credentials and secrets without clear lifecycle control.
Recommendation — Centralise account lifecycle tracking so provisioning, review, and deprovisioning stay traceable. Log approval, entitlement change, and revocation events in a system that supports audit reconstruction. Manage credentials centrally so issuance, rotation, and revocation stay provable.
ISO/IEC 27001:2022 A.5.15 — Access control The topic is about governing and proving who can access what and why.
Recommendation — Set access-control ownership and review rules that preserve a defensible entitlement trail.

Practitioner Guidance

What to verify: Confirm that every access entitlement has a traceable owner, approval path, expiry or review date, and revocation record. If any of those elements lives only in email, spreadsheets, or a local team workflow, treat the governance model as fragmented until proven otherwise.

Decision rule: If you cannot answer the access question from a single authoritative record set, prioritise governance consolidation before expanding more reviews. More attestations do not fix broken evidence chains if provisioning and deprovisioning still occur outside the control plane.

Practitioner takeaway: Under DORA, fragmented identity governance is a resilience defect, not just a reporting inconvenience, because the real failure is the loss of defensible proof over access change, ownership, and revocation.