TL;DR: Identity governance programmes often fail at scale because teams try to deliver too much at once, according to Omada Identity’s webinar on IdentityPROJECT+. A phased, business-driven operating model is now the practical way to reduce implementation risk, align stakeholders, and turn IGA into a durable business capability.
Editorial analysis by NHI Mgmt Group, based on content published by Omada Identity: “Building a Sustainable Identity Governance Program with IdentityPROJECT+”.
Key questions
Q: How should organisations phase an identity governance programme to reduce risk?
A: Start with a limited business area, a clear set of access decisions, and a small number of systems where ownership is obvious.
Q: Why do identity governance projects struggle when they are treated as one-time deployments?
A: Because governance only works when the organisation can operate it repeatedly.
Practitioner guidance
- Define the first governance phase around a narrow business outcome Start with a bounded identity governance use case such as access requests, certifications, or high-risk role review, then prove value before expanding scope.
- Map each phase to a named business owner and operational process Assign clear ownership for approvals, exceptions, and evidence so governance responsibilities align with how the organisation actually works.
- Measure adoption and operational stability after each iteration Track whether users, reviewers, and process owners are completing governance tasks consistently before adding the next phase.
Bottom line: Identity governance maturity depends on operating discipline, not on how much of the platform has been switched on.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phased delivery is the only credible way to make IGA scale. Identity governance programmes fail when they are designed as single-gambit transformations, because the organisation has to absorb process change, data cleanup, policy design, and stakeholder adoption at the same time. A phased model reduces that load and gives each stage a measurable outcome. The implication for practitioners is that programme maturity should be built through controlled increments, not broad declarations of target state.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: How should organisations stop identity governance from stalling in practice?
A: Treat IGA as an operating model problem first. Strengthen integration with core systems, reduce manual exception handling, and validate that the review and approval process still works at scale. If the programme cannot sustain daily operations, adding more controls will not improve governance because the control fabric itself is unstable.
👉 Read our full editorial: Identity governance maturity needs a phased operating model