TL;DR: Compliance-first IGA leaves financial institutions exposed because access reviews are periodic, narrow, and reactive, while SaaS sprawl, contractors, and role changes continuously reshape permissions, according to Zluri. The governance problem is not audit readiness versus security, but whether identity controls can keep pace with real business change.
Editorial analysis by NHI Mgmt Group, based on content published by Zluri: “Evolving IGA in Finance: A Business-First Approach”.
Key questions
Q: How should financial institutions move from compliance-first IGA to business-driven governance?
A: They should connect access decisions to lifecycle events, usage, and risk instead of relying on periodic review alone.
Q: Why do quarterly access reviews miss identity risk?
A: Quarterly reviews miss risk because entitlement abuse can happen and finish long before the next certification cycle.
Q: What breaks when access is approved from org charts instead of actual usage?
A: Org charts are too static to reflect project work, contractor status, inactive accounts, or app-specific sensitivity.
Practitioner guidance
- Map access decisions to lifecycle events Tie provisioning, modification, and revocation to joiner, mover, and leaver events so governance follows business change instead of calendar-based review cycles.
- Replace org-chart approvals with current-context rules Use role, department, app usage, contractor status, and entitlement sensitivity to evaluate whether access is still justified.
- Prioritise high-risk and unused access first Focus review and remediation effort on privileged users, inactive accounts, external users, and over-provisioned entitlements that the article identifies as blind spots.
Bottom line: Compliance-first IGA is too slow for finance because entitlements change continuously while reviews happen on a schedule.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Audit cadence is the wrong unit of control for finance access governance. The article shows that quarterly or annual reviews cannot keep pace with the speed at which entitlements change in SaaS-heavy financial environments. That means the core problem is not weak auditing, but a governance model that measures access after business change has already occurred. Practitioners should treat continuous entitlement drift as the baseline condition, not the exception.
A few things that frame the scale:
- Nearly 60% of IT leaders cite restrictive cost and complexity as a weakness of legacy identity governance, according to the 2025 State of Identity Governance Report.
A question worth separating out:
Q: How do security teams know if business-driven IGA is working?
A: Look for falling revocation latency, fewer orphaned accounts, fewer unused entitlements, and faster completion of access changes after joins, moves, and exits. If review outcomes improve but stale access still persists between cycles, the programme is only documenting risk instead of reducing it.
👉 Read our full editorial: Business-driven IGA in finance: why compliance-first models fall short