TL;DR: Financial services identity programs often fail when teams optimise for today’s constraints and inherit tomorrow’s rework, according to Ory. The real issue is not choosing the “best” platform but matching operating ownership, customization, scale, and residency needs to the institution’s growth path.
NHIMG editorial — based on content published by Ory: Identity that fits today, and tomorrow: Right-sizing for financial services
Questions worth separating out
Q: How should security teams choose between managed and self-hosted CIAM?
A: Security teams should choose based on control boundaries, not feature checklists.
Q: When does identity customization become an architecture problem?
A: It becomes an architecture problem when teams repeatedly add workarounds to keep journeys moving.
Q: What signals show that an identity platform no longer fits an institution?
A: The clearest signals are recurring vendor tickets, duplicated flows, unclear ownership, rising dependency on custom exceptions, and growing difficulty meeting residency or scale requirements.
Practitioner guidance
- Define the operating model you are actually willing to own Map responsibilities for patching, scaling, support, lifecycle management, and incident response before choosing managed or self-hosted identity.
- Score identity options against future-state constraints Test each option against residency, scale, customization, and cost scenarios that are likely over the next 24 to 36 months.
- Review where journey workarounds are already forming Look for duplicated login paths, manual exceptions, custom step-up logic, and vendor-ticket dependencies.
What's in the full article
Ory's full blog covers the operational detail this post intentionally leaves for the source:
- Decision criteria for when managed identity is sufficient versus when self-hosting becomes necessary.
- Architecture tradeoffs for customization, residency, and scale in financial services deployments.
- A practical checklist for evaluating ownership, support burden, and migration flexibility.
- Examples of how identity constraints turn into business workarounds over time.
👉 Read Ory's guide on right-sizing identity for financial services →
Financial services identity operating models: what teams need to decide?
Explore further
Identity architecture in financial services is really an operating model decision. The article is right to frame identity as a choice about ownership, not a checklist of protocols. MFA, SSO, OIDC, and SCIM solve access mechanics, but they do not solve the governance problem of who must carry the operational burden as the institution changes. The implication is that IAM teams need to select for resilience of the operating model, not just feature coverage.
A question worth separating out:
Q: Should organisations plan for future identity migration from day one?
A: Yes. Even if the initial choice is managed identity, the architecture should preserve a clean path to more ownership later. The goal is to avoid locking integrations, data flows, or journey logic into a model that cannot evolve without a rewrite.
👉 Read our full editorial: Right-sizing identity for financial services without future rework