Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk How should organisations evaluate a modern identity governance…
Governance, Ownership & Risk

How should organisations evaluate a modern identity governance and administration platform before a crisis exposes control gaps?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 17, 2026 Domain: Governance, Ownership & Risk

Start by testing whether the platform can prove who has access to what, enforce access policies, and maintain an auditable closed loop for provisioning and revocation. A strong evaluation also checks support for machine and service accounts, segregation of duties, access certifications, and workflow approvals. The best choice aligns with business needs while reducing breach, compliance, and operational risk.

What a real IGA platform evaluation must prove

A modern identity governance and administration platform should be judged by whether it can model access accurately, enforce policy consistently, and close the loop from request to revocation without manual rescue work. The practical test is not feature breadth alone, but whether the system can keep access decisions current, attributable, and defensible across humans, service accounts, and other non-human identities.

That means the platform should demonstrate three things under realistic conditions: it can answer who has access to what, it can apply governance rules before access becomes excessive, and it can produce audit evidence that survives scrutiny. Those capabilities matter because weak governance is usually exposed first as drift, orphaned access, or approvals that do not actually lead to removal when risk changes.

For organisations with a large non-human footprint, the evaluation should also check whether the platform handles machine and service accounts as first-class governed subjects rather than edge cases. NHIMG’s Ultimate Guide to NHIs and its lifecycle processes for managing NHIs are useful reference points for evaluating discovery, ownership, rotation, offboarding, and recertification in environments where non-human access outnumbers human access.

The platform should also support control design, not just record keeping. Segregation of duties, access certifications, role or policy-based assignment, and approval workflows should operate as a closed governance chain, with changes reflected in the target system and provable in logs. If any one of those steps breaks, the platform may still look usable, but it will not reliably reduce access risk.

How to test governance, not just product claims

Use scenario-based testing rather than a checklist demo. Start with a new joiner, a role change, a contractor exit, a privileged access request, and a stale service account, then confirm that each event is handled end to end: approved by the right owner, provisioned in the right place, recertified on schedule, and revoked when it should be. The question is whether the platform preserves intent across the full lifecycle, not whether it can create a ticket.

Pay close attention to evidence quality. A strong platform should show durable audit trails, clear ownership, and review outcomes that are easy to validate after the fact. If certification campaigns, workflow approvals, and deprovisioning are all separate screens with no reliable linkage, investigators will struggle to prove that access was governed rather than merely processed.

Evaluate how the product behaves when reality is messy. Look for exceptions, delayed approvals, shared entitlements, dormant accounts, and inconsistent source data. If the platform cannot reconcile authority across directories, cloud services, and applications, its governance model may be incomplete even if the interface appears polished.

NHIMG’s 2026 Infrastructure Identity Survey is relevant here because it shows how governance gaps become operational when access is overextended or poorly scoped. That is especially important for organisations that are expanding automation and AI-assisted operations, where access controls must stay proportional to actual job function.

What should change your buying decision

Choose the platform that reduces the amount of unmanaged access in the environment, not the one that only makes governance more visible. If a vendor cannot demonstrate policy enforcement, lifecycle closure, and review evidence against your real identity sources, the tool may improve administration but still leave the same exposure in place.

What to verify: confirm that the platform can discover all relevant identity populations, support access certification at scale, enforce revocation without manual intervention, and preserve an auditable history for each decision. Also verify whether it can treat non-human access with the same governance discipline as human access, because that is often where hidden risk accumulates first.

Common mistake: treating approvals as the control instead of the control path. An approval that does not lead to actual entitlement change, or a revocation that leaves credentials usable, gives a false sense of governance and usually fails during incident review or compliance testing.

Practitioner takeaway: the right IGA platform should make access governance operationally boring, meaning every request, review, and revocation is traceable, enforced, and repeatable before a crisis proves otherwise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v85 — Account ManagementIGA evaluation centers on creating, reviewing, and removing account access accurately.
6 — Access Control ManagementThe platform must enforce policy-based access decisions and least privilege at scale.
8 — Audit Log ManagementAuditable closed-loop governance depends on records that prove who approved and changed access.
Recommendation — Verify account lifecycle workflows actually provision, review, and revoke access across systems. Apply access control policies consistently and validate that they restrict access as intended. Retain and review governance logs so access decisions and revocations remain provable.
NIST CSF 2.0PR.AA — Identity Management, Authentication, and Access ControlIGA platforms directly support identity governance and access enforcement outcomes.
GV — GovernancePlatform selection should align access governance with business and risk requirements.
PR.PS — Protective TechnologyIGA tooling is a protective technology that should reduce exposure through enforced workflows.
Recommendation — Map identities, authenticate access, and enforce least privilege across governed systems. Define governance criteria that link identity controls to business risk and accountability. Deploy controls that enforce approvals, provisioning, and revocation without manual gaps.
NIST SP 800-63AAL — Authenticator Assurance LevelIdentity platforms often sit beside assurance decisions that affect access trust.
IAL — Identity Assurance LevelEvaluation should confirm the platform can trust identity source data before governing access.
FAL — Federation Assurance LevelFederated access paths affect how governed identities are trusted across systems.
Recommendation — Match access decisions to appropriate assurance strength for the protected resource. Validate identity proofing and source data quality before relying on access decisions. Set federation trust requirements that preserve consistent access governance across domains.
NIST Zero Trust (SP 800-207)JEA — Just-Enough-Access and Policy EnforcementAccess governance should limit standing privilege and enforce policy at request time.
Recommendation — Enforce just-enough access so standing privilege stays bounded and reviewable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 17, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org