They should treat it as both. Business process digitisation changes the system of record, the approval chain and the identity checks that protect them. If IAM is added after the workflow is live, teams usually discover overbroad access, unclear ownership and weak exception handling. Governance needs to be built into the process design.
Why digital transformation has to be designed as both process and access change
digital transformation changes more than screens and workflows. It changes who approves work, which system becomes the source of truth, when access should exist, and how exceptions are justified. If teams treat it as a process-only programme, they often automate bad access patterns into the new design; if they treat it as IAM-only, they miss the business rules that create the access model.
That is why identity, ownership and approval logic need to be defined with the process itself, not added as a later control layer. The strongest implementations make the process, the access model and the audit trail evolve together.
Where IAM failures show up after a workflow goes live
When governance is bolted on after deployment, the most common failure is overbroad access. Teams grant broad entitlements to keep delivery moving, then struggle to unwind them because the workflow depends on exceptions that were never modelled cleanly. Ownership gaps follow, especially when no one can answer who should approve access changes, who can revoke them, or who owns the recertification cycle.
This is also where a process design can become a control weakness. If the workflow has no clear separation between request, approval, execution and review, the IAM layer has to compensate for design flaws that should have been resolved upstream.
What good looks like when process design and IAM are aligned
Good practice is to define the process rules and the access rules at the same time. The business process should state what is being protected, which roles are entitled to act, what evidence is required for approval, how long access should last, and what happens when the request falls outside policy. IAM then enforces those rules through role design, approval workflows, lifecycle triggers and periodic review.
In that model, the process is not “wrapped” by IAM. IAM becomes the enforcement layer for a business decision that was already deliberately designed. That makes it easier to test, easier to audit and far less likely to accumulate shadow access paths.
Risk and Threat Considerations
Transformations that separate workflow design from identity governance create predictable exposure: excessive privilege, weak exception handling and unclear accountability. Those weaknesses are attractive because they let normal business activity continue while quietly expanding who can approve, access or change sensitive records.
Failure mechanism: The organisation designs the new workflow first, then adds access controls later, so approvals, role boundaries and revocation logic never line up with the real process.
Impact: Access spreads faster than ownership, reviews become unreliable, and a single process exception can turn into durable over-privilege or unauthorised action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | Access and ownership in transformed workflows need disciplined account lifecycle control. |
| Recommendation — Define account ownership, approvals and revocation paths before automating the workflow. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Transformation changes who can act in the process and requires controlled account lifecycle governance. |
| AC-6 — Least Privilege | The question centers on overbroad access if IAM is added after the process is live. | |
| Recommendation — Map workflow roles to approved accounts and remove standing access that the process no longer needs. Limit each workflow role to the minimum permissions needed for that step. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Digital transformation needs access rules embedded in process design and operating control. |
| A.5.16 — Identity management | New workflows require clear identity ownership and lifecycle handling for users and roles. | |
| Recommendation — Define access rules for the transformed process and enforce them consistently. Assign identity ownership for each role and lifecycle state in the new process. | ||
| CSA Cloud Controls Matrix | IAM — Identity and Access Management | Cloud and digital workflow changes require identity governance aligned to business process. |
| Recommendation — Align IAM policy, approvals and recertification to the redesigned business workflow. | ||
Practitioner Guidance
What to prioritise: Start with the system of record, the approval chain and the exception path, because those three elements determine what IAM must enforce. If any of them are ambiguous, lock the process design before finalising roles or automation.
What to verify: Confirm that every privileged workflow step has a named owner, a defined approver and a revocation trigger. If those are missing, the access model is probably compensating for an unresolved business design problem.
Practitioner takeaway: Treat transformation as a joint design problem, not a sequencing problem, because the access model is only trustworthy when it is built from the business process rather than patched onto it.
Related resources from NHI Mgmt Group
- When should organisations treat an NHI as a high-priority risk?
- What is the difference between an IAM project and a business transformation initiative?
- What do organisations get wrong when they treat digital transformation as a software purchase?
- What should organisations do first when their vulnerability remediation process cannot keep up with digital transformation?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org