Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations treat digital transformation as an IAM…
Governance, Ownership & Risk

Should organisations treat digital transformation as an IAM project or a business process project?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

They should treat it as both. Business process digitisation changes the system of record, the approval chain and the identity checks that protect them. If IAM is added after the workflow is live, teams usually discover overbroad access, unclear ownership and weak exception handling. Governance needs to be built into the process design.

Why digital transformation has to be designed as both process and access change

digital transformation changes more than screens and workflows. It changes who approves work, which system becomes the source of truth, when access should exist, and how exceptions are justified. If teams treat it as a process-only programme, they often automate bad access patterns into the new design; if they treat it as IAM-only, they miss the business rules that create the access model.

That is why identity, ownership and approval logic need to be defined with the process itself, not added as a later control layer. The strongest implementations make the process, the access model and the audit trail evolve together.

Where IAM failures show up after a workflow goes live

When governance is bolted on after deployment, the most common failure is overbroad access. Teams grant broad entitlements to keep delivery moving, then struggle to unwind them because the workflow depends on exceptions that were never modelled cleanly. Ownership gaps follow, especially when no one can answer who should approve access changes, who can revoke them, or who owns the recertification cycle.

This is also where a process design can become a control weakness. If the workflow has no clear separation between request, approval, execution and review, the IAM layer has to compensate for design flaws that should have been resolved upstream.

What good looks like when process design and IAM are aligned

Good practice is to define the process rules and the access rules at the same time. The business process should state what is being protected, which roles are entitled to act, what evidence is required for approval, how long access should last, and what happens when the request falls outside policy. IAM then enforces those rules through role design, approval workflows, lifecycle triggers and periodic review.

In that model, the process is not “wrapped” by IAM. IAM becomes the enforcement layer for a business decision that was already deliberately designed. That makes it easier to test, easier to audit and far less likely to accumulate shadow access paths.

Risk and Threat Considerations

Transformations that separate workflow design from identity governance create predictable exposure: excessive privilege, weak exception handling and unclear accountability. Those weaknesses are attractive because they let normal business activity continue while quietly expanding who can approve, access or change sensitive records.

Failure mechanism: The organisation designs the new workflow first, then adds access controls later, so approvals, role boundaries and revocation logic never line up with the real process.

Impact: Access spreads faster than ownership, reviews become unreliable, and a single process exception can turn into durable over-privilege or unauthorised action.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8, NIST SP 800-53 Rev 5 and CSA Cloud Controls Matrix set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementAccess and ownership in transformed workflows need disciplined account lifecycle control.
Recommendation — Define account ownership, approvals and revocation paths before automating the workflow.
NIST SP 800-53 Rev 5AC-2 — Account ManagementTransformation changes who can act in the process and requires controlled account lifecycle governance.
AC-6 — Least PrivilegeThe question centers on overbroad access if IAM is added after the process is live.
Recommendation — Map workflow roles to approved accounts and remove standing access that the process no longer needs. Limit each workflow role to the minimum permissions needed for that step.
ISO/IEC 27001:2022A.5.15 — Access controlDigital transformation needs access rules embedded in process design and operating control.
A.5.16 — Identity managementNew workflows require clear identity ownership and lifecycle handling for users and roles.
Recommendation — Define access rules for the transformed process and enforce them consistently. Assign identity ownership for each role and lifecycle state in the new process.
CSA Cloud Controls MatrixIAM — Identity and Access ManagementCloud and digital workflow changes require identity governance aligned to business process.
Recommendation — Align IAM policy, approvals and recertification to the redesigned business workflow.

Practitioner Guidance

What to prioritise: Start with the system of record, the approval chain and the exception path, because those three elements determine what IAM must enforce. If any of them are ambiguous, lock the process design before finalising roles or automation.

What to verify: Confirm that every privileged workflow step has a named owner, a defined approver and a revocation trigger. If those are missing, the access model is probably compensating for an unresolved business design problem.

Practitioner takeaway: Treat transformation as a joint design problem, not a sequencing problem, because the access model is only trustworthy when it is built from the business process rather than patched onto it.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org