Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What are the signs that IGA is failing…
Governance, Ownership & Risk

What are the signs that IGA is failing to support security goals?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 10, 2026 Domain: Governance, Ownership & Risk

A common sign is that access reviews exist, but permissions keep accumulating and remain unchanged for long periods. Another indicator is that teams cannot tell which entitlements are actively used versus merely granted. If revoked access is rare, stale users persist, and security has little visibility into real time access behavior, governance is operating as compliance theatre rather than risk control.

When governance is producing reports but not changing access

IGA fails security goals when it becomes a reporting layer instead of a control layer. If certifications happen on schedule but access keeps expanding, the programme is not reducing exposure; it is documenting it. Security teams should look for the gap between what is reviewed and what actually changes, especially where stale entitlements, orphaned accounts, or unused privileges remain in production for long periods.

That gap matters because access governance only works when it can influence entitlement lifecycle decisions, not simply record them after the fact. In mature environments, IGA should help answer who has access, why they have it, whether it is still needed, and whether revocation is taking effect. When those questions cannot be answered with evidence, the control is weak even if the workflow exists. NIST SP 800-53 Rev 5 Security and Privacy Controls reinforces this expectation through access enforcement, account management, and auditability requirements, but the practical test is whether governance changes the blast radius of real users and real systems. In practice, many security teams discover that IGA was “working” on paper only after long-lived access has already become normal.

How IGA is supposed to reduce risk in practice

Effective IGA links identity data, entitlement ownership, approval logic, and revocation paths so access does not drift beyond business need. The control fails when those pieces are fragmented across directories, applications, and manual exception processes. In that state, reviewers can approve or reject access entries, but they cannot reliably see whether the entitlement is active, whether it is used, or whether it is still tied to a current job function.

The practical signs of failure usually show up in a few places. One is review fatigue: managers approve access in bulk because the review is too large, too opaque, or too repetitive to evaluate meaningfully. Another is entitlement sprawl: permissions accumulate across systems, but there is no measurable reduction after recertification. A third is weak deprovisioning: leavers, contractors, and role changers keep access longer than policy allows because downstream systems are not wired into timely removal. The result is a control that can describe access but cannot reliably correct it.

For teams handling sensitive identities or secrets, this becomes especially important because governance must keep pace with changes in usage, not just changes in paperwork. NHIMG research on the state of non-human identity security shows how often organisations lack full visibility into connected access paths, which is a useful analogue for human governance when the same fragmentation exists. The point is not to turn every IGA issue into an identity tool problem, but to recognise that governance fails when it cannot verify current state and enforce current decisions.

  • Look for evidence that access review outcomes trigger actual removal, not just attestation completion.
  • Check whether entitlement owners can explain why a permission still exists today.
  • Confirm that joiner, mover, and leaver events propagate to downstream applications without manual chasing.
  • Measure how often revoked access remains effective after the revocation request is closed.

These controls tend to break down in highly federated environments because application owners, HR data, and directory state do not change on the same timeline.

What a broken IGA programme usually looks like day to day

Tighter governance often increases administrative load, so the real tradeoff is between friction and usable control. If the programme relies on manual evidence collection, spreadsheet-based exceptions, or annual reviews with no entitlement telemetry, it will drift toward compliance theatre. Current guidance suggests treating that as a visibility and enforcement problem, not merely a workflow problem, because the failure is usually systemic rather than cosmetic.

Common edge cases reveal where the gap is widest. Dormant access may look acceptable in a review cycle but still provide a path for misuse if a credential is later reused. Service accounts and shared accounts can also distort the picture, because ownership is unclear and usage is hard to attribute. In environments with many acquisitions, SaaS applications, or delegated administration models, access decisions often lose consistency faster than policy can absorb them.

Practitioner judgment matters most when the team must decide whether the issue is isolated exception handling or a design failure. If governance cannot prove that high-risk access is removed quickly, that reviews are risk-based, and that exceptions expire, then the problem is no longer an access review backlog. It is a security control that is not altering exposure in a measurable way.

Risk and Threat Considerations

The material risk is persistent excessive access. When governance does not translate into timely removal, stale privileges and orphaned access can remain available long after the business justification has ended. That creates avoidable exposure for misuse, accidental damage, and post-compromise movement.

Failure mechanism: Weak IGA usually fails through stale entitlement state, incomplete ownership, and poor downstream enforcement. Attackers and insiders benefit when revocation is slow, review data is incomplete, or high-risk access survives because no one can prove it is still needed.

Impact: The organisation keeps a larger attack surface than it believes it has. Sensitive systems remain reachable, audit outcomes lose credibility, and a compromise can spread farther because privilege boundaries were never actually reduced.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC — Identity Management, Authentication and Access ControlAccess governance failures directly weaken identity and access control outcomes.
DE.CM — Continuous MonitoringIGA failure often shows up as poor visibility into active versus granted access.
Recommendation — Enforce lifecycle access controls and verify revocation changes actual system access. Monitor entitlement activity and alert on unused or anomalous access.
CIS Controls v86 — Access Control ManagementIGA is fundamentally about managing who has access and removing excess privileges.
5 — Account ManagementStale users and orphaned accounts are classic account management failures.
Recommendation — Review and remove unnecessary access regularly with enforced deprovisioning. Track account ownership and disable dormant or departed-user accounts promptly.
MITRE ATT&CKT1078 — Valid AccountsExcess or stale access increases the value of valid accounts to attackers.
Recommendation — Hunt for over-privileged valid accounts and reduce their attack utility.

Practitioner Guidance

What to verify: Verify that review completion is followed by confirmed entitlement removal, not just ticket closure or attestation. If a revoked permission still works, the governance process has failed at enforcement, regardless of how clean the review report looks.

What to measure: Track the percentage of high-risk entitlements removed within policy timeframes, the rate of exceptions that expire on time, and the share of access decisions backed by current usage evidence. Those measures reveal whether IGA is changing exposure or only recording it.

Decision rule: If an environment cannot show timely deprovisioning, reliable ownership, and current entitlement usage, treat the programme as an access-risk visibility issue first and a process-improvement issue second.

Practitioner takeaway: IGA is failing security goals when it cannot prove that access decisions materially shrink exposure; if the access graph keeps changing faster than governance can enforce it, the control is descriptive rather than protective.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org