Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks in practice when organisations do not…
Governance, Ownership & Risk

What breaks in practice when organisations do not have IGA in place?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 10, 2026 Domain: Governance, Ownership & Risk

When IGA is missing, organisations lack the plumbing needed for identity processes to flow. That shows up as slow onboarding, inconsistent access changes, poor offboarding, and weak coordination between identity, privileged access, and broader IT operations. The result is not just inefficiency. It becomes harder to enforce secure access rules, maintain accountability, and support growth without adding risk.

Why IGA Gaps Turn Routine Identity Work Into Operational Drift

When IGA is absent, the identity function stops behaving like a governed system and starts acting like a series of disconnected tickets, approvals, and manual exceptions. That matters because joiner, mover, and leaver processes are where access is supposed to stay aligned with role, risk, and accountability. Without a control plane for those changes, organisations often accumulate orphaned access, inconsistent approvals, and privilege that no one can clearly explain or confidently remove. The issue is not only administrative overhead; it is loss of control over who has what access, why they have it, and whether it is still justified.

Identity governance failures also show up in places teams do not always connect to IGA at first: privileged access reviews, application access recertification, audit evidence, and third-party access tracking. The broader the environment, the more manual handling turns into inconsistency. NIST’s NIST SP 800-53 Rev 5 Security and Privacy Controls is useful here because it frames access control and accountability as ongoing control objectives, not one-time setup tasks. In practice, many organisations discover the absence of IGA only after access reviews become unmanageable or an offboarding gap exposes how much trust was being carried by spreadsheets and memory.

How Identity Governance Breaks Down in Practice

IGA provides the rules and workflow layer that connects identity events to access decisions. In a mature setup, it helps determine who should receive access at onboarding, who should lose it after a job change, and who should be removed when they leave. It also creates an auditable record of approvals, exceptions, and reviews. When that layer is missing, identity processes usually still exist, but they are spread across HR notifications, ticket queues, directory changes, application owner emails, and manual spreadsheets. The result is slower execution and weaker control.

The operational breakage tends to follow a predictable pattern:

  • Onboarding becomes inconsistent because access is granted by ad hoc request rather than role or policy.
  • Role changes leave behind stale access because nobody owns the full chain of review and removal.
  • Offboarding becomes partial, especially where multiple applications, service accounts, or delegated admin paths exist.
  • Recertification turns into a burden because reviewers lack reliable inventory, entitlement context, or ownership data.

That matters most where identities span cloud platforms, SaaS tools, directory services, and privileged systems, because manual coordination does not scale with complexity. NHIMG’s guide on the Ultimate Guide to NHIs is relevant because the same governance gaps that affect human access also affect machine accounts, API keys, and other non-human identities that often outlive the employees who deployed them. For teams managing a large number of service accounts, the control problem is not merely speeding up requests; it is keeping entitlement state current enough that access decisions remain trustworthy.

Where IGA is missing, organisations also lose a dependable way to prove that access was approved, reviewed, and revoked on time. That weakens audit readiness and makes it harder to separate legitimate exceptions from hidden drift. These controls tend to break down when access decisions are distributed across too many application owners because no single workflow has enough context to enforce policy end to end.

Common Breakpoints and Edge Cases

Tighter identity governance often increases process overhead, so organisations have to balance speed against assurance. That tradeoff is most visible in environments with highly variable project teams, frequent role changes, or many short-lived contractors, where a rigid manual process can become a bottleneck. Current guidance suggests the answer is not to remove governance, but to automate the repeatable parts and reserve human judgement for exceptions that genuinely need it.

One common edge case is that organisations believe directory cleanup equals governance. It does not. A disabled account in one system can still leave active roles, tokens, delegated permissions, or privileged access paths elsewhere. Another is that teams treat IGA as a human-user problem only, even though machine identities often create the largest hidden cleanup burden because they do not self-report lifecycle changes. If the environment has many application-to-application connections, governance has to cover non-human entitlements as well as employee access.

A second edge case is decentralised ownership. Where each app team manages its own access rules, the organisation may still have approvals, but not a consistent control model. That creates a situation where access is technically managed but operationally ungoverned. The practical test is whether the organisation can answer, quickly and with evidence, who approved access, whether it is still required, and what gets revoked automatically when the identity changes. When that cannot be answered, the gap is no longer administrative; it is a control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, CIS Controls v8, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AC-1 — Identity Management, Authentication and Access ControlIGA governs access lifecycle and entitlement control across identities.
PR.AC-4 — Access Permissions and Authorizations are ManagedMissing IGA leads to stale and inconsistent access permissions.
GV.RM-01 — Risk Management StrategyIGA gaps create governance and accountability risk across the identity estate.
Recommendation — Define and enforce identity lifecycle controls for access approvals, changes, and removals. Review and remove access on role change and termination with consistent authorization rules. Treat identity governance gaps as a formal risk domain and assign ownership for remediation.
CIS Controls v86.1 — Establish an Access Control PolicyIGA is the operational mechanism that sustains consistent access policy enforcement.
5.3 — Disable Dormant and Stale AccountsWithout IGA, dormant and orphaned accounts persist after lifecycle events.
6.3 — Manage Administrative PrivilegesIGA gaps often leave privileged access unmanaged or poorly reviewed.
Recommendation — Standardize access policy and map identity changes to enforced entitlement decisions. Automate detection and removal of stale accounts and unused access paths. Restrict privileged access to approved, reviewed, and time-bounded assignments.
NIST SP 800-63IAL2 — Identity Assurance Level 2IGA relies on trustworthy identity records and lifecycle assurance.
Recommendation — Link identity proofing and account lifecycle events to authoritative identity records.
NIST Zero Trust (SP 800-207)Access Control Principles — Least Privilege and Continuous VerificationIGA supports ongoing least-privilege decisions in a zero-trust model.
Recommendation — Continuously verify entitlement need and reduce standing access wherever possible.

Practitioner Guidance

What to prioritise: Start with the highest-risk identity transitions, not with the most visible requests. Joiner, mover, leaver flows, privileged entitlements, and third-party access usually reveal the largest governance gaps fastest because they expose where access changes are not tied to a reliable lifecycle trigger.

What to verify: Confirm that the organisation can produce current entitlement ownership, approval history, and revocation evidence for both human and non-human identities. If those records only exist in ticket comments, spreadsheets, or tribal knowledge, the process is not governed enough to trust at scale.

Common mistake: Treating periodic review as a substitute for automated lifecycle control. Reviews can find drift, but they rarely prevent it, and they become less effective as the number of identities, roles, and systems grows.

Practitioner takeaway: The real question is not whether access can be requested, but whether the organisation can keep access state accurate as identities change; without that, IGA absence turns every identity event into a potential control gap.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 10, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org