Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when identity governance is centralised but…
Governance, Ownership & Risk

What breaks when identity governance is centralised but scrutiny is local?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Controls can look compliant in a global policy but fail when a regional regulator, auditor, or incident responder asks for specific evidence. The failure is usually not the control idea itself, but the inability to prove ownership, revocation, or lawful access at the right moment.

Why central identity policy breaks at the local evidence layer

Centralising identity governance creates consistency in definitions, workflows, and policy intent, but scrutiny happens where the evidence is consumed. A global rule can say access is approved, revoked, or reviewed; a regional regulator or auditor wants to see who approved it, when it was enforced, and whether the right jurisdictional rule was applied. The control fails when governance exists as policy text but not as provable, local evidence.

That gap is common in identity programmes that assume one approval path or one reporting view can satisfy every oversight body. In practice, the local question is not “does the policy exist?” but “can you prove this specific identity had the right access, at the right time, under the right authority?”

Well-run identity governance depends on IAM and IGA basics, but the evidence standard changes when oversight is local. Ownership, recertification, and entitlement decisions must be traceable to the population and control point being reviewed, not just to a central policy statement.

Where compliance breaks: ownership, revocation, and lawful access

The practical failure mode is usually one of three things: ownership cannot be demonstrated, revocation cannot be timed precisely, or access cannot be tied to a lawful basis at the moment it mattered. Central teams may hold a complete policy record, yet still lack the local artefacts needed to satisfy a plant, country, business unit, or sector-specific review.

This becomes sharper for identities that move across regions, subsidiaries, or regulated services. If the approval chain, entitlement model, or offboarding workflow is centralised but the audit trail is fragmented, you can end up with access that looks controlled in aggregate while still failing a local challenge on recertification, revocation latency, or separation of duties. Those are the moments when identity governance stops being an organisational design problem and becomes an evidence problem.

Access reviews and certification only work when they close the loop at the review boundary being tested. Central approval alone is not enough if the reviewer cannot see the actual entitlement, business justification, and remediation outcome for the scope they are accountable for.

Segregation of duties is another example where local scrutiny often exposes what central policy hides, because the conflict may exist only within a specific system, region, or operating unit.

Designing governance so the evidence survives regional scrutiny

Identity governance needs an evidence model, not just a policy model. That means mapping each controlled action to an accountable owner, a revocation path, a review cadence, and a local proof point that can be produced on demand. The most robust programmes separate the global standard from the local evidence pack, then make sure each reviewable scope can be reconstructed independently.

At scale, this usually requires cleaner role design, tighter joiner-mover-leaver discipline, and more explicit handling of exceptions. A central policy can define the rule, but a local reviewer will ask whether the rule was actually applied to the identity in question. If the answer depends on tribal knowledge, spreadsheets, or a central team translating policy after the fact, the model is already too brittle.

Joiner-Mover-Leaver (JML) Guide is useful here because revocation and re-assignment need to be provable, not inferred. Role mining and role design also matter because poor roles make local evidence harder to interpret and easier to challenge.

Risk and Threat Considerations

Central governance with local scrutiny creates a blind spot: the organisation may believe access is controlled while the local reviewer sees only missing proof. That gap raises regulatory, audit, and incident-response risk because unresolved ownership or revocation questions often surface only after a challenge, complaint, or breach investigation.

Failure mechanism: policy decisions are made centrally, but enforcement and evidence are not preserved in a form that survives local examination. The resulting mismatch can leave stale access, delayed revocation, or ambiguous lawful authority hidden until the identity is tested by a regulator, auditor, or responder.

Impact: the organisation may fail an audit, be unable to defend an access decision, or spend incident-response time reconstructing authority after the fact. In regulated environments, that can turn an otherwise routine access question into a formal control failure.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementCentral governance and local evidence both depend on IAM control structure and traceability.
Recommendation — Map identity decisions to IAM evidence that local reviewers can independently verify.
NIST SP 800-53 Rev 5AC-1 — Access Control Policy and ProceduresThe question concerns whether centrally defined access policy survives local audit scrutiny.
AU-2 — Audit EventsLocal scrutiny depends on recorded events that prove ownership, revocation, and approval timing.
Recommendation — Document access policy with evidence that each jurisdiction can test against local scope. Log the identity events needed to reconstruct access decisions during review.
ISO/IEC 27001:2022A.5.15 — Access controlAccess governance must be enforced and evidenced consistently across local oversight contexts.
A.5.16 — Identity managementThe issue centers on proving who owns and is responsible for identities across regions.
Recommendation — Define access control rules so they can be demonstrated at the point of local scrutiny. Maintain identity records that support ownership and accountability under local review.

Practitioner Guidance

What to verify: Test whether every high-value access decision can be reconstructed from local evidence alone, including approver, timestamp, scope, and revocation outcome. If the answer requires a central team to explain the record manually, the control is not locally defensible.

Decision rule: If a control must satisfy multiple jurisdictions or business units, treat evidence locality as a first-class requirement, not a reporting afterthought. Centralise policy, but decentralise proof.

What good looks like: a regional auditor, regulator, or incident responder can trace the same identity event end to end without relying on informal context or exception memory. The practitioner takeaway is that governance succeeds only when the proof model is as distributed as the scrutiny model.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org