Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What breaks when identity governance is fragmented under…
Governance, Ownership & Risk

What breaks when identity governance is fragmented under DORA?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 7, 2026 Domain: Governance, Ownership & Risk

Fragmented identity governance breaks the ability to prove who had access, why they had it, and whether that access still matched policy. Under DORA, that means resilience evidence becomes incomplete, lifecycle actions are harder to justify, and audit response becomes reconstruction instead of verification.

Where fragmentation breaks the identity governance chain

Fragmentation usually does not fail at a single control. It fails when request, approval, provisioning, review, and revocation live in separate tools or teams, so no one can show a continuous control story. That is why an identity and access governance baseline matters: it links entitlements, ownership, and review evidence into one accountable record.

When that chain is broken, the practical loss is traceability. You may still have logs, tickets, and spreadsheets, but they no longer prove that access was approved for the right reason, by the right owner, for the right period. Under DORA, that weakens the organisation's ability to show operational control over identity-related changes during normal operations and during incidents.

Why DORA makes disconnected identity evidence a resilience problem

DORA is not only about having controls, it is about demonstrating that critical ICT risk is governed consistently and can be evidenced under stress. A fragmented model turns resilience evidence into a reconstruction exercise, because teams must stitch together who approved access, which system created it, and whether the entitlement still matched the policy when the issue occurred. The governance problem becomes more visible when identity controls are mapped to DORA as part of the broader regulatory control set.

That matters most when access decisions cross operational, outsourced, or regulated boundaries. If the identity owner, the application owner, and the compliance reviewer all hold partial context, the organisation can end up with policy intent on one side and operational reality on the other. DORA amplifies that gap because evidence quality itself becomes part of operational resilience, not just an audit convenience.

What fragmented governance prevents you from proving

Fragmentation most often breaks three proofs: who had access, why they had it, and whether it was still justified at the point of use. Without a single governance view, recertification can miss stale entitlements, revocation can lag behind role change, and exceptions can survive past their intended expiry. An access model that keeps reviews, roles, and joiner-mover-leaver actions aligned with the access review and certification process gives you a cleaner evidentiary trail.

Fragmented control also weakens ownership. If no system clearly assigns accountability for a user, service account, or third-party access path, then remediation becomes ad hoc and review outcomes become hard to defend. That is why lifecycle governance is not a side issue here, and why the joiner-mover-leaver process is often where proof either holds together or falls apart.

Risk and Threat Considerations

Fragmented identity governance creates a soft target for both control failure and abuse. Stale or overbroad access can survive because no single team sees the full path from entitlement creation to revocation, and that creates opportunity for privilege creep, orphaned access, and delayed response when something looks wrong.

Failure mechanism: Control breaks occur when approval, provisioning, attestation, and offboarding are distributed across disconnected records or teams, so policy exceptions are not reconciled back to live access.

Impact: Attackers or insiders can exploit the resulting uncertainty to retain access longer, move laterally, or hide unauthorized use inside incomplete evidence, while defenders lose the ability to verify control effectiveness quickly.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.RM-01 — Risk Management StrategyFragmented identity governance is a risk-management issue needing enterprise control ownership.
Recommendation — Define a governance strategy that assigns ownership for access approvals, reviews, and revocation evidence.
NIST SP 800-53 Rev 5AC-2 — Account ManagementFragmentation breaks the lifecycle tracking of accounts and entitlements.
AU-2 — Audit EventsDORA evidence depends on reconstructable records of access changes and review actions.
IA-5 — Authenticator ManagementFragmented governance often leaves credentials and secrets without clear lifecycle control.
Recommendation — Centralise account lifecycle tracking so provisioning, review, and deprovisioning stay traceable. Log approval, entitlement change, and revocation events in a system that supports audit reconstruction. Manage credentials centrally so issuance, rotation, and revocation stay provable.
ISO/IEC 27001:2022A.5.15 — Access controlThe topic is about governing and proving who can access what and why.
Recommendation — Set access-control ownership and review rules that preserve a defensible entitlement trail.

Practitioner Guidance

What to verify: Confirm that every access entitlement has a traceable owner, approval path, expiry or review date, and revocation record. If any of those elements lives only in email, spreadsheets, or a local team workflow, treat the governance model as fragmented until proven otherwise.

Decision rule: If you cannot answer the access question from a single authoritative record set, prioritise governance consolidation before expanding more reviews. More attestations do not fix broken evidence chains if provisioning and deprovisioning still occur outside the control plane.

Practitioner takeaway: Under DORA, fragmented identity governance is a resilience defect, not just a reporting inconvenience, because the real failure is the loss of defensible proof over access change, ownership, and revocation.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 7, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org