Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What do teams get wrong about IGA cost…
Governance, Ownership & Risk

What do teams get wrong about IGA cost after implementation goes live?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 14, 2026 Domain: Governance, Ownership & Risk

Teams often undercount recurring operating effort. They focus on the initial rollout, then discover that campaign administration, policy changes, onboarding, remediation follow-up, reporting, troubleshooting, and audit evidence assembly continue every month. If those tasks still require manual work or external consulting, the platform’s true ownership cost stays high even when the software licence looks affordable.

Where IGA Cost Usually Surprises Teams After Go-Live

Most teams price identity governance as if implementation ends at cutover, then treat ongoing administration as a small support task. In reality, IGA creates a steady operating workload: certification campaigns need scheduling and review, policies need tuning, exceptions need follow-up, and access changes keep arriving after launch. The hidden cost is not just headcount, it is the repeatable process work that software rarely removes on its own.

That is why live-state ownership often looks cheaper on a licence sheet than it does in practice. If joiner-mover-leaver handling, audit evidence, remediation tracking, and troubleshooting still depend on analysts or consultants, the platform has shifted the control point, not eliminated the labour. In practice, teams discover this only after the first few certification cycles and audit requests, when the “steady state” proves busier than the implementation project.

What Drives the Ongoing Run Cost

The biggest mistake is assuming IGA is mostly a product purchase. Once the system is live, cost is driven by operating model quality: who resolves certification findings, who curates entitlements, who handles edge cases, and who owns policy exceptions. A healthy deployment reduces manual effort over time, but it does not remove the need for governance, content maintenance, and business coordination.

Several recurring tasks usually stay expensive:

  • Campaign administration: launching reviews, chasing reviewers, and re-running incomplete campaigns.
  • Policy maintenance: updating rules when roles, apps, or organisational structures change.
  • Remediation follow-up: closing the loop when access removals are delayed or partially executed.
  • Audit support: producing evidence that approvals, reviews, and exceptions actually happened.
  • Integration upkeep: fixing broken connectors, attribute mappings, and upstream data quality issues.

If the deployment has weak identity data or poor application onboarding, the platform becomes a work queue for manual cleanup instead of an automation layer. That is where the true cost sits: not in the licence itself, but in the labour needed to make the governance process trustworthy. The practical reality is that IGA gets more expensive whenever the organisation expects policy enforcement to compensate for messy upstream identity and entitlement data.

How Mature Teams Keep the Cost from Reappearing in Other Forms

Tighter governance often increases operating overhead at first, requiring teams to balance control strength against the cost of maintaining it. Mature programmes reduce long-term spend by designing for simpler operations, not by chasing the lowest initial implementation price. They limit custom logic, standardise entitlements, and define which exceptions are truly worth supporting.

Useful practitioner moves include:

  • Define service ownership for campaigns, entitlement changes, and remediation before go-live.
  • Measure the percentage of access decisions that can be completed without manual intervention.
  • Track how many policy exceptions recur every cycle, because repeated exceptions usually signal bad role design.
  • Keep connector scope narrow until the process is stable, then expand only where it reduces net effort.
  • Require evidence-ready workflows so audit requests do not become a separate reporting project.

Teams also underestimate how much cost is driven by change management. If business owners do not understand review responsibilities, the IGA tool shifts work to identity operations rather than distributing it properly. The best cost control is usually simplification: fewer bespoke approvals, fewer entitlement variants, cleaner joiner-mover-leaver rules, and less dependence on consultants for routine triage. That approach keeps governance scalable instead of turning every access change into a bespoke service desk case.

Common Variations and Edge Cases

Stricter governance often raises short-term effort, because more controls mean more review, more exceptions, and more cleanup before the process stabilises. That tradeoff is acceptable when the organisation has high audit pressure, complex entitlements, or frequent joiner-mover-leaver events, but it can be wasteful if the deployment is oversized for the actual risk profile.

Some environments have cost patterns that are easy to miss. A small application portfolio with many custom roles can cost more to govern than a larger estate with clean role models. A heavily outsourced operating model can also look efficient at first while hiding dependency risk in external remediation and reporting support. Likewise, organisations that add more campaigns without improving data quality often create the appearance of maturity while increasing churn.

The other edge case is over-automation. Automating approvals or access rules before the underlying entitlement model is stable can lock in bad governance at scale. The question is not whether the tool is live, but whether the organisation can sustain it with its own people, data, and process discipline.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CIS Controls v85 — Account ManagementIGA run costs are driven by ongoing account and access governance work.
6 — Access Control ManagementIGA cost is tied to how access requests, approvals and exceptions are governed.
8 — Audit Log ManagementAudit evidence assembly is a recurring post-go-live IGA cost driver.
Recommendation — Standardise account review and remediation workflows to reduce recurring manual effort. Implement structured access control processes to limit recurring governance overhead. Retain auditable records that make review and evidence collection efficient.
NIST CSF 2.0GV.OC — Organizational ContextIGA cost depends on defining the operating model, ownership and scope.
PR.AA — Identity Management, Authentication, and Access ControlIGA programmes manage recurring access lifecycle and governance work.
GV.RM — Risk Management StrategyTeams must budget for steady-state governance effort as a managed risk.
Recommendation — Define ownership and scope for identity governance operations before rollout. Align access lifecycle processes with the identity governance operating model. Bake recurring operating cost into the risk and budget model for IGA.

Practitioner Guidance

What to prioritise: Budget for campaign operation, remediation, and evidence production as permanent run costs, not optional support. If those functions are not owned explicitly, they will reappear as ad hoc analyst work or consulting spend.

What to verify: Check whether every recurring IGA activity has a named business owner, a measurable completion target, and a documented fallback path for incomplete reviews, failed connectors, and unresolved exceptions. If not, the platform is likely masking manual labour rather than reducing it.

Decision rule: If the platform only looks affordable when you exclude internal operations and audit support, treat the deployment as under-costed. If it remains affordable after adding the people and process load, the model is more realistic.

Practitioner takeaway: The real question is not whether IGA reduces risk, but whether the organisation has designed a steady-state operating model that can keep the control effective without turning governance into a perpetual manual service.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 14, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org