Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What happens when IGA programmes rely on manual…
Governance, Ownership & Risk

What happens when IGA programmes rely on manual work disguised as software savings?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 14, 2026 Domain: Governance, Ownership & Risk

The platform may appear inexpensive, but the organisation is quietly paying for missing capability with staff time. Manual reviewer reminders, spreadsheet correlation, ticket creation, deprovisioning, and evidence assembly all turn into ongoing labour costs. That approach also slows governance outcomes, because access decisions and remediation depend on people moving files instead of automated workflows.

Why Manual “Savings” Usually Just Move the Bill

IGA programmes look cheaper when the software line item is low, but the hidden cost is that people become the workflow engine. Reviewer chasing, exception follow-up, spreadsheet reconciliation, ticket handoffs, deprovisioning checks, and evidence assembly all consume recurring labour, which turns a supposed platform saving into an operating expense. The result is often slower access governance, not leaner governance. A common pattern is that teams buy tooling to reduce effort, then recreate the missing automation with email and spreadsheets.

That tradeoff matters because governance work is time-sensitive: access changes lose value when they sit in queues, and control evidence becomes less reliable when it is assembled manually after the fact. In practice, manual work often survives as “temporary” process glue long after the platform is live.

How the Workload Shows Up in Practice

The strongest sign of disguised manual work is that the platform creates alerts and tickets but does not complete the decision path. Reviewers still need reminders, approvers still chase context, and operators still copy data between systems to answer basic questions such as who has access, why they have it, and whether it was removed on time. That means the organisation is paying twice, once for the platform and once for the labour needed to make the platform usable.

  • Review campaigns may be launched automatically but closed by spreadsheet comparison and manual exception handling.
  • Access removals may require a human to open, route, and verify tickets instead of triggering a controlled workflow.
  • Evidence for audits may be reconstructed from email, screenshots, and exports rather than produced by the system of record.
  • Role or entitlement clean-up may depend on analysts mapping mismatched records across HR, directory, cloud, and application systems.

For identity-heavy programmes, the labour burden scales with the number of accounts and access edges, not with the number of licences purchased. NHIMG data shows how often that burden lands on weak visibility, with Ultimate Guide to NHIs reporting that only 5.7% of organisations have full visibility into their service accounts. Even when the immediate question is about IGA economics, poor visibility is what turns “automation” into repeated manual triage.

These controls tend to break down when identity data is fragmented across legacy systems, SaaS apps, and custom entitlements because the platform cannot reliably decide without human cleanup.

Where the Savings Claim Breaks Down

Tighter automation often increases upfront implementation effort, so organisations have to balance lower steady-state labour against higher design and integration work. The savings claim fails when the programme is measured by licence cost alone instead of by the cost of operating the control over time.

The main edge case is partial automation: if the platform handles requests but not approvals, or approvals but not downstream enforcement, the manual residue becomes the real system. Another common issue is that teams accept low-quality entitlement data because cleansing feels expensive, only to pay that cost repeatedly in every review cycle. Guidance is evolving here, but the practical rule is simple, use software to remove recurring decision and routing work, not just to formalise it.

When a programme still needs humans to discover, correlate, approve, deprovision, and prove the outcome for every cycle, the organisation has not bought efficiency, it has purchased a more organised manual process.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST CSF 2.0 set the technical controls, while ISO/IEC 42001:2023 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS 5 — Account ManagementIGA work centers on managing access lifecycle and reviews.
Recommendation — Automate account review and removal workflows to reduce manual governance labour.
NIST CSF 2.0PR.AA — Identity Management, Authentication and Access ControlAccess governance effectiveness depends on timely identity and entitlement control.
GV.OV — OversightManual-heavy IGA programs often hide operating cost behind licence savings.
Recommendation — Implement access governance controls that reduce manual review and remediation work. Track operating effort and control completion, not just software cost.
ISO/IEC 42001:2023AI governance systemOnly applicable if IGA work is being automated with AI decision support.
Recommendation — Govern automated decision support so human review is reserved for exceptions.

Practitioner Guidance

What to prioritise: Separate “workflow completed by the system” from “workflow tracked by the system.” If reviewers, approvers, or operators still have to move data between tools, the platform is not reducing labour in the part of the process that usually dominates cost.

What to verify: Check whether the programme can produce access decisions, removals, and audit evidence from system-generated records alone. If success depends on exports, reconciliations, or inbox chasing, count that as operating labour, not automation.

Decision rule: If a control still needs repeated human follow-up to finish, treat the manual step as a core dependency and include it in the business case, staffing plan, and risk assessment.

Practitioner takeaway: The real question is not whether the platform is inexpensive, but whether it eliminates recurring human effort at the exact points where governance work must be timely, accurate, and provable.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 14, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org