Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should organisations include in IGA total cost…
Governance, Ownership & Risk

What should organisations include in IGA total cost of ownership calculations?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 6, 2026 Domain: Governance, Ownership & Risk

They should include licensing, professional services, integrator cost, internal FTE time, and ongoing maintenance. A narrow software-only view hides the real delivery burden and makes deployments look cheaper and faster than they actually are.

What belongs in an IGA total cost of ownership model?

The useful way to price IGA is to treat the platform as only one component of delivery. total cost of ownership should capture software licensing, implementation and integration services, internal delivery effort, and the ongoing cost of operating the programme after go-live. That wider view is what separates a procurement estimate from a realistic business case.

Why software-only pricing usually understates the true cost

Most of the cost in IGA is not the licence line item. The hard work sits in connector build-out, role and policy design, workflow tuning, access review operations, testing, cutover, and remediation of messy entitlement data. A narrow view misses the effort required to make the controls usable, and that is why projects often feel more expensive than the original bid.

Internal effort also needs to be counted explicitly. Security, IAM, application owners, HR, procurement, audit, and business approvers all contribute time to design decisions, data cleansing, role mapping, exception handling, and recurring certification campaigns. The IGA platform may be software, but the operating model is a people-and-process investment as much as a technical one.

How to structure the TCO calculation

Start with direct vendor costs, then add the delivery costs required to reach steady state. A practical model usually includes licence fees, implementation partner or systems integrator charges, internal FTE time, training, connector maintenance, support renewals, and the ongoing effort to manage access reviews, lifecycle workflows, and policy changes. If the model cannot show who does the work, it is incomplete.

It also helps to separate one-time and recurring cost buckets. One-time costs typically include discovery, architecture, integration, role engineering, migration, and testing. Recurring costs include subscriptions, support, admin time, rule maintenance, onboarding new systems, and continuous access-governance operations. That distinction makes it easier to compare vendors and to forecast the steady-state run cost after deployment.

For buyer guidance on the kinds of implementation and governance effort that should be expected, the IGA Buyer's Guide is useful because it frames evaluation around lifecycle, requests, reviews, roles, SoD, connectors, and governance work rather than only product features. For the operating model behind that work, IAM and IGA Basics helps anchor the difference between access administration and governance.

Where hidden cost usually appears in practice

Hidden cost often shows up in connector complexity, because each target system has its own integration pattern, data quality problems, and exception handling. Another common surprise is policy and role rationalisation: if roles are poorly designed, the programme absorbs extra effort every time access is reviewed or a new application is onboarded. These are delivery costs, not edge cases.

Organisations also underestimate the operational overhead after initial rollout. Access review campaigns, leaver processing, role changes, recertification, audit evidence, and exception tracking all require ongoing ownership. That is why lifecycle design matters to TCO, not just initial procurement. The Joiner-Mover-Leaver (JML) Guide and the Access Reviews and Certification Guide both illustrate why day-two governance work belongs in the cost model.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-5 — Account ManagementIGA TCO includes lifecycle operations, reviews, and access administration costs.
Recommendation — Budget for recurring account and access governance work, not just software acquisition.
NIST SP 800-53 Rev 5PM-11 — Mission and Business Process DefinitionTCO should reflect the business processes and operating effort IGA must support.
IA-5 — Authenticator ManagementIGA programmes carry ongoing credential and access lifecycle management costs.
Recommendation — Define the operating processes and ownership model before finalising the business case. Include credential lifecycle administration and renewal overhead in the cost model.
ISO/IEC 27001:2022A.5.15 — Access controlIGA is fundamentally about governing access, so its operating cost tracks access-control administration.
Recommendation — Include the people and process cost of access governance alongside licence spend.

Practitioner Guidance

What to prioritise: Build the business case from the operating model backward. If you cannot identify the teams, hours, and integration work needed to run IGA at scale, the TCO is not credible yet.

What to verify: Check whether the estimate includes implementation partner fees, internal reviewer time, admin overhead, role engineering effort, and ongoing connector maintenance. Those items usually determine whether the programme is sustainable.

Common mistake: Treating licence price as the total programme cost. That shortcut tends to understate delivery effort and creates optimism bias in schedule and ROI claims.

Practitioner takeaway: A sound IGA TCO model measures what it takes to operate governance continuously, not just what it costs to buy the platform.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org