Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk Who should be accountable for IGA selection when…
Governance, Ownership & Risk

Who should be accountable for IGA selection when IT, security, HR, compliance, and finance all have different priorities?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 24, 2026 Domain: Governance, Ownership & Risk

Accountability should be shared, but one function must own the final decision criteria. IT should lead operational fit, security should pressure-test coverage and risk reduction, compliance should validate evidence and review workflows, HR should assess employee experience, and finance should confirm cost assumptions. If one group dominates, the platform is usually chosen against only part of the problem it must govern.

Why This Matters for Security Teams

IGA selection is not just a tooling choice, it is a governance decision that shapes how access is requested, approved, reviewed, and revoked across the business. When IT, security, HR, compliance, and finance each optimise for their own priorities, the result is usually a platform that looks good in one workshop and fails in day-to-day operations. NHI Management Group’s Ultimate Guide to NHIs — Regulatory and Audit Perspectives reinforces that governance and evidence quality matter as much as feature depth, while NIST Cybersecurity Framework 2.0 frames this as an outcomes problem, not a procurement contest.

The practical risk is misaligned ownership: IT may favour integration speed, security may demand stronger controls, HR may want simple joiner-mover-leaver flows, compliance may require audit trails, and finance may push lowest total cost. None of those views is wrong, but none of them is sufficient alone. The deciding function needs authority to arbitrate tradeoffs against explicit criteria, then document why those criteria win. In practice, many security teams encounter broken IGA ownership only after access reviews stall, audit evidence gaps appear, or revocation workflows fail in production.

How It Works in Practice

The cleanest model is shared accountability with one named final owner for decision criteria, usually a governance, security, or enterprise architecture function with enough mandate to resolve conflict. That owner should not make the decision in isolation. Instead, each stakeholder group defines measurable requirements before vendors are scored. IT validates directory, HRIS, ERP, ticketing, and cloud integration fit. Security evaluates least privilege, separation of duties, logging, privileged access handling, and control coverage. Compliance checks attestations, evidence export, review cadence, and policy traceability. HR focuses on employee and manager workflow usability. Finance confirms licensing, implementation, and operating costs, including hidden process overhead.

A workable selection process usually includes:

  • one requirements register with weighted criteria agreed before demos
  • scenario-based testing for joiner, mover, leaver, contractor, and exception workflows
  • evidence review against audit and control requirements, not just feature lists
  • proof that workflows can support both human identities and, where relevant, NHIs with lifecycle controls from Top 10 NHI Issues
  • clear decision rights for disputes, so no function can veto outside its domain

For teams aligning to control frameworks, the selection process should also map to identity governance expectations in ISO/IEC 27001:2022 and evidence retention expectations in NIST SP 800-53 Rev 5 Security and Privacy Controls. These controls tend to break down when one department buys the platform on its own because integration, approval routing, and control evidence are discovered only after rollout.

Common Variations and Edge Cases

Tighter accountability often increases process overhead, requiring organisations to balance decision speed against governance quality. That tradeoff is real, especially in mergers, regulated sectors, and global enterprises where every stakeholder group has legitimate operational constraints. Current guidance suggests the best approach is a steering model with defined RACI boundaries, not a unanimous committee and not a single-function mandate disguised as consensus.

There are a few common edge cases. In smaller organisations, one function may own the final decision and still consult everyone else, but the criteria must remain explicit. In heavily regulated environments, compliance may have a stronger veto role on evidence and control design, while finance still owns budget approval. In larger enterprises, HR and IT often influence the request and provisioning experience more than the scoring model itself. For NHI-heavy environments, the evaluation should expand beyond classic IGA workflows to cover secrets, service accounts, and lifecycle controls described in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs. That keeps the decision grounded in operational reality instead of human-only assumptions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.OC-01Shared governance and decision ownership are central to selecting an IGA platform.
NIST SP 800-63Identity lifecycle assurance depends on consistent governance across joiner-mover-leaver flows.
OWASP Non-Human Identity Top 10NHI-06NHI lifecycle governance matters when IGA must cover non-human identities too.
NIST AI RMFGOVERNDecision accountability and role clarity are part of trustworthy governance.
CSA MAESTROGOVCross-functional governance is necessary for secure platform selection and oversight.

Use identity assurance and lifecycle expectations to test whether IGA workflows are operationally sound.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org