Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Who should own IAM service quality when the…
Governance, Ownership & Risk

Who should own IAM service quality when the platform is managed by a third party?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

The business and security function still own the risk, even if operations are delegated. A managed service provider can run monitoring, support, and enhancement work, but the organisation must define service expectations, approve priorities, and confirm the IAM posture still aligns with compliance and business goals. Clear accountability prevents gaps between operational execution and governance responsibility.

Who owns IAM service quality when a third party runs the platform?

Service quality is not the same as service operation. If a vendor runs the platform, the organisation still owns the outcome, including policy, risk acceptance, oversight, and whether the service is fit for business use. That means the internal business and security stakeholders must define expectations, review performance, and keep accountability tied to enterprise risk.

What the organisation must keep control of

A managed IAM service can delegate day-to-day administration, monitoring, and enhancement work, but it cannot delegate accountability. The organisation still needs clear ownership for service levels, change approval, exception handling, and control effectiveness. In practice, that means the business decides what “good” looks like, security decides what is acceptable, and the provider executes within those boundaries.

That ownership model matters most when service quality affects access decisions, identity lifecycle timing, or evidence for audits and compliance. Internal governance should therefore cover both delivery performance and security posture, because a fast service that weakens access control is not actually high quality.

How service quality should be measured and governed

Quality should be measured against outcomes, not just uptime. Useful measures include response times for access requests, timeliness of joiner-mover-leaver actions, accuracy of entitlement changes, incident handling, backlog age, and how often the provider misses agreed control checks. Those metrics should sit inside a formal service review, not be left as informal support reports.

For IAM specifically, service quality also includes whether the control model still works under real operating conditions. The organisation should verify that the provider’s processes preserve segregation of duties, support access review evidence, and keep privileged and non-privileged workflows distinct. IAM and IGA Basics is useful here because it ties service delivery back to the control outcomes that matter.

Risk and Threat Considerations

When a third party operates the platform, the main risk is governance drift: the provider may optimise for operational convenience while the organisation remains accountable for access risk, auditability, and compliance. That gap can leave approval paths unclear, SLAs misaligned with business priority, and control failures unnoticed until an incident or audit exposes them.

Failure mechanism: Service delivery and control ownership become separated, so missed reviews, delayed deprovisioning, weak escalation, or poorly governed exceptions are treated as operational issues instead of access-risk issues.

Impact: Excess privilege, stale access, failed evidence, or unapproved changes can persist longer than intended, increasing exposure and making it harder to prove the IAM control environment is effective.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-2 — Audit EventsIAM service quality depends on auditable control execution and traceability.
AC-2 — Account ManagementManaged IAM service quality affects provisioning, changes, and timely removal of access.
CA-7 — Continuous MonitoringThird-party-run IAM needs ongoing oversight of control health and service performance.
Recommendation — Define audit events and review them to verify IAM operations and control performance. Require account lifecycle controls and validate they are executed on schedule. Monitor IAM control effectiveness continuously and escalate sustained degradation.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsA managed IAM platform creates supplier governance obligations for security and quality.
A.5.22 — Monitoring, review and change management of supplier servicesService quality is governed through review and change control of the outsourced service.
Recommendation — Set security requirements for the supplier relationship and review them regularly. Monitor supplier service changes and review performance against agreed expectations.

Practitioner Guidance

What to prioritise: Put accountability in writing. The provider can own execution, but the internal business owner, security function, and service owner should explicitly own the risk, approval model, and acceptance of exceptions.

What to verify: Confirm the contract and operating model cover service levels, control reporting, escalation, audit support, data handling, and who signs off on risk when the service deviates from target state. If those points are vague, the service will usually drift toward “the vendor’s problem.”

Decision rule: If a service issue can change who gets access, when access is removed, or whether evidence stands up in audit, treat it as a governance issue, not just a support ticket.

Practitioner takeaway: Managed IAM reduces operating burden, but it does not move accountability, the organisation must own the risk and the quality bar even when a third party runs the platform.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org