Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

IAAM

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Governance, Ownership & Risk

IAAM is a broader identity operating model that combines identity management, access management, and authorisation across the full lifecycle of a person or entity. It covers onboarding, account creation, access assignment, periodic review, and offboarding, with the goal of keeping access aligned to current business need.

What IAAM Covers Across the Identity Lifecycle

IAAM is not just account administration. It ties identity management, access management, and authorization together so organisations can create, assign, change, review, and remove access in step with business need and role change.

That lifecycle view matters because access is never static. A useful IAAM model tracks who or what the identity represents, what it can do, and when that access should be revalidated or withdrawn.

How IAAM Relates to Identity Governance

IAAM sits close to identity governance because it connects provisioning, entitlement decisions, periodic access review, and offboarding into one operating model. It helps reduce the gap between an identity being active in a system and that identity still needing the access it already has.

This is where organisations usually feel the operational weight of the model: joins, moves, and leaves are not separate chores, but linked stages in the same control chain. If any stage is weak, access drift accumulates.

Why IAAM Matters for Access Control

At a control level, IAAM is about making access decisions reflect current need rather than inherited history. That means access assignment should be deliberate, review should be periodic, and removal should be prompt when an identity no longer needs a privilege.

In practice, IAAM is often the difference between an account that exists and an account that is still appropriately authorised. The stronger the mapping between identity, entitlement, and business purpose, the less room there is for excess access to persist.

Where IAAM Breaks Down

IAAM fails when identity records, entitlement records, and ownership responsibilities fall out of sync. Common breakdowns include delayed deprovisioning, stale entitlements after role changes, inconsistent review processes, and unclear accountability for approving access.

Those failures do not just create administrative noise, they can leave active accounts with outdated permissions long after the business reason has disappeared. Over time, that weakens confidence in access decisions across the environment.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementIAAM centers on provisioning, modifying, reviewing, and removing account access across its lifecycle.
AC-6 — Least PrivilegeIAAM is meant to keep assigned access aligned to current business need and limit excess entitlement.
IA-5 — Authenticator ManagementIAAM programs often manage credentials and access material as part of identity lifecycle operations.
Recommendation — Apply AC-2 to govern account creation, periodic review, and timely deactivation of stale access. Apply AC-6 to restrict each identity to the minimum access needed for its current role. Apply IA-5 to manage authenticator lifecycle, renewal, and revocation alongside identity changes.
NIST CSF 2.0PR.AA-01 — Identities and credentials are issued, managed, verified, revoked, and auditedIAAM is fundamentally about issuing, managing, reviewing, and revoking identities and access over time.
PR.AA-05 — Physical and logical access is limited to authorized users, processes, and devicesIAAM exists to keep access constrained to what is currently authorised.
Recommendation — Use PR.AA-01 to keep identity and access records current across onboarding, changes, review, and offboarding. Use PR.AA-05 to enforce current authorisation boundaries and remove access that is no longer needed.
ISO/IEC 27001:2022A.5.16 — Identity managementIAAM directly concerns the assignment, maintenance, and removal of identities and associated access.
A.5.18 — Access rightsIAAM covers how access rights are granted, reviewed, and withdrawn as business need changes.
Recommendation — Implement A.5.16 to manage identity records through onboarding, change, review, and deprovisioning. Implement A.5.18 to control entitlement approval, review, and timely removal of access rights.

Practitioner Guidance

Governance implication: Treat IAAM as an operating model with named ownership, not as a one-time provisioning activity. The value comes from keeping joiner, mover, reviewer, and leaver decisions consistent across the full lifecycle, so access remains aligned to purpose rather than historical convenience.

What to watch for: Watch for entitlements that survive role changes, accounts with no clear owner, and reviews that happen after access has already become stale. Those are usually the earliest signs that identity and authorization processes have drifted apart.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org