Identity and Access Management is widely recognized as critical. It supports security, enables business processes, and helps meet regulatory requirements. Nevertheless, IAM programs struggle to progress in a predictable and coordinated way.
During my recent webinar “From IAM Pitfalls to Realistic Roadmaps: Structuring Identity Projects for Success”, several polls were conducted to better understand priorities and challenges. The results highlight a gap between the importance of IAM and the way it is implemented in practice, raising the question of why it remains difficult to turn IAM into an executable program.
These results, combined with observations from advisory work, point to a pattern: the challenge lies less in defining individual IAM activities and more in aligning priorities, ownership, and processes to create a consistent and manageable setup.
IAM Balances Competing Expectations Across the Organization
IAM operates at the intersection of business, security, and compliance. Each of these domains brings different expectations.

Figure 1: Influencing Factors that Shape IAM
Business teams focus on enablement. They expect fast onboarding, seamless access, and support for digital services. Security focuses on protection, including reducing identity-related risks and strengthening controls. Compliance focuses on accountability through governance, documentation, and auditability.
These expectations are valid, but they do not naturally align. Measures that strengthen security can introduce friction. Compliance requirements for approvals and documentation can slow down access processes. At the same time, pressure for speed and flexibility can challenge control mechanisms.
IAM therefore requires coordination across different stakeholders, while also balancing their often competing priorities. It connects stakeholders such as IT, HR, security, compliance, and application owners. When these perspectives are not aligned, the resulting tension becomes visible in how priorities are set and how initiatives are executed.
Too Many Priorities, but No Clear Direction
When asked about the biggest challenge in IAM, the responses indicate a tendency:
33% of participants selected “too many competing priorities or limited resources”, followed by 26% pointing to a “lack of clear strategy or target architecture”. “Unclear ownership” accounted for 19%. Tool complexity (15%) and data quality (7%) are mentioned less frequently.
This highlights an important aspect: IAM is not lacking topics or initiatives. Organizations are addressing multiple demands simultaneously. The challenge lies in how these demands are structured and related to each other.
Without a defined target state, prioritization is driven by urgency, stakeholder pressure, or immediate requirements rather than a coherent roadmap. This makes competing priorities difficult to manage, as decisions are not guided by a shared direction, clear governance, or a realistic view of available resources. As a result, individual requirements will be implemented in isolation instead of contributing to a coherent overall setup.
From a project perspective, this becomes visible when initiatives expand in scope or budget or lose direction over time. The underlying issue is not the absence of activities, but a lack of shared orientation.
Prioritization Happens, but It Is Largely Driven by Immediate Needs
The second poll focused on how IAM investments are prioritized:
38% prioritize based on security/ risk reduction, followed by 29% based on compliance/audit requirements. 21% report that no structured prioritization approach is in place. A smaller share prioritizes based on urgent business needs (8%). Only 4% selected prioritization based on a defined target state.
This distribution shows that prioritization is present but primarily influenced by immediate drivers such as risk and compliance requirements.
These drivers are necessary and expected. However, when they dominate decision-making, IAM development can follow a reactive pattern. Activities are initiated in response to findings or requirements rather than being guided by a clear target state.
The relatively low share of target-state-driven prioritization suggests that a forward-looking perspective is not yet consistently established across organizations. This makes it more difficult to align initiatives over time and to connect short-term actions with long-term objectives.
Defined Processes Do Not Guarantee Reliable Execution
The maturity poll adds another perspective on how IAM is established in practice:
54% of participants describe their IAM maturity as medium, meaning processes are defined but not consistently implemented. 29% report a high maturity with an integrated and automated setup, while 17% describe their environment as largely reactive and ad hoc.
Maturity is typically used as an indicator of how well IAM processes are established. The results suggest that organizations have defined core IAM processes such as lifecycle management, access requests, and governance controls. However, the execution and enforcement of these processes may be lacking. In practice, this leads to manual workarounds, unclear responsibilities, and exceptions that deviate from defined processes.
This matters because IAM effectiveness depends not on whether processes exist, but on whether they are applied reliably. When execution varies across systems or organizational units, access decisions become less reliable, controls lose their effectiveness, and operational effort increases due to manual work and exceptions.
As a result, IAM may appear mature on paper, while delivering inconsistent outcomes in practice.
What Organizations Expect Will Help Them Move Forward
The final poll provides a perspective on what organizations expect will help move IAM forward:
27% selected strengthening governance, ownership, and processes as the most important step. Assessing IAM capabilities and defining a target state followed with 23% each, while building a prioritized roadmap reached 18%. Improving data quality and introducing a new tool were each selected by only 5%.
These responses indicate a shift in focus. Rather than emphasizing additional tooling, participants highlight the need to improve how IAM is organized and managed. Governance, ownership, capability transparency, and a defined target state all contribute to clearer responsibilities and more structured decision-making.
Taken together, the implication is less about introducing new tools and more about applying what is already defined. Establishing governance and ownership, defining a target state, and aligning initiatives through a prioritized roadmap only create value if they are followed and enforced in practice. Without this, even well-defined approaches remain conceptual, and IAM activities continue to be reshaped by immediate demands rather than progressing in a sustained direction.
Technology Is Present, but Structure Determines Its Effectiveness
When comparing challenges and improvement priorities, an interesting observation appears. Only 15% of participants identify tool complexity or integration challenges as their main issue. Similarly, only 5% indicate that introducing a new tool would be the most helpful step forward. Meanwhile, organizational aspects such as governance, ownership, and process consistency receive significantly more attention, with 27% prioritizing these topics, followed by capability assessment and target-state definition.
This does not imply that technology is irrelevant. Instead, IAM platforms and integrations remain essential. However, the responses indicate that existing challenges appear to be less related to the presence of technical solutions and more to how IAM is organized and positioned across the organization.
IAM does not operate within a single domain. It spans multiple areas such as business, security, compliance, and IT, each with its own priorities, responsibilities, and expectations. As a result, IAM challenges often arise not within a single function, but at the interfaces between them, where coordination, alignment on processes and ownership, and agreement on access decisions are required.
This becomes particularly visible during project execution. Structural gaps such as unclear ownership, fragmented handovers, or undefined processes may not be fully visible at the beginning. They tend to surface once implementation starts, leading to rework, extended timelines, and increased complexity. Technology can make these conditions visible, but it does not resolve them on its own.
From Fragmentation to Direction
Across the poll results and project observations, a direction takes shape. IAM challenges are not solely about missing tooling but also about how existing processes, responsibilities, and capabilities work together in practice. Many organizations have already implemented specific IAM capabilities and processes. The difficulty lies in aligning them in a way that creates a reliable and manageable setup.
Competing priorities exist, but they are not fully aligned toward a common goal or target state. As a result, prioritization is driven by immediate requirements rather than a defined direction. Governance and ownership also remain only partially defined across the organization.
What makes a difference is not adding further activities, but connecting what already exists. This includes defining what IAM should deliver, clarifying responsibilities, and aligning priorities across stakeholders. Based on this, organizations can translate individual initiatives into a coherent roadmap that reflects dependencies and available capacity.
IAM remains a cross-functional topic connecting business, security, and compliance, requiring alignment between these perspectives in execution.
The poll results suggest that this shift toward more structured and coordinated IAM approaches is already taking shape. The remaining step is to translate that understanding into execution. Without this, even well-defined strategies and roadmaps remain conceptual, and IAM continues to be shaped by short-term demands rather than progressing in a sustained direction.
For those interested in further exchange with IAM practitioners, the European Identity and Cloud 2026 offers a good opportunity to do so.
Disclaimer: The observations in this blogpost are based on poll responses collected during a webinar, with approximately 30 participants per poll, and should therefore be interpreted as indicative rather than representative.