Technology selection remains an important element of IAM programs. Meanwhile, discussions with end user organizations reveal that challenges lie elsewhere: Recertifications that consume more time than expected, processes that exist on paper but are not consistently followed, and tools that are technically implemented yet fail to deliver the expected level of efficiency or control. In many cases, these discussions quickly move beyond product features and lead to a broader question:
How can Identity and Access Management deliver value within an organization?
Across advisory engagements, several recurring themes tend to emerge. The challenges observed in IAM programs are not caused by missing technology alone. Instead, they are linked to operability, clearly defined responsibilities, and whether controls function reliably.
Operability as a Common Denominator
Many end user organizations operate in grown and heterogeneous environments. Their Identity and Access Management (IAM) landscapes have evolved over many years, with long-running IGA programs, established PAM solutions, and defined control mechanisms. The challenge is less about introducing another system and more about ensuring that existing systems and processes function reliably and fulfill their intended purpose.
Operability has therefore become a central topic in IAM programs. The key question is not simply the presence of IAM capabilities, but whether they function reliably when needed. This becomes visible when looking at questions such as:
- Do IAM processes run reliably and consistently across the organization?
- Are access decisions transparent, justified, and aligned with business needs?
- Are control mechanisms effective in practice, not just formally implemented?
- Do security measures support operations rather than obstruct them?
In complex enterprises, IAM operates at the intersection of business, IT, and security. This is where ownership becomes crucial. When responsibilities overlap or remain implicitly assumed, friction becomes increasingly likely. Resulting issues are organizational rather than purely technical and may stem from unclear decision paths, inconsistent enforcement of policies, and missing end-to-end processes.
Strengthening operability requires clarity about who is responsible for which IAM decisions and processes. This results in defining roles and responsibilities across IAM capabilities, for example:
- Who defines policies?
- Who owns role models and access concepts?
- Who approves and reviews access?
- Who is accountable for exceptions and remediation?
When ownership is clearly defined and decision paths are transparent, coordination overhead is reduced and existing tooling becomes significantly more effective.
Target Operating Models as a Response
As discussions move from tools to responsibilities, they may eventually shift toward organizational structures. In globally operating organizations, local regulatory requirements, business models, and legacy structures can differ significantly. Certain governance capabilities, such as policy definition and oversight, remain centralized, while operational tasks move closer to local entities or may even be outsourced to service partners. This requires operating models that define who does what and at which level.
Target Operating Models (TOMs) are increasingly used to formalize these structures and clarify interaction points. However, defining a TOM is only the starting point and must be followed by translating it into operational practice. A model that remains conceptual rarely resolves operational friction on its own. Instead, it must be translated into clearly assigned roles, defined collaboration models, measurable responsibilities, and enforceable control mechanisms.
In this sense, a Target Operating Model is not just documentation. It acts as a reference point that aligns responsibilities, collaboration, and decision making across daily operations.
Regulatory Compliance: A Catalyst for Change
Regulatory developments add another layer of pressure to IAM discussions. Frameworks such as the Network and Information Security Directive 2 (NIS2) and the Digital Operational Resilience Act (DORA) formalize expectations around governance, resilience, and third-party management. While compliance has always influenced IAM programs, what has changed is the level of executive attention.
Board members and senior management increasingly expect clear roadmaps, defined milestones, and transparent reporting on IAM capabilities to better understand the overall compliance status. Therefore, IAM is no longer treated as a purely technical topic but discussed in the context of risk exposure and organizational accountability.
While regulation does not automatically improve architecture or resolve structural weaknesses, it does change the visibility and prioritization of IAM programs. This results in:
- Clearer executive ownership and reporting lines
- Defined timelines and structured roadmaps
- Increased budget allocation and program funding
- Formalized responsibilities and documentation requirements
Projects that were previously postponed gain urgency, and loosely defined decision paths must be clarified. In that sense, regulation acts as a catalyst. Not because it solves problems directly, but because it forces organizations to address them more systematically.
Recurring Challenges
Across advisory engagements, certain challenges become visible. The following list illustrates typical challenges encountered in IAM program.
- Data quality remains a foundational issue:
Advanced authorization models and attribute-based approaches depend on accurate, timely, and consistent information. When identity attributes are outdated, incomplete, or inconsistent across systems, even well-designed solutions cannot function as intended. Poor data quality turns controls, such as access reviews or recertifications, into clicking exercises and weakens the reliability of access decisions. The same applies to emerging technologies such as AI-driven analytics or decision support: without reliable identity data, their effectiveness remains limited. - Business ownership is weak or unclear:
IAM programs without strong business involvement tend to struggle with alignment and acceptance. When role models and processes are defined primarily from a technical perspective, they mirror system structures rather than organizational realities. Controls may formally exist, but they are not well integrated in business processes. - Responsibilities are fragmented or overlapping:
Within IT, ownership is not always clearly defined. Different teams may operate identity platforms, manage directories, or define operational policies, sometimes without clearly documented interfaces or handovers. This fragmentation slows decision-making and creates responsibility gaps, particularly when incidents or audit findings require coordinated action. - Exceptions may gradually become the norm:
Over time, temporary access decisions, local deviations, and workaround solutions accumulate. Without regular, structured review and cleanup, the exception path can gradually become more dominant than the standard process, potentially weakening the reliability and consistency of controls. - Compliance focus outweighs practical impact:
Regulatory and audit requirements play a major role in shaping IAM processes. As a result, some controls may primarily serve to demonstrate compliance. While these activities are important, their effectiveness in improving day-to-day access governance can vary depending on how they are implemented and embedded in operational processes.
Addressing above challenges can deliver noticeable improvements. Clear processes, defined ownership, and reliable data foundations have a significant impact on the effectiveness and value creation of identity-related controls.
Conclusion: Why Structure Makes the Difference
Taken together, these insights reflect a development in IAM discussions. While technology selection remains important, increasing attention is placed on how IAM processes, responsibilities, and controls are managed.
Organizations that align technology, processes, and responsibilities are able to address regulatory requirements, modernization projects, and growing complexity more systematically. When responsibilities are clear and controls are integrated into daily operations, IAM becomes increasingly reliable, sustainable and can actively contribute to business value creation.
Structured approaches can provide orientation in this context. Clearly defined Target Operating Models help organizations translate IAM responsibilities, decision paths, and operational processes into an organizational structure. Frameworks such as the KuppingerCole Identity Fabric and the Reference Architecture help organizations assess maturity, identify gaps, and design IAM environments that remain flexible and sustainable over time.