Identity & Access Management in large banking groups is rarely a pure technology issue! It is an organizational challenge that spans Group functions, IT service providers and the business entities. This session presents how KuppingerCole helped a leading Central and Eastern European banking group move from distributed, IT-centric IAM initiatives to a coherent, group-wide IAM program. Starting from a capability-based view (Identity Fabric and IAM Reference Architecture), the project created a shared language that business, risk, HR, IT and local entities could all use. On this basis, a Group IAM Strategy was defined that clarifies “who does what”: Group sets principles and minimum standards, the internal IT provider operates central IAM services, and entities run their processes within a common framework while business and control functions own access decisions. A matching target architecture with central identity services, a standardized IGA layer and harmonized IAM was then designed to mirror this operating model. Attendees will learn how aligning governance and architecture unlocks real value: better regulatory alignment, clearer accountability, and a non-siloed IAM program that is ready for today's and future requirements.