Run an IAM maturity assessment before signing any licence deal
A licence can look cheap until identity gaps turn into audit findings, help-desk overload, and delayed go-lives. An IAM maturity assessment shows whether your team can actually operate the platform you are about to buy.
Nesqual Tech AI
The licence is not the risk. Your IAM maturity gap is.
A platform demo can hide a lot. The real failure shows up 90 days after signature, when your team discovers it needs 14 custom workflows, three manual approval chains, and a contractor onboarding process nobody documented. In 2026, the average enterprise IAM rollout still fails less from missing features than from weak operating maturity: unclear ownership, brittle integrations, and policy sprawl.
A recent enterprise assessment pattern we see repeatedly is blunt: organizations that skip an IAM maturity assessment spend 25-40% more on implementation services and take 2-3x longer to reach steady state. The licence price was never the expensive part. The expensive part is buying controls you cannot run.
What an IAM maturity assessment actually proves
An IAM maturity assessment is not a vendor scorecard. It is a readiness check for whether your people, processes, and architecture can sustain identity at enterprise scale.
It answers four questions:
- Can you provision and deprovision users within your target SLA?
- Can you enforce least privilege without creating ticket chaos?
- Can you survive an audit with evidence that is complete and current?
- Can your target platform integrate with your current stack without custom code everywhere?
The five maturity dimensions that matter
Use these dimensions to score the current state from 1 to 5:
- Governance: policy ownership, exception handling, RACI clarity.
- Lifecycle automation: joiner-mover-leaver coverage, HR triggers, contractor expiry.
- Access management: SSO, MFA, conditional access, privileged access.
- Identity data quality: authoritative sources, duplicate identities, attribute completeness.
- Operations and observability: ticket volumes, failed syncs, audit evidence, recovery time.
A bank with 98% SSO coverage but 46% automated deprovisioning is not mature. A SaaS company with clean SSO but no privileged access review process is not mature either. Maturity is the ability to operate controls end to end, not the number of features enabled.
How to run the assessment before procurement
The best time to run the IAM maturity assessment is before procurement signs the order form. That gives you leverage to reject mismatched products, right-size the implementation, and set realistic timelines.
Step 1: Map your identity estate
Start with a simple inventory. Count every identity source, every target system, and every manual exception.
Example baseline for a 12,000-employee enterprise:
- 1 HR system of record
- 2 directory services
- 18 SaaS apps tied to SSO
- 11 apps with local accounts
- 3 privileged access tools
- 4 contractor feeds
- 27 manual spreadsheet-based access processes
If you cannot inventory the estate in two weeks, your IAM maturity assessment should flag data ownership as a critical gap.
Step 2: Measure operational friction
Pull 90 days of operational data. Do not rely on opinions.
Track:
- median time to provision a standard employee: target under 15 minutes for automated flows
- median time to deprovision after termination: target under 5 minutes for HR-driven automation
- access request fulfillment time: target under 4 business hours for low-risk entitlements
- failed sync rate: target under 1%
- help-desk tickets per 1,000 users per month: target under 20 for a mature SSO estate
If your numbers are far outside those ranges, the IAM maturity assessment should treat process redesign as mandatory, not optional.
Step 3: Test the ugly paths
Most vendors demo the happy path. Your assessment should test the messy cases:
- contractor starts on a Saturday and ends on a holiday
- employee changes legal entity mid-quarter
- acquired company uses a different email domain and duplicate IDs
- privileged admin access needs emergency elevation with full audit trail
A realistic test is better than a polished workshop. For example, one healthcare group found that 17% of leaver events bypassed deprovisioning because their HR feed did not carry termination timestamps consistently. That is not a feature problem. That is a control design problem.
Step 4: Score readiness against the target operating model
Use a simple rubric:
- 1 = manual and ad hoc
- 2 = repeatable but brittle
- 3 = partially automated
- 4 = measured and controlled
- 5 = optimized and continuously improved
A platform purchase is safe only when the gap between current state and target state is manageable within your implementation window. If your current state is 1.8 and the target operating model assumes 4.0, you are buying a transformation, not a licence.
What to test in the architecture, not just the product
A strong IAM maturity assessment checks whether the architecture can absorb the platform without creating a new pile of custom code.
Integration patterns that usually break first
Focus on these interfaces:
- HRIS to IAM via SCIM or event-driven APIs
- IAM to SaaS via SCIM 2.0 and SAML/OIDC
- IAM to PAM via just-in-time elevation
- IAM to ITSM for request and approval workflows
- IAM to SIEM for identity telemetry and anomaly detection
A practical architecture decision: prefer event-driven lifecycle updates over nightly batch syncs. In a 2026 enterprise deployment, moving from 1-hour batch jobs to near-real-time events can reduce orphan-account windows from 45 minutes to under 3 minutes.
HRIS -> Event Bus -> Identity Orchestrator -> SaaS Apps
| | |
| | +--> ITSM for approvals
| +------------------> SIEM for audit events
+--------------------------------> Data quality checks
A sample control check you can automate
control_id: IAM-LCM-07
name: Termination deprovisioning SLA
source: HRIS
trigger: employee.termination.timestamp
expected_actions:
- disable_primary_directory_account
- revoke_saas_tokens
- remove_group_memberships
- disable_pam_entitlements
sla_minutes: 5
exception_policy: security_review_required
evidence:
- event_id
- timestamp_received
- timestamp_completed
- approver
If your vendor cannot map controls like this to your actual workflows, the IAM maturity assessment should score them low on fit.
Reference architecture decision matrix
Option A: Monolithic IAM suite
- Pros: fewer vendors, simpler procurement
- Cons: heavier customization, slower change cycles
- Best when: you have standardized apps and a strong IAM team
Option B: Composable IAM stack
- Pros: better fit, faster integration with modern SaaS
- Cons: more governance required, more integration points
- Best when: you have heterogeneous apps and mature platform engineering
In 2026, many enterprises are choosing composable IAM because it fits cloud-first estates and AI-assisted operations. But composable only works when the IAM maturity assessment shows strong API governance and identity data discipline.
Common Pitfalls
The same mistakes show up again and again, and they are expensive.
Mistake 1: Buying for features instead of operating model fit
A vendor may support adaptive MFA, passwordless login, and fine-grained policy engines. If your team cannot maintain policy rules or monitor exceptions, the platform will drift.
Avoid it: require a maturity-to-capability mapping before procurement. For each critical control, define who owns it, how it is tested, and what evidence proves it works.
Mistake 2: Ignoring identity data quality
Dirty attributes ruin automation. If department codes, manager IDs, and worker types are inconsistent, lifecycle rules fail.
Avoid it: run a data profiling pass. In one retail enterprise, 11% of identities had missing manager attributes, which blocked access certification automation for six months.
Mistake 3: Underestimating privileged access
Teams often assess SSO and ignore admin access. That is where breach impact lives.
Avoid it: include PAM in the IAM maturity assessment. Check whether emergency access is logged, time-bound, and reviewed within 24 hours.
Mistake 4: Treating the assessment as a one-time workshop
A maturity score is stale the moment you finish the deck if you do not tie it to operational metrics.
Avoid it: refresh the IAM maturity assessment quarterly until go-live, then monthly for the first two quarters after deployment.
Mistake 5: Not budgeting for change management
A licence can be approved in a week. Behaviour change takes months.
Avoid it: budget 15-20% of implementation cost for process redesign, training, and exception cleanup. That is usually cheaper than living with manual workarounds.
A practical scoring model you can use this week
You do not need a consulting-heavy framework to start. Use a weighted scorecard and make procurement depend on it.
weights = {
"governance": 0.20,
"lifecycle_automation": 0.25,
"access_management": 0.20,
"identity_data_quality": 0.20,
"operations_observability": 0.15
}
scores = {
"governance": 2.5,
"lifecycle_automation": 1.8,
"access_management": 3.2,
"identity_data_quality": 2.1,
"operations_observability": 2.0
}
weighted = sum(scores[k] * weights[k] for k in weights)
print(round(weighted, 2)) # 2.31
A score below 3.0 usually means you should not sign a licence without a remediation plan. A score between 3.0 and 4.0 means you can proceed, but only with explicit assumptions and a phased rollout. A score above 4.0 suggests the platform can fit your current operating model with limited adaptation.
What good looks like in real numbers
A mature enterprise IAM program in 2026 typically shows:
- 95%+ automated joiner and mover events
- 90%+ deprovisioning completed within 5 minutes
- 80%+ of access requests handled through catalog-driven workflows
- less than 10 tickets per 1,000 users per month for identity issues
- quarterly access reviews completed on time at 98%+
If your baseline is half of that, the IAM maturity assessment should drive a phased roadmap, not a big-bang rollout.
Key Takeaways
- Run the IAM maturity assessment before procurement, not after signature.
- Score governance, automation, access, data quality, and observability with real operational evidence.
- Test the ugly cases: contractors, acquisitions, emergency access, and bad HR data.
- Tie vendor selection to your target operating model, not to feature checklists.
- Budget for remediation, change management, and integration work; the licence is rarely the largest cost.
- Reassess quarterly until go-live so the IAM maturity assessment stays aligned with reality.
This article was written by an AI system and published pending human review. Verify anything you intend to act on.
Written by
Nesqual Tech AI
Nesqual Tech
Have a project in mind?
Get an instant AI price estimate for it, or talk directly to our team.
One email a month on what we learn building with AI