Identity Governance Gaps
The IGA Covers Joiners, Movers, and Leavers. Vendor Identities Are in a Spreadsheet.
7 min read · 3 July 2026 · Security
A healthcare technology company had deployed SailPoint IdentityNow for comprehensive identity governance , covering all internal employees through automated provisioning, access reviews, and lifecycle management tied to HR system events. During a compliance audit, auditors asked the governance team to demonstrate identity governance coverage for all identity populations with access to systems containing patient data. The IGA covered eight hundred internal employees comprehensively. It did not cover the sixty-three vendor and contractor accounts also present in those systems. Vendor accounts were managed through a combination of a manually maintained spreadsheet, direct provisioning requests to system administrators, and email-based access review communications sent quarterly to vendor account managers. The spreadsheet had not been updated in four months and listed seventeen accounts , the environment contained forty-three. The quarterly email review had achieved a fifty-three percent response rate in the last cycle, meaning nearly half of vendor accounts had not been reviewed. The IGA program was mature and comprehensive for the population it was designed to govern. The vendor identity population was outside its scope and governed at a fraction of that maturity level.
What are Identity Governance Gaps, Really?
Identity governance is the program of policies, processes, and tools that ensure digital identities , user accounts, service accounts, API credentials, and other access principals , are created appropriately, maintained proportionately, and retired timely throughout their operational life. Identity governance programs typically emerge from internal employee management requirements: provisioning employees at hiring, adjusting access as roles change, and deprovisioning at termination. The joiner-mover-leaver framework was designed for the employee lifecycle. Its application to vendor, contractor, and partner identities is frequently an afterthought that produces governance processes significantly weaker than those applied to internal employees.
The population exclusion problem is the structural root of identity governance gaps. IGA deployments are scoped at implementation , the identity population the system is configured to manage, the HR systems it integrates with for lifecycle events, and the applications it governs for access reviews. Vendor identities are typically excluded from IGA scope because they are not in the HR system, because they are managed through a different onboarding process, or because the IGA deployment preceded the recognition that vendor identities required equivalent governance. The exclusion is often intentional at implementation and overlooked as the governance gap it represents.
The manual governance deficit is the practical consequence of population exclusion. Identity populations outside the IGA are governed through manual processes , spreadsheets, email communications, calendar-driven review reminders, and administrator discretion. These manual processes produce governance that is inconsistent, effort-dependent, and systematically less rigorous than the automated governance applied to populations within the IGA scope. Access reviews achieve lower response rates. Lifecycle events generate less reliable provisioning and deprovisioning actions. Account inventories are less accurate. The governance maturity gap between IGA-governed and manually-governed identities is substantial and grows over time as the IGA-governed population benefits from continuous improvements while the manually-governed population remains static.
- Vendor identities excluded from IGA scope , manual governance processes for identity populations outside IGA coverage
- No HR-triggered lifecycle events for vendor departures , vendor offboarding not integrated with IGA lifecycle management
- Lower access review completion rates for vendor accounts , email-based vendor reviews achieving significantly lower response rates than IGA-enforced reviews
- Account inventory inaccuracy , manually maintained vendor account lists significantly less accurate than IGA-managed employee account lists
- No automated anomaly detection for vendor identities , behavioral analytics and risk scoring not applied to populations outside IGA scope
Why this matters
Identity governance gaps matter for TPRM because they reveal a systematic difference in governance maturity between how a vendor manages its own employee identities and how it manages the identities of the vendor staff accessing customer environments. A vendor with an excellent internal IGA program that excludes contractor and vendor staff accounts from that program has a two-tier identity governance posture , one tier for internal staff with full governance, and one tier for external staff with manual governance. The customer's exposure is primarily through the external staff accessing their environment , which is in the weaker governance tier.
The audit finding dimension is also directly relevant. Identity governance coverage is increasingly examined in regulatory audits, SOC 2 assessments, and TPRM reviews. Auditors who discover that vendor identities with access to regulated data are governed through a spreadsheet last updated four months ago , while the internal employee population is governed by a mature IGA , will find a significant governance gap regardless of the maturity of the internal program. The audit addresses the data's protection across all identity populations, not the IGA's maturity for the populations it covers.
Where most teams get this wrong
The most consistent failure is equating IGA program maturity with identity governance coverage. A mature IGA that covers internal employees comprehensively and excludes vendor identities from scope has high maturity for the population it covers and no automation for the population it does not. The maturity score describes the IGA deployment. The coverage gap describes the identity populations that live outside it.
- Equating IGA maturity with identity governance coverage
- Vendor identity exclusion from IGA scope treated as acceptable
- Manual governance for vendor accounts not recognised as a governance tier gap
- Account inventory accuracy not assessed separately for vendor vs employee populations
- Access review completion rates not tracked by identity population
What good looks like
Mature identity governance programs extend IGA coverage to all identity populations with significant access to sensitive data , internal employees, contractors, vendors, and service accounts , with appropriate integration points for each population's lifecycle events, consistent access review enforcement across all populations, and unified anomaly detection that covers all governed identities.
- IGA scope extended to vendor and contractor identities , same governance tooling for all identity populations
- Vendor lifecycle event integration , departure notifications trigger IGA deprovisioning actions rather than manual processes
- Consistent access review enforcement , vendor account reviews with the same completion rate requirements as employee reviews
- Unified account inventory , vendor accounts in the same authoritative source as employee accounts
- Behavioral analytics coverage for vendor identities , risk scoring and anomaly detection applied across all identity populations
Tooling
Identity Governance , SailPoint, Saviynt, Omada
Enterprise IGA platforms support multiple identity population types , employees, contractors, vendors, and service accounts , with configurable lifecycle integration points for each. SailPoint IdentityNow's non-employee identity management module specifically addresses contractor and vendor identity governance with configurable lifecycle events and access review workflows. For TPRM practitioners, asking whether the vendor's IGA covers vendor and contractor identities alongside internal employees surfaces the coverage scope question.
Vendor Management Integration , ProcessUnity, ServiceNow
Vendor management platforms with IGA integration connect vendor relationship lifecycle events , engagement start, engagement end, personnel changes , to IGA provisioning and deprovisioning workflows. The integration replaces manual notification processes with automated lifecycle triggers that produce more reliable and timely access management. For TPRM practitioners, asking whether the vendor's IGA has integration with their vendor management system for lifecycle events provides a specific automation coverage question.
Governance challenges
The governance challenge with identity governance gaps is the integration complexity of extending IGA coverage to non-employee populations. Employee identity lifecycle is well-understood: HR system events trigger IGA actions. Vendor identity lifecycle has no equivalent clean integration point , vendor departure notification may come through email, through contract management systems, or not at all. Building equivalent lifecycle automation for vendor identities requires either integrating the vendor management process with the IGA or implementing a vendor-specific notification mechanism that the IGA can act on reliably.
- Assess IGA coverage scope , which identity populations are included and which are excluded
- Ask about vendor identity governance specifically , how vendor accounts are governed relative to the internal IGA program
- Compare account inventory accuracy between employee and vendor populations
- Compare access review completion rates between IGA-governed and manually governed populations
- Require IGA coverage for vendor identities as a vendor access governance standard
If you are a small team
Ask your highest-risk vendors two questions that reveal the identity governance coverage gap directly. First: does your identity governance platform cover vendor and contractor accounts that access customer environments , or are those identities managed through a separate manual process? Second: what is the account inventory accuracy for your vendor accounts , specifically, when did you last reconcile your vendor account list against the actual accounts active in the systems those vendors access? Those two questions reveal whether vendor identity is in the IGA or in a spreadsheet, and whether the spreadsheet is current.
- Ask whether IGA covers vendor and contractor accounts alongside employees
- Ask about vendor account inventory accuracy and last reconciliation date
- Ask about access review completion rates for vendor vs employee accounts
- Ask about vendor lifecycle event integration with IGA
What to require
Ask directly:
"Does your identity governance platform cover vendor and contractor accounts that have access to customer environments , or are those identities managed through a separate manual process such as spreadsheets and email-based reviews?"
"What is the account inventory accuracy for vendor accounts in your environment , specifically, when was the last reconciliation between your vendor account documentation and the actual active accounts in your systems?"
Expect as evidence
- IGA coverage scope documentation , identity populations included
- Vendor account inventory with last reconciliation date
- Access review completion rate data by identity population
- Lifecycle event integration for vendor accounts
A vendor who confirms a mature IGA deployment should be asked specifically whether that IGA covers vendor and contractor accounts or only internal employees. The maturity of the IGA for the population it covers does not describe the governance for populations outside its scope. Ask which populations are in scope. The ones outside it are the governance gap.
How to evidence it
- IGA coverage scope documentation including vendor and contractor identities
- Vendor account inventory reconciliation records
- Access review completion rate comparison by identity population
- Vendor lifecycle integration documentation
Key Takeaway
The IGA governs the populations it was designed to govern. The vendor identities in a spreadsheet last updated four months ago are not in the IGA , they are in the spreadsheet, governed by whoever remembers to update it, reviewed by whoever responds to the quarterly email, and removed by whoever notices the departure. Forty-three accounts. Seventeen in the spreadsheet. The governance gap is the difference. Extending IGA coverage to all identity populations with significant access to sensitive data requires the integration work to connect vendor lifecycle events to IGA actions , but the alternative is maintaining a permanently inferior governance tier for the identities that most directly affect customer risk.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association