Your organization has an IAM program. You have tools deployed, processes documented, and policies approved. But when your CISO asks, "Where do we stand?" or the board wants to know, "How mature is our identity security posture?" you're left assembling an answer from scratch.
This checklist offers a structured way to assess your IAM maturity across the most critical domains. Not all IAM capabilities carry equal weight, some are foundational, some are advanced. Claiming maturity in advanced areas while foundational controls are missing creates a false sense of security.
What This Checklist Covers
This assessment evaluates four core IAM domains: identity lifecycle management, access management and authentication, privileged access management, and governance. Each domain is assessed independently before considering an aggregate view. An organization with excellent governance but lacking privileged access controls has a fundamentally different risk profile than one with moderate capabilities across the board, even if their overall scores look similar.
Prerequisites
Before you start:
- Inventory your identity sources. List authoritative sources for human identities (HR systems, Active Directory, cloud directories) and non-human identities (service accounts, API keys, certificates).
- Define your scope. Are you assessing the entire enterprise or a specific business unit? Cloud-only or hybrid? Customer identities or workforce identities?
- Gather documentation. Collect your IAM policies, architecture diagrams, access control standards, and any previous assessment reports.
- Identify stakeholders. You'll need input from identity administrators, security operations, application owners, and compliance teams.
Foundational Controls (Must Pass Before Advanced Assessment)
These controls are prerequisites. Gaps here invalidate claims of advanced maturity, regardless of how sophisticated your other capabilities appear.
1. Multi-Factor Authentication on Privileged Accounts
Check: Every account with administrative, root, or privileged access requires MFA.
Good looks like: Zero exceptions. Domain Admins, cloud tenant administrators, PAM vault administrators, and service accounts with elevated permissions all require a second factor. You have documentation showing MFA enforcement and regular audits confirming compliance.
2. Automated Joiner-Mover-Leaver Process
Check: Identity lifecycle events trigger automated provisioning and deprovisioning without manual intervention.
Good looks like: When HR records a termination, the identity management system automatically disables the account, revokes access, and triggers vault rotation for any shared credentials the user accessed. When someone changes roles, their entitlements update based on their new position. You can produce audit logs showing the time between HR event and access change.
3. Centralized Authentication for Critical Systems
Check: Your most sensitive applications and infrastructure authenticate against a centralized identity provider, not local credentials.
Good looks like: Financial systems, HR platforms, production infrastructure, and privileged access management tools all federate authentication to your enterprise directory or SSO provider. Local admin accounts exist only for break-glass scenarios and are monitored separately.
4. Access Request and Approval Workflow
Check: Users cannot grant themselves access to resources. All access requests follow a documented approval path.
Good looks like: You have a request portal, defined approvers based on data classification or application risk, and an audit trail showing who requested what, who approved it, when, and why. Approvals include business justification.
Identity Lifecycle Management
5. Birthright Access Assignment
Check: New users receive appropriate Birthright Access automatically based on role, department, or location.
Good looks like: You have documented birthright access profiles. A new finance analyst receives access to the ERP, email, file shares, and collaboration tools on day one without submitting individual requests. The profile is maintained in your IGA system and updates when organizational standards change.
6. Reconciliation Process
Check: You regularly compare what access exists in target systems against what your IGA system believes should exist.
Good looks like: Automated reconciliation runs at least weekly. Discrepancies trigger alerts. You have a process for investigating and resolving orphaned accounts, unauthorized permissions, and entitlement drift.
Access Management and Authentication
7. Phishing-Resistant Authentication for High-Risk Users
Check: Executives, finance teams, and IT administrators use FIDO2 or Multi-Factor Cryptographic Devices, not SMS or push-based MFA.
Good looks like: Your authentication policy specifies which roles require phishing-resistant authentication. You've deployed hardware security keys or platform authenticators. You can report adoption rates and have a plan to expand coverage.
8. Session Management Controls
Check: User sessions have defined timeouts, re-authentication requirements for sensitive actions, and centralized termination capability.
Good looks like: Sessions expire after inactivity. High-risk actions (privilege elevation, financial transactions) require step-up authentication. Your identity provider can terminate all active sessions for a compromised account from a central console.
Privileged Access Management
9. Just-in-Time Elevation
Check: Administrative access is granted on-demand for a limited time window, not as standing permissions.
Good looks like: Administrators request elevated access through a PAM system, provide business justification, receive time-limited credentials, and have their session recorded. When the window expires, access automatically revokes. You have reports showing average elevation duration and frequency.
10. Vault Rotation for Shared Credentials
Check: Passwords for service accounts, admin accounts, and shared infrastructure credentials rotate automatically.
Good looks like: Your PAM vault manages these credentials, rotates them on a defined schedule, and updates dependent systems automatically. Manual password resets are rare exceptions, not standard practice.
Governance
11. Certification Campaign Process
Check: You regularly review and certify who has access to what.
Good looks like: You run certification campaigns at least annually for all users, more frequently for high-risk entitlements. Reviewers are application owners or data stewards, not IT. Non-responses escalate. Revocations happen automatically. You track certification completion rates and revocation percentages.
12. Toxic Access Combination Detection
Check: Your system identifies and prevents combinations of permissions that violate separation of duties.
Good looks like: You've defined toxic combinations based on your business processes (for example, the ability to both create vendors and approve payments). Your IGA system flags violations during access requests and certification campaigns. You have a remediation process for legacy violations.
13. Compliance Reporting
Check: You can produce access reports that map to specific regulatory requirements without custom development.
Good looks like: Your IGA system includes pre-built reports for SOX, PCI-DSS, HIPAA, or other relevant frameworks. Reports show who has access to in-scope systems, when access was granted, who approved it, and when it was last certified. You can generate these reports on-demand for auditors.
Common Mistakes
Claiming maturity based on tool deployment, not capability. You have an IGA platform, but if manual processes still dominate, you haven't achieved lifecycle automation maturity.
Treating all domains equally. Excellent governance doesn't compensate for absent privileged access controls. Assess each domain independently.
Skipping non-human identities. Machine identities outnumber human identities by approximately 80 to 1 according to recent research. If your assessment ignores service accounts, API keys, and workload identities, your maturity score is incomplete.
Using aggregate scores without context. A maturity score means nothing without industry benchmarks. A score of 3.2 out of 5 is actionable only if you know that peers in your industry average 2.8 or 3.6.
Next Steps
If you passed all foundational controls and most domain-specific items, you're positioned for advanced capabilities: identity threat detection, AI agent governance, continuous adaptive trust evaluation.
If you have gaps in foundational controls, stop. Do not invest in advanced capabilities until you've addressed MFA on privileged accounts, automated lifecycle management, and centralized authentication. Research consistently shows that 60-70% of organizations remain at early-to-mid stages of IAM maturity, foundational gaps are the primary reason.
Document your results with specifics: which controls passed, which failed, what evidence supports each assessment. Use that documentation to build a prioritized remediation roadmap. And if your organization contributes anonymized assessment data to industry benchmarks, you help build the empirical foundation the IAM community still lacks.





