Measuring IAM Maturity: Metrics Executives Actually Understand
Boards don't fund 'better identity governance.' They fund measurable risk reduction. Here is the capability model and the handful of metrics I use to make the case.
Identity teams routinely struggle to secure investment, and it is usually a communication failure, not a merit failure. We talk in entitlements, correlation, and provisioning pipelines; executives think in risk, cost, and audit outcomes. Bridging that gap requires two things: a maturity model that shows where you are and where you're going, and a small set of metrics that translate identity work into language a board already cares about.
I turned this thinking into a free, two-minute self-assessment. Take the IAM Maturity Index to score your own program across six domains and get a radar profile with tailored next steps.
A capability model, not a tool inventory
Maturity is about capabilities, not products. I assess across a handful of dimensions — lifecycle automation, access governance, privileged access, authentication strength, and identity visibility — and rate each on a simple progression:
- Initial — manual, ticket-driven, inconsistent. Access is granted and removed by human effort and memory.
- Managed — documented processes exist; some automation; controls are real but not comprehensive.
- Defined — authoritative-source-driven lifecycle, governed access requests, PAM in place, controls tested.
- Optimised — least privilege enforced, just-in-time access, continuous certification, identity signals feeding detection.
The value of the model is that it turns "we need more identity investment" into "we are at Managed on privileged access against an industry expectation of Defined, and here is the gap." That is a sentence a board can act on.
The metrics that travel to the boardroom
Most identity metrics are operational noise to an executive. A few translate directly into risk and resonate:
Time-to-revoke for leavers (risk window on exit) · Standing privileged accounts and the JIT conversion rate (attack surface) · Dormant privileged access (unused risk) · Orphaned accounts (governance gaps) · MFA coverage on privileged and remote access (control completeness) · Access certification revocation rate (is governance actually doing anything).
Each of these maps cleanly to a question a board already asks: how exposed are we, how fast can we contain a problem, and are our controls real or theatre? Report the trend, not just the number — direction of travel is what tells leadership whether their investment is working.
Tie maturity to outcomes leadership feels
The maturity model lands hardest when each level is connected to consequences executives experience directly: audit findings, incident exposure, operational cost, and the ability to onboard acquisitions or new business quickly. "Advancing privileged access from Managed to Defined" is abstract. "Reducing the standing privileged accounts an attacker could target from 1,200 to 200, and cutting leaver risk window from days to minutes" is a business case. Always translate the capability into the consequence.
Benchmark honestly
Executives invariably ask "how do we compare?" Answer it honestly, against recognised frameworks — the maturity expectations embedded in standards like the Essential Eight, NIST, and ISO 27001 give you defensible external reference points rather than your own opinion. Being able to say "industry and regulatory expectation is here, we are here, and this investment closes the gap" is far more persuasive than internal advocacy, however well-reasoned.
Concretely, here is how I map the six identity domains onto the control frameworks an Australian regulated enterprise is already measured against — so a maturity score isn't an abstract number, it's a position against obligations you can't argue with:
| Identity domain | NIST CSF 2.0 | ISO/IEC 27001:2022 | ACSC Essential Eight | APRA CPS 234 |
|---|---|---|---|---|
| Identity Lifecycle | PR.AA / GV | A.5.16, A.5.18 (identity & access rights) | — | Para 27 (access provisioning & removal) |
| Access Governance | PR.AA-05 | A.5.15, A.5.18 (access control & review) | — | Para 27, 35 (control testing) |
| Privileged Access | PR.AA-05, PR.PS | A.8.2 (privileged access rights) | Restrict admin privileges (ML1–3) | Para 27 (privileged access) |
| Authentication & Zero Trust | PR.AA-03 | A.5.17, A.8.5 (secure authentication) | Multi-factor authentication (ML1–3) | Para 27 (authentication) |
| Visibility & ITDR | DE.CM / RS | A.8.15, A.8.16 (logging & monitoring) | — | Para 33–36 (detection, response, testing) |
| Non-Human & AI Identity | PR.AA-01, ID.AM | A.5.16, A.8.2 (identities & secrets) | — | Para 21–27 (information asset controls) |
Mappings are indicative, not certification claims — frameworks overlap and your control catalogue will differ — but a table like this turns "we should improve IAM" into "we are below the CPS 234 and Essential Eight expectation on privileged access, and here is the remediation." That sentence gets funded.
Identity maturity is a journey measured in capabilities and communicated in risk. Build the model, pick the handful of metrics that translate to the boardroom, tie each level to consequences leadership feels, and benchmark against external standards. Do that, and identity stops being the team that asks for money and becomes the team that demonstrably reduces risk — which is the only argument that reliably gets funded.
Looking for an IAM lead who thinks this way?
I help regulated enterprises govern identity at scale — from SailPoint to PAM to audit.
Get in touch