Back to Insights
Guide

How to Run an IAM Maturity Assessment

By Vidyaa Ganesh · Published

Most IAM maturity assessments fail before the first question is answered. Not because the instrument is wrong, but because the process around it is: one person answers alone, nobody checks a claim against actual evidence, and the resulting score gets filed away rather than tracked. I covered what an IAM maturity model measures in a companion piece. This one is narrower: the operational steps that turn a questionnaire into a measurement someone can defend in front of a board or an auditor.

None of this requires a consulting engagement. It requires roughly a week of preparation, an hour of structured answering, and a habit of repeating the exercise on a schedule rather than once and never again.

Step 1: Choose Your Scope Before Anything Else

An IAM program usually covers two populations that behave very differently: the workforce (employees, contractors, service accounts) and customers (anyone who authenticates to a product you sell). Scoring them together produces a number that describes neither well, because the controls, the risk profile, and the regulatory exposure diverge. A workforce PAM gap and a customer credential-stuffing gap are not the same problem wearing different clothes.

Decide up front which population this assessment is for. A workforce-only assessment covers identity governance, privileged access, workforce authentication, cloud and SaaS IAM, identity security, and operating model and governance. A customer-facing assessment adds CIAM and its intersections with data security and privileged access. If the organization runs both a workforce program and a customer-facing product, run both scopes as separate assessments rather than one blended one. Comparing a workforce score against a peer's workforce score is useful. Comparing a blended score against anything is not, because no one else blended the same way.

Step 2: Assemble the Right People, Not Just the IAM Lead

A single respondent is the most common way an assessment goes wrong. The IAM program owner knows what was designed and purchased. They are frequently the worst-positioned person to say what is actually deployed, because admitting a gap in your own program is harder than admitting a gap in someone else's. This is not dishonesty. It is the same optimism bias that shows up in every self-assessed survey.

Pair the IAM lead with at least one person who operates the estate day to day: someone from infrastructure or the service desk who processes the actual joiner, mover, and leaver tickets, and someone from GRC or internal audit who has seen what an access review actually produces. For the privileged access and identity security domains, include whoever owns the vaulting or EDR tooling directly. Three perspectives in the room, even for thirty minutes each, catch more overstatement than any amount of careful question wording.

Step 3: Gather Evidence Before You Open the Questionnaire

The single highest-leverage preparation step is pulling a small evidence packet before anyone answers a question. For each domain in scope, that typically means: the most recent access review report and its actual revocation count, the exit record for the last two or three employees who left the organization, the privileged account inventory or vault report, the MFA enrollment rate broken out by application rather than reported as a single company-wide number, and the SSO application coverage list.

This step exists because IAM tooling and IAM outcomes are not the same thing. Ponemon Institute and GuidePoint Security surveyed 626 IT and security professionals in 2025 and found that only half rated their IAM tooling as effective, and that 34% were still running access reviews from spreadsheets. A spreadsheet-based review can still produce a real revocation count. The evidence packet is what lets the assessment tell the difference between a control that exists on paper and one that changes anything.

Step 4: Answer Against Evidence, Not Intent

This is the rule that does the most work: for every question, the answer is what the evidence packet shows, not what the roadmap says or what the tool was purchased to do. If the claim under consideration is “we automatically deprovision leavers,” the test is not the identity platform's configuration screen. It is whether the last actual leaver lost access on their last day, confirmed against the exit record pulled in Step 3. If the claim is “privileged sessions are recorded,” the test is whether a session recording exists for a real privileged login from the last month, not whether the PAM tool has a recording feature enabled somewhere in its settings.

Score the gap between design and evidence honestly rather than rounding up. A control that is deployed for 40% of the estate is a partial control, not a completed one. An assessment that lets a pilot deployment answer as if it were universal is measuring intentions, and intentions do not stop a breach or satisfy an auditor. Every option in a well-built question ladder should specify what evidence backs it, which is exactly what turns “probably” into a defensible answer.

Step 5: Treat the First Score as a Baseline, Not a Verdict

The first assessment an organization runs almost always produces a lower number than anyone in the room expected, once questions are answered against evidence rather than intent. That is normal, not a failure. Independent research places the median organization at early-to-mid maturity: Simeio's cross-industry State of Identity research puts average maturity at 2.4 on a five-point scale, and SailPoint's Horizons research (375 IAM decision-makers, 2025-2026) places roughly 63% of organizations in its bottom two maturity horizons. A first score that lands in that range is ordinary.

What the first score is for is establishing a baseline against which the next one can be compared. Resist the temptation to relitigate a low score by re-answering more generously. The value of the exercise is entirely in the delta between this assessment and the next one, and that delta only means something if both were answered the same way.

Step 6: Set a Reassessment Cadence and Stick to It

A maturity score with no successor is a snapshot, not a management tool. Reassess on a fixed schedule, typically every six to twelve months, and additionally after any event that plausibly changed the program: a merger or acquisition, a new identity platform, a significant breach or near-miss, or a reorganization that moved IAM ownership. Put the next assessment date on a calendar when the current one closes. Programs that reassess only when someone remembers tend not to reassess at all.

A deterministic instrument, one where the same evidence produces the same score regardless of who is running the questionnaire, is what makes the trend trustworthy. If the scoring depends on the assessor's judgment calls, a rising or falling number could reflect a change in assessor rather than a change in the program, and the board conversation collapses back into the same argument the assessment was supposed to settle.

What Derails an Assessment

One respondent, no cross-check. The single most common failure mode. Fix it with the pairing described in Step 2, even if it is a thirty-minute conversation rather than a formal interview.

Evidence means the design document. A control that exists in an architecture diagram is not a control. If the evidence packet in Step 3 cannot produce a real example from the last quarter, treat the control as partial.

The score becomes the target. Once a target maturity level attaches to a performance review or a board commitment, the incentive to answer generously grows. Keep the assessment and the accountability conversation separate, or the numbers stop meaning anything within two cycles.

No foundational check. A program can present strong governance while a prerequisite control, workforce MFA or a privileged account inventory, remains essentially absent. A model that lets strength in one area mask a missing foundation is measuring the wrong thing. AXIS handles this with foundational controls that gate the overall result; the design rationale is on the methodology page.

Running the Assessment in Practice

The AXIS assessment applies this process directly. Pick a scope, answer 37 questions against the evidence in front of you rather than the roadmap in your head, and get a domain-by-domain result rather than a single number. Each answer maps to the compliance frameworks it satisfies through the framework library, so the same evidence packet that supports the maturity score also supports an audit conversation. The result compares against industry benchmarks adjusted for organization size and region, and every score is cryptographically signed so it can be verified later, which matters once a score is being cited in a board deck. It is free, takes under an hour once the evidence packet is assembled, and requires no account to run.

Common Questions

How long does an IAM maturity assessment take? The questionnaire itself takes under an hour. The preparation, pulling the evidence packet described in Step 3 and scheduling the right participants, typically takes three to five business days depending on how quickly reports can be pulled from existing tooling.

Who should own the assessment internally? Ownership and answering are different roles. The IAM program lead should own scheduling the assessment and acting on the result, but should not be the sole respondent, for the reasons in Step 2.

Should we assess before or after a major remediation project? Both. Assess before, to establish the baseline the project is meant to move, and again after the project closes, to confirm the delta is real rather than assumed. A remediation project with no before-and-after assessment is a cost with no measured outcome.

AXIS is free to use. Assemble your evidence, pick a scope, and get a domain-by-domain maturity score benchmarked against your industry.

Start Assessment

Sources

  • Ponemon Institute and GuidePoint Security, “The State of IAM Maturity” (2025, 626 IT professionals)
  • SailPoint, “The Horizons of Identity Security 2025-2026” (375 IAM decision-makers)
  • Simeio, “State of Identity 2024”
  • Ganesh, “We Still Don't Have a Standard Way to Measure IAM Maturity,” IDPro Newsletter, Parts 1-3 (2026)