Fortunately, the Netherlands doesn’t have a strict accountability culture. If something breaks the rules within an organization, we discuss it after discovering it. Strict measures are taken if it’s truly clear that the rules have been deliberately and seriously violated.
An IAM environment established in the Netherlands, designed to exercise a certain degree of control, often focuses on process management and post-process auditing. In countries with Anglo-Saxon cultures, rules are more strictly enforced, and the consequences for violations are somewhat harsher than here in the Netherlands.
Yet organizations are guided by analysts and reports that recommend systems developed for organizations in countries that value strict control, accountability and formality.
In practice, when implementing IAM environments designed for strict control, customers will encounter questions that have never before been addressed in their business processes. This is one of the reasons why IAM implementations run late or fail.
Basic IAM functionality
The core functionality of Identity & Access Management (IAM)—the automated and controlled joiner, mover, and leaver processes of identities—already demonstrates the convergence of technology, process, and control. In the vast majority of IAM functionality, the “business process” component outweighs the “technology” component.
Frequently asked questions are: how many connectors does IAM solution X have? Is a connector available for connection to system Y? In our experience, the connector specifications are not decisive for success, but rather how they are handled. Is it known which information needs to be passed on or synced? Is it known with what frequency and when this should happen? Is it known whether identity data in the supplying (source) systems is present and/or complete? In short: are the Use Cases for the joiner/mover/leaver process correct, are they compliant with laws and regulations, and are they complete? It will not surprise you: this set of information is rarely or never complete.
Accountability culture versus reasonableness
Then a sensitive topic: To what extent will IAM monitor business processes and make it transparent where and by whom any violations have been committed?
In the US, in particular, employees and managers who commit violations are dealt with harshly. At the very least, they receive some degree of exposure, and at the most, they are dismissed and subsequently prosecuted. In Germany, such cases are handled with a sense of procedure and a greater commitment to hierarchy than we would here.
Things are different in the Netherlands; we want to have a reasonable degree of control and, if something goes wrong, be able to have a good discussion about how to prevent it in the future. Fortunately, we don’t allow a culture of fear to develop, and the IAM solution shouldn’t feel like a trap.
Only in cases of blatant fraud will strict enforcement be taken. Being able to determine what and where went wrong afterward works well enough.
Creativity of man
True story: A married couple worked at a large organization in a large city. One worked in Finance and the other in Purchasing; you guessed it. And it’s true; one created the budget and the other managed its “depletion.” Segretation of duties can be configured extensively in most IAM systems.
The system in place wasn’t designed to extend the Segretation of Duties into private relationships, but it is possible. But do we even want to be so tightly controlled? Or do we want to accept that this can happen, occasionally?
Too much control is uncomfortable and, just like prolonged (coronavirus) guidelines, will get on our nerves. Remember: no system can match the creativity of humans (read: employees).
Darryl Karamat-Ali
Sales, Trusted-ID
