CIOPages
All RFP packages

RFP Package · Cybersecurity & Identity

Identity Governance & Administration (IGA) RFP questions and template

124 questions, 10 demo scenarios and a five-vendor scorecard for choosing Identity Governance & Administration (IGA) software, in one Excel workbook.

What this package is for

Use it to run a Identity Governance & Administration (IGA) software selection, from the first long list to the final scorecard.

What the category covers. Software that governs who has access to what across an organization's applications: connectors and entitlement aggregation, the identity record, joiner-mover-leaver automation, access requests, certification campaigns, roles, segregation of duties and audit evidence. Bought by identity, security and audit leaders replacing an aging governance suite or extending identity-provider governance to ERP, mainframe and cloud entitlements.

A selection usually runs in three rounds. The package has questions for each:

  • RFI, to the long list. 25 questions screen out products that lack something you need.
  • RFP, to the shortlist. 67 questions ask how each product does the work.
  • Deep dive, to the finalists. 32 questions ask for proof on your own data.

10 demo scenarios tell each vendor what to load and what to show, so every product does the same work in front of you. 90 due-diligence questions cover security, integration, implementation and exit. The scorecard weights the answers and ranks up to five vendors.

Each question comes with why it matters, what a good answer looks like and the red flags, so the people scoring the replies know what to look for.

3 questions from the package

From the RFI round. The first shows part of the guide each question carries; the workbook adds follow-ups, how to verify the answer, a priority and a weight.

1. Provide your out-of-the-box connector list mapped against our [in-scope application list], showing for each connector which account and entitlement operations it supports (read, create, update, disable, delete).

Why it matters. Connector gaps found after contract signing become custom builds. These delay application onboarding and add maintenance cost the buyer did not budget for.

Good answer
  • Each listed application is marked as native connector, generic connector configuration, or custom build
  • Operations are listed per connector, with read-only and write support shown separately
  • Entitlement types ingested are named per connector rather than stated as "groups" only
Red flags
  • A list of application logos with no operation detail
  • Targets marked "supported" that actually require undisclosed partner or custom work
  • No distinction between account-level and entitlement-level ingestion

2. Can your product build identity records from more than one authoritative source at the same time, such as [HR system] for employees and [contractor management system] for contractors?

Why it matters. Workforce populations are often held in separate systems. A product limited to one source forces the buyer to merge the sources outside the product, which creates a data pipeline that the product does not govern.

3. Can your product assign birthright access automatically through rules evaluated on identity attributes, such as department, location, job code or worker type?

Why it matters. If birthright access can only be granted through manually maintained lists or custom scripts, new hires start without the access they need or receive access copied from a peer. The buyer then cannot show auditors the rule behind each grant.

Capability areas

Connectors & Entitlement Aggregation (15)

Out-of-the-box and custom connectors to target systems (ERP, directories, mainframe, ITSM, SaaS, homegrown apps), fine-grained entitlement ingestion, aggregation scheduling, reconciliation and delta handling, and the effort to build and maintain connectors for non-standard applications. Generic public APIs, SDKs and webhooks are covered by the integration module.

Identity Data Model & Authoritative Sources (11)

How the product builds the identity record from one or more HR and non-HR authoritative sources, correlates accounts to identities, handles contractors and other non-employee populations, and detects and remediates orphan, dormant and mismatched accounts before governance runs. Lifecycle event processing is covered under JML.

Joiner-Mover-Leaver Lifecycle Automation (12)

HR-event-driven provisioning and deprovisioning, including birthright access, mover handling of access no longer needed, leaver timing, rehires, future-dated and back-dated events, and fulfillment to connected and disconnected (ticket-based) targets. Self-service requests are covered under ARQ. Attribute- and rule-based birthright policies are in scope here; role definitions are covered under ROL.

Access Request & Approval (11)

Self-service access catalog, requests for self and others, policy-aware approval routing, time-bound and just-in-time access, request-time risk and eligibility checks, and expiry handling. Request-time SoD rule logic is covered under SOD.

Access Certification Campaign Design (12)

Campaign types (user, manager, application, role, entitlement, account), event-driven and micro-certifications, scoping and scheduling, reviewer assignment, delegation, reassignment, escalation and campaign closure rules. Reviewer decision aids and revocation fulfillment are covered under REV.

Reviewer Decision Support & Closed-Loop Remediation (10)

Business context, last-used data, peer-group comparison and risk scoring shown to reviewers, recommendations, detection of rubber-stamp review behavior, and closed-loop revocation that removes access in the target system and confirms the removal. Generic AI oversight controls are covered by the ai-human-oversight module. Population-wide outlier and access-risk analytics outside a campaign are in scope here; posture signals from identity threat tools are covered under CNV.

Role Modeling & Role Mining (10)

Business and technical role models, role mining from entitlement and HR attribute data, role definition approval, role versioning and change impact analysis, role ownership and role certification. SoD rules applied to roles are covered under SOD.

Segregation of Duties & Access Policy (13)

Cross-application SoD rule definition, toxic-combination detection at the fine-grained entitlement level, preventive (request-time) and detective enforcement, prebuilt ERP rule sets, mitigating-control assignment and expiry, and emergency or elevated access governance in ERP systems.

Audit Evidence & Compliance Reporting (9)

Tamper-evident history of requests, approvals, certifications, provisioning and revocations; evidence packages for auditors; mapping of controls to our compliance frameworks; and point-in-time reporting of who had access to what. Vendor attestations and certifications are covered by the compliance-certifications module.

Identity-Security Convergence (11)

Governance of cloud entitlements across public cloud providers, non-human and machine identities (service accounts, API keys, workload identities), ownership of those identities, integration with privileged access tooling, and use of identity threat detection and posture signals in governance decisions. It also covers whether these functions share one data model and console or are separate modules.

Program Operability & Incumbent Migration (10)

Configuration versus custom code, promotion of configuration between environments, upgrade impact on customizations and connectors, admin and analyst skills needed to run campaigns and policies, and migration of roles, policies and certification history from an incumbent IGA product run in parallel by application tier. Professional-services scope and contract-level exit terms are covered by the implementation-onboarding and migration-exit modules.

Demo scenarios

Each scenario lists the data to load before the demo, then the steps to show, and the questions it scores.

  1. Connecting our hardest application
  2. Joiner, transfer and leaver for two workers
  3. Manager review with real reviewers
  4. Request that creates a cross-application conflict
  5. Mining and approving a business role
  6. Review triggered by a job change
  7. Answering an auditor's sample request
  8. Cloud access and an orphaned service account
  9. Temporary elevated access to production
  10. Migrating from our current IGA product

Due diligence

The workbook carries the screening questions from these modules. Each module is also sold on its own.

Questions about this package

How many Identity Governance & Administration (IGA) RFP questions are there?

124 solution questions in 11 capability areas: 25 for the RFI, 67 for the RFP and 32 deep-dive questions for the finalists. The workbook adds 90 due-diligence questions on security, integration, implementation and exit.

What comes with each question?

Why it matters, good-answer signals, red flags, follow-up questions, how to verify the answer (a demo step, a test or a document), and a suggested priority and weight for scoring.

Can I edit the questions?

Yes. The workbook is an ordinary Excel file. Change, add or remove questions, and change the weights; the scorecard recalculates.

Which license do I need?

The Enterprise License covers any number of evaluations inside one organization. The Consultancy License covers use with any number of clients. Neither allows reselling or republishing the questions.

Before you shortlist

The buyer guide compares the products in this category and what decides between them.

Buyer Guide
Identity Governance & Administration (IGA)

For the business side of the same change: