Skip to main content

      Feeling overwhelmed by Identity and Access Management (IAM)? You’re not alone. IAM can seem complex, spanning user lifecycle controls, access requests, role design, and regulatory requirements. A well‑designed IAM framework is more than a set of policies; it’s a practical operating model that ensures the right people have the right access at the right time. It defines clear roles and responsibilities, streamlines approval flows, enforces controls, and delivers measurable insight through reporting and certification. Whether addressing joiner/mover/leaver processes, privileged access, or compliance audits, effective IAM helps organizations reduce risk, improve user experience, and support scalable digital growth.

      To bring clarity, we sat down with two of KPMG’s IAM specialists: Robbie Goetschalckx and Ben De Backer. In this edition, the experts explain what it takes to build a robust IAM capability in practice: how KPMG helps organizations assess the current state, design a Target Operating Model (TOM), select the right technology, and implement solutions that reflect real‑world processes and dependencies. They also share lessons from guiding clients through end‑to‑end IAM programs - from role modelling and policy definition to governance, automation, and continuous improvement tailored to each organization’s needs.

      What are the main challenges on IAM projects?

      Robbie: One of the trickiest parts is aligning everyone around the TOM. KPIs are usually straightforward, but processes can be more complex. IAM implementations go beyond technology: they touch every corner of the business, so change management plays a big role. And since not everyone works in “IAM” day to day, even discussions about reference users or roles need a thoughtful approach.

      Ben: Another challenge is that many companies rely on external providers for their applications. Coordinating with them takes time. Then there’s the “black box” issue: legacy systems where documentation doesn’t always match reality. TOMs often look perfect on paper, but in practice they can differ. Changing user habits can also be tricky. For example, people are used to just sending an email request, but now everything goes through a portal. Changing habits can be challenging, even when the change appears simple and contributes to improving overall cybersecurity.

      Ben De Backer, Sr. Advisor

      Ben De Backer, Sr. Advisor, Enterprise Risk Services

      Robbie Goetschalckx, Sr. Advisor

      Robbie Goetschalckx, Sr. Advisor, Enterprise Risk Services

      What is your most memorable IAM project until now?

      Ben: For me, the most memorable project was my very first at KPMG, an international project. It was my first time working with SailPoint, coming from a company using an outdated in-house tool. Moving to a cloud solution with an active community and strong support was a complete gamechanger. The project was international from day one and showed me what a mature IAM tool can really achieve.

      Robbie: For me, the most memorable project was a project at a construction client. We came in for PAM quality assurance, and we tightened governance so well that they actually asked us to take over the broader IAM service. Going from a Quality Assurance role to owning IAM governance and delivery was memorable.

      If you could choose your dream project, what would it look like?

      Robbie: My ideal project would be end-to-end project: start with an assessment, design the TOM, implement an IGA tool, and include PAM responsibilities. Handling both governance and PAM makes ownership clear and processes more efficient.

      Ben: I would also go for a full end-to-end project, in a cloud-friendly company where every app is ready for SailPoint connectors, there’s budget to fix application issues, and SSO with Entra ID is included. Ideally, it would be in a high-tech environment, with all applications in scope so IAM is implemented thoroughly. Essentially, a project where IAM is executed properly from start to finish with all necessary resources.

      How did you end up at KPMG?

      Ben: My background is in Applied Informatics, focusing on computer and cybercrime. I started as a Java developer, but the work quickly became too repetitive. I then moved into enterprise access management at a large company, working with an outdated in-house tool, and later into SecOps in vulnerability management at an automotive firm. When an ex-colleague suggested KPMG, I saw it as a real turning point. At KPMG, I had the chance to work with SailPoint, a widely used, cutting-edge platform, and gain deep exposure to the functional side of IAM. The scale of the projects, the supportive environment, and the opportunity to grow both technically and functionally really set KPMG apart.

      Robbie: I joined straight from university. After attending a meet-and-greet to learn more about the company culture, KPMG immediately stood out. Compared to other firms, it felt less hierarchical and more human: an environment where people are approachable, ideas are welcomed, and you’re encouraged to take initiative. That combination of professionalism and personal support made it clear that KPMG was a place where I could grow and make a real impact.

      Why should people join KPMG?

      Robbie: There are so many learning opportunities, both on the job and through partner training like SailPoint. Initiative is encouraged, and growth is real. Projects are varied, the culture is authentic, and colleagues are supportive and welcoming.

      Ben: It’s also about scale and speed. At KPMG, you get the chance to work on large, complex projects that span multiple countries, industries, and technologies. The exposure you gain is intense and rapid. You are learning on the job every day, tackling challenges that would take years to encounter elsewhere. This kind of experience accelerates both your technical and professional growth, giving you skills, insights, and confidence that are hard to achieve at other companies.


      Do you have questions related to IAM?

      For guidance or further information on IAM-related topics, feel free to reach out to Benny Bogaerts.

      Benny Bogaerts

      Partner, Technology | Advisory

      KPMG in Belgium



      Digital Risk Management

      KPMG Technology services.
      Technology advisory

      Stay informed

      Be the first to know about top business trends that can drive success for your company.

      stay informed