NHI vs IGA vs PAM vs ITDR
These four are not competitors, and treating them as such is how coverage gaps form. Each was designed around a different primitive.
| Discipline | Designed around | Core question | Covers NHIs? | Blind spot |
|---|---|---|---|---|
| IGA Identity governance and administration | The human joiner-mover-leaver lifecycle | Should this person still have this access? | Partially. Access-review concepts extend; the lifecycle model does not, because NHIs have no HR record | Scale and primitives. Reviewing 100,000 machine identities through processes built for 1,000 humans does not work |
| PAM Privileged access management | The privileged session | Who used this elevated account, and what did they do? | Yes, for privileged service accounts. Genuinely deep here | SaaS-to-SaaS OAuth grants, CI/CD tokens, cloud workload identities, agent credentials. None of which are sessions |
| ITDR Identity threat detection and response | Anomalous identity behaviour | Is this identity being abused right now? | Increasingly yes, as a detection layer | Detection is not governance. It tells you an identity is behaving oddly, not whether it should have existed |
| NHI governance | The non-human credential and its owner | Should this identity exist, who owns it, and what may it reach? | By definition | Maturity. The discipline is young, the tooling consolidated in 2026, and the vocabulary is still unsettled |
Where the overlap causes real failures
- "Our PAM covers this." The most common and most expensive assumption. PAM covers privileged accounts, typically well. The Salesloft/Drift pattern, a third-party OAuth integration with broad scope, is invisible to it.
- "Access reviews already cover it." They cover the human population the review was scoped to. Extending scope is a configuration decision nobody has made.
- "ITDR will catch it." Detection assumes a baseline. An over-privileged service account behaving exactly as configured produces no anomaly, right up until an attacker uses it exactly as configured.
- Ownership falls between teams. IGA sits with identity, PAM with security operations, ITDR with the SOC, and NHIs with nobody. This is the single most reliable predictor of a stalled programme.
ISO/IEC 42001 vs NIST AI RMF vs EU AI Act
| ISO/IEC 42001 | NIST AI RMF 1.0 | EU AI Act | |
|---|---|---|---|
| Type | Management system standard | Voluntary risk framework | Regulation, legally binding |
| Status | Ratified 2023, certifiable | Published Jan 2023, not certifiable | In force, phased application |
| Obliges you to | Operate and evidence an AI management system | Nothing. It is guidance you elect to follow | Meet specific obligations if you place or use in-scope AI in the EU |
| Key dates | , | , | Art. 5 prohibitions 2 Feb 2025 · GPAI 2 Aug 2025 · Annex III high-risk 2 Dec 2027 · Annex I 2 Aug 2028 |
| Says about NHI | Nothing by name; evidence lands in clauses 6.1, 8.1, 9.1, 10 | Nothing by name; Govern and Measure functions imply it | Nothing by name; logging and human-oversight duties require it |
| Best used as | The operating spine and the certifiable proof point | Risk vocabulary and a structure for the risk register | The obligation set that defines what must be evidenced |
None of the three mentions non-human identity. All three effectively require it, because each demands that you can say what an AI system did and under whose authority. That gap between what the frameworks say and what they require is the reason this site exists.
Which to anchor to
- If you sell into enterprises or the EU: anchor on ISO/IEC 42001. It is the only certifiable option, and certification is the artefact procurement teams actually ask for. See ISO/IEC 42001 and NHI.
- If you are US-based and not EU-exposed: anchor on NIST AI RMF for vocabulary, and use 42001's management-system structure even without certifying. The structure is the valuable part.
- If you have EU exposure: the AI Act defines the floor regardless of what else you adopt. The Digital Omnibus deferred the high-risk dates; it did not remove the obligations, and the co-legislators were explicit that preparation should already be under way.
- In all cases, the evidence machinery is the same. Inventory, ownership, bounded credentials, delegation logging, tested revocation. Build once, map to whichever framework the buyer or regulator asks about.
Frequently asked questions
What is the difference between NHI governance and IGA?
IGA was designed around the human joiner-mover-leaver lifecycle, driven by an HR record. Non-human identities have no HR record, no manager and no leaving date, so the lifecycle model does not extend even though access-review concepts do. The other difference is scale: reviewing 100,000 machine identities through processes designed for 1,000 humans does not work operationally.
Does PAM cover non-human identities?
Partially and deeply, for privileged service accounts, particularly in regulated on-premise environments. PAM was designed around the privileged session, so it does not natively cover SaaS-to-SaaS OAuth grants, CI/CD pipeline tokens, cloud workload identities or AI agent credentials, none of which are sessions. Assuming PAM coverage is one of the most common gaps found in assessments.
Should we adopt ISO 42001 or the NIST AI RMF?
ISO/IEC 42001 if you need a certifiable artefact, which is what enterprise procurement and EU-exposed buyers ask for. The NIST AI RMF is valuable as risk vocabulary and as a structure for the risk register but is voluntary and not certifiable. Many organisations use both: NIST language inside a 42001 management system.
Do any AI governance frameworks mention non-human identity?
None of ISO/IEC 42001, the NIST AI RMF or the EU AI Act uses the term. All three effectively require it, because each demands that you can demonstrate what an AI system did and under whose authority, which is not answerable without identity, ownership and delegation records.
Deciding which framework to anchor to?
A free 18-question assessment scores your ISO 42001 documentation position in about two minutes, and a free classifier maps your systems against the AI Act.
Assess your own NHI programme.
Run the free maturity assessment or the OWASP NHI Top 10 self-audit, get your score in the browser, and unlock the full written report.