Strategy

On-premises vs cloud IAM: making the data-sovereignty decision honestly

Global identity vendors will tell you the future is SaaS-only. Indian regulators, procurement rules and CERT-In directions tell a more nuanced story. The right question isn't 'cloud or not' — it's 'which of our identity workloads can leave our perimeter, and under whose jurisdiction?'

The forcing factors

Three requirements push identity infrastructure on-premises or into Indian sovereign environments. First, log residency: CERT-In directions require 180-day ICT log retention within India, and authentication logs are squarely in scope. Second, sector rules: RBI, SEBI and IRDAI expectations around data location and auditability make many BFSI institutions keep identity data in their own data centres as a matter of policy. Third, procurement: government and PSU tenders frequently require indigenous software and in-country deployment outright.

Against that, cloud deployment wins on speed to value and operational overhead. For unregulated mid-market companies, a cloud IAM deployment is usually the right default.

The honest decision framework

Ask four questions. Where must authentication and access logs physically live? Which regulator can audit you, and what have they flagged at peers? What latency does your core application estate tolerate for authentication round-trips? And who patches the platform at 2 a.m. — your team or your vendor's?

The answers usually land in one of three patterns: fully on-premises (government, banks, insurers with strict interpretations), hybrid (regulated core on-prem, workforce SaaS apps via cloud), or fully cloud (growth-stage companies without sectoral mandates). The platform decision that keeps all three open is choosing software that runs identically in every topology — so a regulatory change is a redeployment, not a re-procurement.

Frequently asked questions

Does Indian regulation require IAM to be hosted on-premises?

Not universally. CERT-In directions require ICT logs — including authentication logs — to be retained for 180 days within India. RBI, SEBI and IRDAI expectations around data location and auditability lead many BFSI institutions to keep identity data in their own data centres as policy, and government and PSU tenders often require in-country deployment outright.

Which identity data is affected by log residency requirements?

Authentication and access logs are squarely in scope of the 180-day ICT log retention requirement, which is why log residency is usually the first constraint an identity architecture runs into.

When is cloud IAM the right default?

For unregulated mid-market companies without sectoral mandates. Cloud deployment wins on speed to value and operational overhead when no regulator is dictating where identity data lives.

What does a hybrid identity deployment look like in practice?

The regulated core stays on-premises while workforce SaaS applications are served from cloud — one of the three patterns organisations typically land on, alongside fully on-premises and fully cloud.

How do you keep the deployment decision reversible?

By choosing software that runs identically in every topology. Then a change in regulatory position is a redeployment rather than a re-procurement.

Sources

  1. CERT-In — Directions under sub-section (6) of section 70B of the Information Technology Act, 2000 (28 April 2022)