Since the homegrown identity management system has already been flagged by an auditor as misaligned with industry best practices, and it must scale to handle dynamic, temporary user populations, the priority is to plan for a replacement that meets modern IAM standards (provisioning workflows, role-based access control, MFA support, audit logging, etc.). Starting with a clear requirements document ensures the new solution will address current gaps and support future needs.