Skip to main content

Industry · FinTech & Banking

Your examiners stopped asking whether you have IAM.

Regulators from the OCC to OSFI and the AMF now treat access control as a board-level obligation. The question is whether you can prove every privileged action — to both of them, from one system of record.

Cross-Border By Default

One control set. Both sets of rules.

If you operate in both the US and Canada, you're being measured twice. Our Toronto base means we build once and map evidence both ways — instead of running parallel compliance programs.

United States

  • FFIEC

    The Authentication booklet and InfoBase VI.A.3 expect layered security, privileged-user authentication, and third-party access controls. These were not sunset — the confusion below is about a different instrument.

  • What replaced the FFIEC CAT

    The FFIEC sunset the Cybersecurity Assessment Tool on 31 August 2025 and now points institutions to NIST CSF 2.0, the CRI Profile, CISA's Cybersecurity Performance Goals, and the CIS Controls. We map your CAT access-management maturity statements onto CSF 2.0 PR.AA outcomes and CRI diagnostic statements, so you show continuity instead of starting over.

  • NYDFS Part 500

    The 2023 amendments phased in over two years; the final tranche took effect 1 November 2025, including the broad MFA mandate under Section 500.12. NYDFS published and then revised comprehensive MFA FAQs in February 2026. Plus CISO accountability and 72-hour ransomware notice.

  • GLBA / SOX

    Access governance and SoD evidence that survives OCC, FDIC, and state examinations.

  • PCI DSS 4.x

    MFA everywhere in the cardholder data environment; account management requirements that map directly to IAM hygiene.

Canada

  • OSFI B-13

    Technology and Cyber Risk Management, in force 1 January 2024 — the guideline that actually speaks to identity and access management, privileged accounts, and access review for federally regulated financial institutions.

  • PIPEDA

    Safeguards principle (Clause 4.7) demands access controls proportional to sensitivity of the financial data handled.

  • Québec Law 25

    Incident reporting, privacy impact assessments, and consent mechanics that touch customer identity design directly.

  • OSFI B-10

    Third-party risk expectations reaching how your vendors' identities access Canadian financial data.

What enforcement looks like in practice: in August 2025 NYDFS entered a USD 2M consent order against a licensed insurance agent where multi-factor authentication had not been enabled on Outlook Web Access. Not a sophisticated intrusion — one identity control that was in the policy and not in the tenant. Public enforcement actions like this are the clearest statement of what Section 500.12 is actually tested against.

Where It Breaks

What we find in every fintech assessment

Examiners ask 'who had access, when, approved by whom?'

Spreadsheet-era SoD fails the moment access changes faster than the spreadsheet. We move SoD into the access engine itself.

Privileged access sprawl across core systems

Shared admin passwords on legacy cores, standing cloud-owner roles, unmonitored vendor sessions — the pattern behind most damaging banking audit findings.

Access reviews that approve everything

A certification campaign that closes at 100% approved with zero revocations is not evidence of clean access — it reads as a rubber stamp. Usage evidence and documented remediation are what make the review count.

Third-party and partner federation risk

B2B integrations, open-banking APIs, and vendor accounts create identity paths no single tool governs end-to-end.

How We Fix It

Deliverables built for examination day

Preparing for an exam or post-incident review?

an Identity Risk Review maps your current gaps against exactly what FFIEC, NYDFS, and OSFI-aligned examiners test for — with a prioritized fix list.

Book an Identity Risk Review