Examiners ask 'who had access, when, approved by whom?'
Spreadsheet-era SoD fails the moment access changes faster than the spreadsheet. We move SoD into the access engine itself.
Industry · FinTech & Banking
Regulators from the OCC to OSFI and the AMF now treat access control as a board-level obligation. The question is whether you can prove every privileged action — to both of them, from one system of record.
Cross-Border By Default
If you operate in both the US and Canada, you're being measured twice. Our Toronto base means we build once and map evidence both ways — instead of running parallel compliance programs.
FFIEC
The Authentication booklet and InfoBase VI.A.3 expect layered security, privileged-user authentication, and third-party access controls. These were not sunset — the confusion below is about a different instrument.
What replaced the FFIEC CAT
The FFIEC sunset the Cybersecurity Assessment Tool on 31 August 2025 and now points institutions to NIST CSF 2.0, the CRI Profile, CISA's Cybersecurity Performance Goals, and the CIS Controls. We map your CAT access-management maturity statements onto CSF 2.0 PR.AA outcomes and CRI diagnostic statements, so you show continuity instead of starting over.
NYDFS Part 500
The 2023 amendments phased in over two years; the final tranche took effect 1 November 2025, including the broad MFA mandate under Section 500.12. NYDFS published and then revised comprehensive MFA FAQs in February 2026. Plus CISO accountability and 72-hour ransomware notice.
GLBA / SOX
Access governance and SoD evidence that survives OCC, FDIC, and state examinations.
PCI DSS 4.x
MFA everywhere in the cardholder data environment; account management requirements that map directly to IAM hygiene.
OSFI B-13
Technology and Cyber Risk Management, in force 1 January 2024 — the guideline that actually speaks to identity and access management, privileged accounts, and access review for federally regulated financial institutions.
PIPEDA
Safeguards principle (Clause 4.7) demands access controls proportional to sensitivity of the financial data handled.
Québec Law 25
Incident reporting, privacy impact assessments, and consent mechanics that touch customer identity design directly.
OSFI B-10
Third-party risk expectations reaching how your vendors' identities access Canadian financial data.
Where It Breaks
Spreadsheet-era SoD fails the moment access changes faster than the spreadsheet. We move SoD into the access engine itself.
Shared admin passwords on legacy cores, standing cloud-owner roles, unmonitored vendor sessions — the pattern behind most damaging banking audit findings.
A certification campaign that closes at 100% approved with zero revocations is not evidence of clean access — it reads as a rubber stamp. Usage evidence and documented remediation are what make the review count.
B2B integrations, open-banking APIs, and vendor accounts create identity paths no single tool governs end-to-end.
How We Fix It
an Identity Risk Review maps your current gaps against exactly what FFIEC, NYDFS, and OSFI-aligned examiners test for — with a prioritized fix list.
Book an Identity Risk Review