Skip to main content

The Regulated IAM Assessment Guide

The instrument we score identity risk with, published in full.

Ten categories, weighted for your sector. A 0–4 scoring model. A US–Canada control crosswalk with an evidence query for every line. Free, and written to be used rather than skimmed.

Pick your sector on the form. That is the edition you get.

The 10 categories are shared across all three editions. The weights, the instruments and the artifacts are not — because an FFIEC examiner, an OCR investigator and a customer’s vendor-risk team are testing genuinely different things.

  • A 10-category taxonomy, weighted for your sector
  • A 0–4 behavioural scoring model, plus a worked example scored end to end
  • A US–Canada control crosswalk with an evidence query for every line
  • The artifacts assessors ask for first, and how each one is tested
  • A blank scorecard to run the whole thing against your own systems

20 PAGES · PDF · EVERY CITATION CARRIES ITS INSTRUMENT AND EDITION

Get the Banking & FinTech edition

Work email only. We check the domain accepts mail before the download unlocks.

No sales sequences. One delivery email; occasional vaultKEY updates; unsubscribe anytime. Processed per our Privacy Policy.

What separates the three editions

You do not have to read these to download — the form above already has your sector. This is here for anyone who wants to know what actually changes between them.

What all three share

Identity only

This scores identity and access management, not security as a whole. Network, endpoint, application and data controls are explicitly out of scope, and the guide says so on the first page. A good identity score does not offset weakness elsewhere.

Reproducible

Every level names an observable state, so two people scoring the same organization should land within a few points of each other. Every category carries a query you can run rather than a judgement you have to make.

Cited, with editions

Regulatory material moves by amendment rather than by calendar. Every instrument in the crosswalk carries the edition it was read at, and every statistic names its report and year.

Not a certification

No score produced with this constitutes an attestation, and vaultIAM is not an auditor. It is a diagnostic that tells you where you would fail before somebody else finds out.