The Regulated IAM Assessment Guide
The instrument we score identity risk with, published in full.
Ten categories, weighted for your sector. A 0–4 scoring model. A US–Canada control crosswalk with an evidence query for every line. Free, and written to be used rather than skimmed.
Pick your sector on the form. That is the edition you get.
The 10 categories are shared across all three editions. The weights, the instruments and the artifacts are not — because an FFIEC examiner, an OCR investigator and a customer’s vendor-risk team are testing genuinely different things.
- A 10-category taxonomy, weighted for your sector
- A 0–4 behavioural scoring model, plus a worked example scored end to end
- A US–Canada control crosswalk with an evidence query for every line
- The artifacts assessors ask for first, and how each one is tested
- A blank scorecard to run the whole thing against your own systems
20 PAGES · PDF · EVERY CITATION CARRIES ITS INSTRUMENT AND EDITION
Get the Banking & FinTech edition
Work email only. We check the domain accepts mail before the download unlocks.
The guide has opened in a new tab.
If your browser blocked it, open the guide.
What separates the three editions
You do not have to read these to download — the form above already has your sector. This is here for anyone who wants to know what actually changes between them.
Banking & FinTech
Identity and access management, scored the way a banking examiner scores it — US and Canadian regimes answered from one control set.
- Heaviest categories
- Standing privilege · Authentication strength · Access certification
- Instruments crosswalked
- 39
Healthcare & HealthTech
Identity and access management, scored the way an OCR investigator and a hospital vendor-risk team score it — with the Canadian health privacy regimes answered from the same control set.
- Heaviest categories
- Authentication strength · Third-party access · Standing privilege
- Instruments crosswalked
- 37
Compliance-dependent sectors
Identity and access management for organizations whose obligations arrive through contracts, questionnaires and multiple frameworks at once — scored once, evidenced to each.
- Heaviest categories
- Standing privilege · Authentication strength · Joiner–mover–leaver
- Instruments crosswalked
- 39
What all three share
Identity only
This scores identity and access management, not security as a whole. Network, endpoint, application and data controls are explicitly out of scope, and the guide says so on the first page. A good identity score does not offset weakness elsewhere.
Reproducible
Every level names an observable state, so two people scoring the same organization should land within a few points of each other. Every category carries a query you can run rather than a judgement you have to make.
Cited, with editions
Regulatory material moves by amendment rather than by calendar. Every instrument in the crosswalk carries the edition it was read at, and every statistic names its report and year.
Not a certification
No score produced with this constitutes an attestation, and vaultIAM is not an auditor. It is a diagnostic that tells you where you would fail before somebody else finds out.