Regulated industries & vendors edition
The Regulated IAM Assessment Guide
Identity and access management for organizations whose obligations arrive through contracts, questionnaires and multiple frameworks at once — scored once, evidenced to each.
Written for the person who owns identity at a SaaS company, insurer, payments-adjacent platform, or any organization that has to answer SOC 2, PCI DSS, ISO 27001 and a customer's vendor questionnaire from the same estate.
- The ten-category taxonomy, weighted for compliance-dependent sectors — Standing privilege, Authentication strength, Joiner–mover–leaver carry the most
- A 0–4 behavioural scoring model, plus a worked example showing where the points actually go
- A control crosswalk covering 39 US and Canadian instruments, with an evidence query for every line
- The six artifacts assessors ask for first, and how each one is tested
- The questions you will be asked, what each is really testing, and what a good answer sounds like
- 8 remediation actions ordered by risk reduction per engineering hour, not by severity
- A blank scorecard to run the whole thing against your own systems
20 pages · PDF · every citation carries its instrument and edition
Get the Compliance-dependent sectors edition
Work email only. We check the domain accepts mail before the download unlocks.
The guide has opened in a new tab.
If your browser blocked it, open the guide.
Why this edition scores differently
All three editions share the same ten categories. The weights, the instruments and the artifacts are not shared, because what an assessor leans on is not the same in a bank as it is in a hospital.
Privilege
Standing privilege
Who holds administrative rights right now, without asking anyone?
Access
Authentication strength
What does it actually take to become a user — and to become an admin?
Lifecycle
Joiner–mover–leaver
How long does access outlive the reason it was granted?
These are the three categories this edition weights most heavily. All 10 categories, the weighting behind each, and the reasoning are set out in section 03 of the guide.
Not your sector?
The guide is published in three editions. Pick the one that matches who assesses you.
Banking & FinTech
Identity and access management, scored the way a banking examiner scores it — US and Canadian regimes answered from one control set.
Healthcare & HealthTech
Identity and access management, scored the way an OCR investigator and a hospital vendor-risk team score it — with the Canadian health privacy regimes answered from the same control set.