White paper · 2026
Access control is among the findings we see repeat most often in financial services, and in our experience it repeats for a structural reason: firms remediate the evidence rather than the entitlement model underneath it. This paper sets out why that happens, what a durable identity control model looks like, and how one programme can satisfy SOX ITGC, NYDFS Part 500, PCI DSS v4.0 and DORA at the same time.
Audience: CISOs, heads of IAM, IT audit and technology risk leaders in banks, insurers, payments and asset management.
In short. Three root causes account for most repeat findings: entitlements defined per application rather than per job function, leaver processes that depend on a human remembering, and privileged access that is vaulted but not time-bound. Fix the model once and the evidence for four frameworks falls out of the same controls.
A repeat finding is rarely a tooling gap. Most firms we assess already own an IGA platform, a PAM vault and a directory. The finding returns because the remediation targeted the artefact the auditor sampled — a review spreadsheet, a revocation ticket — rather than the mechanism that produced it.
| SYMPTOM AT AUDIT | USUAL REMEDIATION | ACTUAL ROOT CAUSE |
|---|---|---|
| Reviewers rubber-stamp access campaigns | Reviewer training, tighter deadlines | Entitlements presented as technical permissions no line manager can interpret |
| Leaver access removed late | A faster manual checklist | No authoritative joiner-mover-leaver trigger from HR to the target systems |
| Standing administrative privilege | Credentials moved into a vault | Vaulting without time-bound elevation — the entitlement is still permanent |
| Segregation-of-duties conflicts persist | Case-by-case exceptions | No SoD ruleset expressed in business terms, so conflicts are invisible at request time |
| Service and system accounts unowned | A one-off inventory spreadsheet | No lifecycle for non-human identities: no sponsor, no expiry, no rotation |
The overlap between the frameworks a financial firm faces is substantial. Designing the control once and mapping it to each obligation is what makes a multi-framework programme affordable — and it is what stops four teams building four versions of the same access review.
| CONTROL | EVIDENCE IT PRODUCES | OBLIGATIONS SERVED |
|---|---|---|
| Role-based entitlement model in business language | Role catalogue, mapping to technical permissions, approval history | SOX ITGC · PCI DSS Req. 7 · ISO 27001 A.5.15 · DORA |
| Automated joiner-mover-leaver from an authoritative source | Timestamped provisioning and revocation records | SOX ITGC · SOC 2 CC6 · NYDFS 500.7 · HIPAA where applicable |
| Just-in-time privileged elevation with session recording | Elevation requests, approvals, session logs, expiry evidence | NYDFS 500.7 · PCI DSS Req. 7–8 · DORA · ISO 27001 A.8.2 |
| Phishing-resistant MFA with a documented fallback | Policy configuration export, exception register | NYDFS 500.12 · PCI DSS Req. 8 · SOC 2 CC6 · DORA |
| SoD ruleset enforced at request time | Conflict rules, blocked-request log, approved exceptions with compensating controls | SOX ITGC · ISO 27001 A.5.3 · internal audit |
| Non-human identity lifecycle | Sponsor register, rotation evidence, expiry and decommission records | PCI DSS Req. 8.6 · DORA · ISO 27001 · AI agent governance |
Mapping is directional, not a legal opinion: which obligations apply to your firm depends on your licences, regions, product mix and the scope your auditors agree.
Access reviews fail when a line manager is shown a permission string and asked whether it is appropriate. They succeed when the reviewer sees a job function they recognise, with the sensitive capabilities inside it named in plain terms — "can release a payment", "can amend a customer record", "can approve a limit change".
Building that model is unglamorous work: entitlement discovery, clustering by actual usage, sign-off by business owners, then a deliberate decision about what stays as a role and what remains a requestable exception. It is also the single highest-leverage piece of identity work a regulated firm can do, because every downstream control — reviews, SoD, PAM scope, joiner-mover-leaver — inherits its quality.
Sequencing rule. Do not automate a bad model. Automation applied to unclear entitlements produces faster, better-documented wrong answers — and auditors sample the output, not the intent.
Workforce identity is an audit problem. Customer identity is a fraud and abandonment problem. The same authentication decision sits between a legitimate customer and a takeover attempt, and between that customer and a completed application. Treat CIAM as a joint design between security, fraud and product, with step-up authentication tied to transaction risk rather than applied uniformly. Delegated administration for partner and broker channels deserves particular attention: it is where entitlement sprawl is least visible.
AI agents acting inside financial workflows are non-human identities with unusually broad reach. They need the same lifecycle every service account should have had: a registered identity, a human sponsor, scoped and time-bound credentials, an approval gate for consequential actions, and a revocation path someone has tested. Firms that fixed their non-human identity lifecycle for PCI DSS are, unexpectedly, already most of the way there.
| PHASE | WORK | EXIT CRITERION |
|---|---|---|
| Assess | Entitlement discovery across in-scope systems; findings mapped to each framework; repeat-finding root causes named. | Findings register agreed with internal audit |
| Model | Role catalogue built and signed off by business owners; SoD ruleset drafted; exception policy agreed. | Role model owned by the business, not by IT |
| Automate | Joiner-mover-leaver automation, connector build, campaign calendar, PAM just-in-time elevation. | Revocation evidence generated without human prompting |
| Evidence | Evidence pack assembled per framework; control owners rehearsed for sampling; monitoring in place. | A control owner can answer an auditor without preparation |
Senior-led engagements under a statement of work: identity assessment, entitlement and role modelling, IGA and PAM implementation, access review operation, and evidence packaging for SOX, NYDFS, PCI DSS and DORA. Onshore architecture and auditor-facing work; offshore engineering for connector build, migration waves and evidence collection.
Talk to a practice lead: info@aceitsolutions.ai · +1 (650) 606-5553
© 2026 ACE IT Solutions. ACE IT Solutions — an Autharva company. This paper is general information, not legal or audit advice. Framework and standard names are the property of their respective owners. ACE IT Solutions provides advisory and implementation services designed to support compliance; certification is granted solely by accredited certification bodies.