IAM Compliance: What the Rules Actually Require, and How to Prove It
Regulators increasingly expect continuous evidence that identity controls work, not just paperwork saying they exist.

Key points
- IAM compliance means proving that identity and access rules are enforced day to day, not just written down in a policy binder.
- SOX, HIPAA, PCI DSS and GDPR all require access controls, though each frames the duty differently.
- Auditors are shifting from quarterly access reviews to demanding continuous, timestamped evidence.
- Non-human identities, service accounts and API keys, now outnumber human users at most organisations and fall inside the same rules.
- Failed access reviews and stale accounts remain the most common audit findings across frameworks.
IAM stands for identity and access management: the systems that decide who can log in to what and what they're allowed to do once inside. Compliance is the practice of showing a regulator that those rules are actually being followed.
That second half matters more than it used to.
For years, organisations passed audits by producing a written policy, a spreadsheet of user reviews and a few screenshots. Regulators have grown sceptical. They want to see the control working on a Tuesday afternoon in March, not just on audit day.
Which rules actually apply?
Most large organisations sit under several at once, and each frames identity controls in its own language.
In the United States, the Sarbanes-Oxley Act requires public companies to control access to systems that touch financial reporting. The section auditors care about most puts management on the hook to attest that internal controls, access controls included, are effective. We first covered SOX's identity implications on 17 August 2026.
Healthcare organisations fall under HIPAA, the Health Insurance Portability and Accountability Act. Its Security Rule requires unique user identification, automatic logoff, and access limited to what each worker needs.
Anyone handling card payments is bound by PCI DSS, the Payment Card Industry Data Security Standard. Version 4.0.1 became the only supported version in early 2025, and its access and authentication requirements spell out least-privilege rules in some detail.
In Europe, GDPR requires appropriate technical and organisational measures to protect personal data. Regulators have consistently read that to include access control, though the text doesn't use those words. The NIS2 Directive, which EU member states were supposed to transpose by 17 October 2024, pushes identity controls further into critical-sector firms and adds personal liability for senior managers.
What does "continuous" evidence look like?
It means logs and system state, not screenshots. Auditors increasingly want to see that a joiner-mover-leaver process actually revoked an employee's access within a set window, with a timestamp to prove it.
A quarterly access review, where a manager clicks through a list and approves everyone, is still common. It's also the control most likely to fail on audit. Reviews happen, but stale accounts get approved anyway.
The direction of travel is toward tooling that pulls entitlements from every connected system and flags drift automatically. That includes non-human identities: the service accounts and API keys that run between machines. They rarely get reviewed at all. Our recent coverage of Hush Security's $30 million raise showed how investors are now backing exactly this problem, specifically giving AI agents verifiable identities and auditable trails.
What should a compliance team focus on first?
Start with the accounts carrying the most risk: privileged users and any identity that can reach regulated data. Get those under multi-factor authentication, log every use, and move to monthly reviews rather than quarterly ones.
Then work outward. Map each identity control to the specific clause it satisfies, so when an auditor asks about a PCI DSS authentication requirement or a HIPAA access provision, you can point to the exact log query that answers them.
The harder truth, as Edna Conway argued in her conversation about the real future of cyber risk, is that passing an audit and actually being secure aren't the same thing. Compliance teams that understand that distinction tend to build controls that hold up under real scrutiny.
Common questions
Is IAM compliance the same as cybersecurity?
No. Compliance proves you meet a written standard. Security is whether you can actually withstand an attack. A firm can pass an audit and still be breached, which is why regulators are moving toward evidence of real enforcement.
Do small companies have to worry about this?
Yes, if they take card payments, handle health data, or supply a regulated customer. PCI DSS and GDPR apply regardless of size, and NIS2 pulls in mid-sized firms in critical sectors across the EU.



