Skip to content
IT Canvass
Core concepts · Lesson

Compliance

Quick answer

Compliance in IGA means proving access is appropriate and controlled. SailPoint generates the reviews, policies and audit trails that satisfy frameworks like SOX and HIPAA.

Key takeaways

  • Compliance = provable, controlled, appropriate access
  • Certifications provide periodic review evidence
  • SoD policies enforce regulatory control separation
  • Audit logs give a full history of access changes

In identity governance, compliance means being able to prove that access is controlled, appropriate, and continuously reviewed, on demand, to an auditor. Almost every regulatory framework that touches systems and data eventually asks the same questions about access, and SailPoint exists in large part to answer them efficiently instead of through frantic spreadsheet exercises before each audit.

What auditors actually ask

Strip away the framework-specific language and audits converge on a handful of access questions:

  • Who has access to this sensitive system or data, and why?
  • Was that access granted through an approved, controlled process?
  • Is it reviewed regularly, and is inappropriate access removed?
  • Are toxic combinations of access (separation-of-duties conflicts) prevented or detected?
  • Is there a complete, tamper-evident history of who changed what and when?

Each of these maps directly onto a SailPoint capability, which is why the platform is often justified primarily on the cost and risk of failing audits.

Mapping frameworks to features

FrameworkPrimary access concernSailPoint capability
SOXFinancial-system access and SoDSoD policy, certifications, audit trail
HIPAAWho can see patient dataAccess review, least privilege
GDPRAccountability for data accessAccess visibility, certification evidence
ISO 27001Access control process (A.9)Request/approval workflow, reviews
PCI DSSLeast privilege to cardholder dataRole design, certifications

The three pillars of compliance evidence

Certifications

Access certifications are the workhorse of compliance. A scheduled campaign presents each reviewer with the access their people hold and records an explicit approve or revoke decision, with reviewer, timestamp and comments. That record is the audit evidence, it demonstrates a controlled, periodic review actually happened.

Separation-of-duties policy

SoD policies encode combinations of access that must never coexist, for example the ability to both create a vendor and pay that vendor. SailPoint can prevent the conflict at request time and detect existing violations during refresh, giving auditors confidence that toxic combinations are controlled.

The audit trail

Every access change, request, approval, provisioning action and certification decision is logged. This immutable history answers "who changed what, when, and who approved it" without manual reconstruction.

Turning compliance from a fire drill into a byproduct

The strategic win is that a well-run governance programme produces audit evidence continuously as a byproduct of normal operation. Instead of assembling access reports under deadline pressure, the team runs a report. Designing for that outcome, clean roles, scheduled certifications, enforced SoD, complete logging, is what separates a mature programme from one that merely survives each audit.

Common pitfalls

  • Certifying to tick a box: reviewers who approve everything create evidence of a process that adds no real control.
  • SoD defined but not enforced: policies that only detect after the fact, with no remediation, satisfy no one.
  • Gaps in coverage: a sensitive application not onboarded to SailPoint is invisible to every control above it.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. What does compliance require in IGA?

    • A. That access is controlled, appropriate, periodically reviewed and fully auditable.
    • B. Access certifications, which record who reviewed and approved each access.
    • C. By enforcing separation of duties and reviewing financial-system access with an audit trail.
    Show answer

    A. That access is controlled, appropriate, periodically reviewed and fully auditable.

    That access is controlled, appropriate, periodically reviewed and fully auditable.

  2. Which feature provides periodic review evidence?

    • A. That access is controlled, appropriate, periodically reviewed and fully auditable.
    • B. By enforcing separation of duties and reviewing financial-system access with an audit trail.
    • C. Access certifications, which record who reviewed and approved each access.
    Show answer

    C. Access certifications, which record who reviewed and approved each access.

    Access certifications, which record who reviewed and approved each access.

  3. How does SailPoint help with SOX?

    • A. Access certifications, which record who reviewed and approved each access.
    • B. By enforcing separation of duties and reviewing financial-system access with an audit trail.
    • C. That access is controlled, appropriate, periodically reviewed and fully auditable.
    Show answer

    B. By enforcing separation of duties and reviewing financial-system access with an audit trail.

    By enforcing separation of duties and reviewing financial-system access with an audit trail.

Frequently asked questions

What does the term Compliance refer to in SailPoint?

In identity governance, compliance means being able to prove that access is controlled, appropriate, and continuously reviewed, on demand, to an auditor.

How do certification campaigns involve Compliance?

A scheduled campaign presents each reviewer with the access their people hold and records an explicit approve or revoke decision, with reviewer, timestamp and comments.

What else is worth knowing about Compliance?

SoD policies encode combinations of access that must never coexist, for example the ability to both create a vendor and pay that vendor.

What tends to go wrong with Compliance?

Certifying to tick a box: reviewers who approve everything create evidence of a process that adds no real control. SoD defined but not enforced: policies that only detect after the fact, with no remediation, satisfy no one.
CallWhatsAppEnquire