Compliance
Quick answer
Compliance in IGA means proving access is appropriate and controlled. SailPoint generates the reviews, policies and audit trails that satisfy frameworks like SOX and HIPAA.
Key takeaways
- Compliance = provable, controlled, appropriate access
- Certifications provide periodic review evidence
- SoD policies enforce regulatory control separation
- Audit logs give a full history of access changes
In identity governance, compliance means being able to prove that access is controlled, appropriate, and continuously reviewed, on demand, to an auditor. Almost every regulatory framework that touches systems and data eventually asks the same questions about access, and SailPoint exists in large part to answer them efficiently instead of through frantic spreadsheet exercises before each audit.
What auditors actually ask
Strip away the framework-specific language and audits converge on a handful of access questions:
- Who has access to this sensitive system or data, and why?
- Was that access granted through an approved, controlled process?
- Is it reviewed regularly, and is inappropriate access removed?
- Are toxic combinations of access (separation-of-duties conflicts) prevented or detected?
- Is there a complete, tamper-evident history of who changed what and when?
Each of these maps directly onto a SailPoint capability, which is why the platform is often justified primarily on the cost and risk of failing audits.
Mapping frameworks to features
| Framework | Primary access concern | SailPoint capability |
|---|---|---|
| SOX | Financial-system access and SoD | SoD policy, certifications, audit trail |
| HIPAA | Who can see patient data | Access review, least privilege |
| GDPR | Accountability for data access | Access visibility, certification evidence |
| ISO 27001 | Access control process (A.9) | Request/approval workflow, reviews |
| PCI DSS | Least privilege to cardholder data | Role design, certifications |
The three pillars of compliance evidence
Certifications
Access certifications are the workhorse of compliance. A scheduled campaign presents each reviewer with the access their people hold and records an explicit approve or revoke decision, with reviewer, timestamp and comments. That record is the audit evidence, it demonstrates a controlled, periodic review actually happened.
Separation-of-duties policy
SoD policies encode combinations of access that must never coexist, for example the ability to both create a vendor and pay that vendor. SailPoint can prevent the conflict at request time and detect existing violations during refresh, giving auditors confidence that toxic combinations are controlled.
The audit trail
Every access change, request, approval, provisioning action and certification decision is logged. This immutable history answers "who changed what, when, and who approved it" without manual reconstruction.
Turning compliance from a fire drill into a byproduct
The strategic win is that a well-run governance programme produces audit evidence continuously as a byproduct of normal operation. Instead of assembling access reports under deadline pressure, the team runs a report. Designing for that outcome, clean roles, scheduled certifications, enforced SoD, complete logging, is what separates a mature programme from one that merely survives each audit.
Common pitfalls
- Certifying to tick a box: reviewers who approve everything create evidence of a process that adds no real control.
- SoD defined but not enforced: policies that only detect after the fact, with no remediation, satisfy no one.
- Gaps in coverage: a sensitive application not onboarded to SailPoint is invisible to every control above it.
Want to learn this properly?
Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.
Check your understanding
What does compliance require in IGA?
- A. That access is controlled, appropriate, periodically reviewed and fully auditable.
- B. Access certifications, which record who reviewed and approved each access.
- C. By enforcing separation of duties and reviewing financial-system access with an audit trail.
Show answer
A. That access is controlled, appropriate, periodically reviewed and fully auditable.
That access is controlled, appropriate, periodically reviewed and fully auditable.
Which feature provides periodic review evidence?
- A. That access is controlled, appropriate, periodically reviewed and fully auditable.
- B. By enforcing separation of duties and reviewing financial-system access with an audit trail.
- C. Access certifications, which record who reviewed and approved each access.
Show answer
C. Access certifications, which record who reviewed and approved each access.
Access certifications, which record who reviewed and approved each access.
How does SailPoint help with SOX?
- A. Access certifications, which record who reviewed and approved each access.
- B. By enforcing separation of duties and reviewing financial-system access with an audit trail.
- C. That access is controlled, appropriate, periodically reviewed and fully auditable.
Show answer
B. By enforcing separation of duties and reviewing financial-system access with an audit trail.
By enforcing separation of duties and reviewing financial-system access with an audit trail.