Compliance

How identity governance turns RBI, SEBI and IRDAI audits into report downloads

Ask anyone who has survived an RBI inspection, a SEBI CSCRF audit and an IRDAI review: the identity questions are nearly identical. Show us your user access lists. Who approved this access? When was it last reviewed? Why does this person in operations have a finance entitlement? How quickly was this leaver's access removed?

In most organisations, answering means weeks of spreadsheet assembly — exports from dozens of applications, merged by hand, reconciled against HR lists, formatted per regulator. The output is stale the day it's produced, and auditors know it.

Evidence as a by-product, not a project

Identity governance inverts the model. When provisioning flows through the platform, every grant has a requester, an approver and a timestamp. When reviews run as certification campaigns, every decision is recorded with the reviewer's identity and the revocations execute automatically. When offboarding is HR-driven, deprovisioning timelines are measured by the system, not asserted in a memo.

The audit response then stops being an assembly project. The access register is a live query. The review evidence is the campaign record. The SoD position is the rule engine's current state plus its exception log.

One control set, three regulators

The overlap between frameworks is the efficiency opportunity. RBI's least-privilege and review expectations, CSCRF's Protect-function identity controls and IRDAI's access-management chapter are satisfied by the same underlying capabilities: certification campaigns, SoD enforcement, lifecycle automation and comprehensive access logs.

Structure your identity programme around the controls once, and each regulator's questionnaire becomes a different report over the same data. That's also precisely the posture the DPDP Act's Rule 6 will require of every large data-handling organisation by 2027 — regulated or not.

Frequently asked questions

What access evidence do RBI, SEBI and IRDAI audits ask for?

User access lists, who approved each access, when it was last reviewed, why someone in one function holds an entitlement belonging to another, and how quickly a leaver's access was removed.

Why is spreadsheet-based audit evidence a problem?

Assembling exports from dozens of applications by hand, reconciling them against HR lists and reformatting per regulator takes weeks — and the output is stale the day it's produced.

How does identity governance produce audit evidence automatically?

Because the evidence is a by-product of the process. Every grant carries a requester, an approver and a timestamp; every certification decision carries the reviewer's identity; and deprovisioning timelines are measured by the system rather than asserted in a memo.

Can one control set satisfy several regulators?

Yes. RBI's least-privilege and review expectations, CSCRF's Protect-function identity controls and IRDAI's access-management chapter are satisfied by the same capabilities — certification campaigns, SoD enforcement, lifecycle automation and comprehensive access logs.

Sources

  1. SEBI — Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities