Evidence as a by-product, not a project
Identity governance inverts the model. When provisioning flows through the platform, every grant has a requester, an approver and a timestamp. When reviews run as certification campaigns, every decision is recorded with the reviewer's identity and the revocations execute automatically. When offboarding is HR-driven, deprovisioning timelines are measured by the system, not asserted in a memo.
The audit response then stops being an assembly project. The access register is a live query. The review evidence is the campaign record. The SoD position is the rule engine's current state plus its exception log.
One control set, three regulators
The overlap between frameworks is the efficiency opportunity. RBI's least-privilege and review expectations, CSCRF's Protect-function identity controls and IRDAI's access-management chapter are satisfied by the same underlying capabilities: certification campaigns, SoD enforcement, lifecycle automation and comprehensive access logs.
Structure your identity programme around the controls once, and each regulator's questionnaire becomes a different report over the same data. That's also precisely the posture the DPDP Act's Rule 6 will require of every large data-handling organisation by 2027 — regulated or not.