Authorisation structures are the foundation of every secure IT landscape – and in reality they are often historically grown, redundant and hard to trace. Vetrexa analyses, cleans up and optimises your role and access structures cross-system, governance-compliant and audit-ready. From baseline assessment through to continuous operation we deliver defensible results – compliant with MaRisk, BAIT and DORA.
Overview
Why structured authorization management is now indispensable.
Regulated industries face the challenge of managing thousands of identities, roles and entitlements consistently, in an audit-proof way and efficiently across hybrid system landscapes. Lack of transparency, over-privileged accounts and unresolved SoD conflicts are among the most common audit findings – and among the largest attack surfaces in cybersecurity.
We combine functional consulting, deep tooling know-how (including the NEXIS Platform, IVIP and SailPoint IIQ) and regulatory expertise into an integrated approach. The result: clear role models, clean entitlements, effective recertifications and KPI-based reporting that convinces the board, internal audit and supervisors alike.
Services
What we deliver.
Six building blocks for consistent, audit-ready and economically sustainable authorisation management.
01
Analysis and clean-up of existing entitlements
We create transparency over grown entitlement landscapes, identify redundancies and remove legacy baggage across systems.
Baseline capture and inventory of all entitlements
Detection of orphaned and redundant accounts
Analysis of over-privileged users and toxic combinations
We design robust role models that reflect business processes while remaining technically efficient to operate.
Role concepts based on business processes
Role mining and role consolidation with NEXIS
Separation of business and IT roles
Approval and request workflows
Governance model including role ownership
03
SoD analysis and conflict remediation
We identify, assess and remediate segregation-of-duties conflicts – rule-based and fully traceable.
Definition and maintenance of the SoD rule set
Cross-system conflict analysis
Risk assessment and prioritisation
Mitigating controls for exceptions
Continuous SoD monitoring
04
Recertification campaigns and access reviews
We design and operate audit-proof recertifications – from campaign planning to result analysis.
Campaign design by risk and system class
Owner reviews and escalation logic
Automated reminders and deadline management
Audit-proof documentation and audit trail
Analysis and derivation of corrective actions
05
NEXIS Platform rollout and IVIP activation
As NEXIS Silver Partner we accompany you from tool selection through to productive operation of the NEXIS Platform with IVIP at its core.
Fit/gap analysis and business case
Connection of source systems and data quality
Configuration of IVIP, role mining and reviews
Integration into your existing IAM/IGA landscape
Enablement and knowledge transfer to your business
06
Governance reporting and KPI dashboards
We deliver metrics and reports that create steering capability for business, IT, internal audit and supervisors.
Definition of risk-oriented KPIs
Power BI dashboards for management and audit
Regulatory reports (MaRisk, BAIT, DORA)
Trend analyses and maturity measurement
Automated data preparation from IGA sources
Approach
Our approach in 4 phases.
A clearly structured path from analysis through to sustainable operation – iterative, transparent and audit-ready.
01
Analysis
Baseline capture of all identities, roles, entitlements and processes. Assessment of SoD conflicts, over-privileged accounts and governance gaps. Outcome: a defensible situation view and prioritised action plan.
02
Design
Target design: RBAC/ABAC model, SoD rule set, recertification process, role governance and tooling architecture (e.g. NEXIS Platform, SailPoint IIQ). Sign-off by business, IT and compliance.
03
Implementation
Configuration, role rollout, clean-up, connection of source systems, build-out of reports and training of role owners. Delivery in cleanly cut waves with defined success criteria.
04
Continuity
Operation of recertification campaigns, continuous monitoring, KPI reporting and iterative evolution of the role model – as a managed service or anchored within your organisation.
Project experience
Selected projects.
Representative reference projects – without naming clients.
Banking
Entitlement clean-up and RBAC rollout
Cross-system clean-up of legacy entitlements, role consolidation with NEXIS/IVIP, build-out of governance and KPI reporting.
NEXIS · IVIP · SailPoint IIQ · SAP · AD · Power BI · MaRisk
Insurance
Audit-proof recertification
Design and operation of half-yearly campaigns. Owner reviews, escalation logic, audit trail and automated reporting.
RBAC (Role-Based Access Control) grants entitlements based on defined roles – structurally clear, easily auditable and well suited to stable organisations. ABAC (Attribute-Based Access Control) decides dynamically based on attributes such as department, location, time of day or risk class, and is more flexible for complex, context-dependent access decisions. In practice we frequently combine both: RBAC as the backbone, ABAC for fine-grained exceptions and risk-based decisions.
What is the benefit of the NEXIS Platform versus built-in tools?
The NEXIS Platform, powered by IVIP, provides a cross-system view of identities, roles and entitlements including visualisation, role mining and automated recommendations. Built-in tooling of individual systems (SAP, AD, ServiceNow) only shows its own slice and rarely uncovers SoD conflicts, orphaned accounts or redundancies across systems. NEXIS significantly accelerates clean-up, recertification and reporting.
How often should recertifications be run?
For critical systems and privileged access we recommend at least half-yearly recertifications, and annual campaigns for standard entitlements. Event-driven reviews (mover, leaver, reorganisation) and risk-based ad-hoc recertifications complement the regular cycle and meet the requirements of MaRisk AT 4.3.1 and DORA Art. 9.
How do you ensure MaRisk and DORA compliance?
We align authorisation processes rigorously with MaRisk AT 7.2, BAIT and DORA Chapter II: documented role models, traceable request and approval workflows, audit-proof recertifications, SoD controls, KPI reporting and full audit trails. Controls are surfaced as evidence via Power BI and the GRC tool and are regularly confirmed by internal audit and external auditors.
Entitlements under control. Governance demonstrable.
Talk to us about your authorisation structures – we show you the fastest path to transparency, compliance and economically sound operation.