Vetrexa Competence

IAM & Security

Identity Access Management (IAM) and IT security form the backbone of every modern, regulated IT landscape. Tightening supervisory requirements from MaRisk, BAIT, DORA, NIS-2 and ISO 27001:2022, hybrid cloud architectures and rigorous zero-trust principles demand an IAM that enforces the least-privilege principle end-to-end and remains audit-ready at all times. Grown entitlement structures, heterogeneous target systems and weak role governance, by contrast, lead to audit findings, elevated access risk and inefficient recertification. Vetrexa supports you as an experienced, vendor-neutral partner – from IAM target architecture through tool selection (SailPoint IIQ, Microsoft Entra ID, CyberArk, One Identity, NEXIS) to day-to-day operations including KPI steering. Our focus lies on heavily regulated sectors such as banking, insurance, automotive and public sector, where we have consistently delivered governance, compliance and efficiency outcomes for many years.

Overview

Why IAM & Security?

Digitalisation, cloud migration and zero-trust models are reshaping the logic of security. At the same time, MaRisk, BAIT, DORA and ISO 27001 sharpen expectations around evidence, control and auditability. Many organisations struggle with grown entitlement structures, heterogeneous target systems and inefficient recertification. This is exactly where we come in – as an independent consultancy without vendor lock-in, focused on sustainable governance and measurable outcomes.

Our approach covers the full value chain: from IAM strategy, through target architecture, tool selection and implementation, to continuous optimisation in operations. We bring experience from numerous programmes in EMEA, APAC and the US, with a clear industry focus on banking, insurance and industry – where regulation, scale and complexity meet.

Regulatory pressure notably intensifies in 2026: the MaRisk update sharpens requirements around IT entitlement management (AT 7.2 and the IT-specific BT chapters), while BAIT and the European DORA regulation, together with its level-2 Regulatory Technical Standards (RTS), require end-to-end ICT third-party risk management, granular access logging, documented emergency procedures and robust business-continuity evidence. In parallel, NIS-2 significantly broadens the scope of in-scope organisations across industry, energy, healthcare and public institutions, and mandates formal risk and incident-reporting processes. ISO 27001:2022 has sharpened the focus on access control, identity management, authentication information and rights revocation via the new controls A.5.15 to A.5.18. We translate these expectations into concrete controls: risk-based recertification intervals, a documented SoD matrix with exception handling, break-glass accounts with an end-to-end PAM session-recording chain, access reviews with owner attestation, and automated reporting for external auditors, internal audit and supervisors (BaFin, Bundesbank, ECB).

Our services

What we deliver

IAM Target Architecture & Strategy

We derive a resilient IAM target architecture from your business and IT strategy – including operating model, sourcing strategy and roadmap. We factor in hybrid cloud landscapes, legacy core systems and third-party connections and derive a coherent identity-fabric target picture. The result is a robust blueprint with clear governance, role accountability and quantifiable KPIs for programme steering committees.

  • IAM maturity and readiness assessments
  • Target design (IGA, PAM, authentication, federation)
  • Zero-trust framework and segmentation
  • Business case and ROI modelling
  • Roadmap with delivery waves and KPI framework
  • Identity-fabric architecture with hybrid cloud integrations
  • Sourcing and build-vs-buy analysis including TCO

SailPoint IIQ – Implementation & Optimisation

From greenfield implementation to modernisation of existing deployments – configurable, performant and audit-ready. We bring deep experience with SailPoint IdentityIQ – from data-model definition through configurable recertification campaigns to bespoke BeanShell rules and custom connectors. For existing platforms we deliver structured health checks, upgrade paths and performance optimisation.

  • Provisioning and workflow configuration
  • Target system integration (SAP, AD, ServiceNow)
  • Recertification campaigns and policy models
  • Performance tuning and health checks
  • UAT concepts, cutover and hypercare
  • Migration from IIQ 8.x to current LTS releases
  • Custom connector development and BeanShell rule design

Privileged Access Management (PAM)

We bring privileged access under control – from concept design to hardening critical systems. Core building blocks are PAM session recording with tamper-evident storage, just-in-time (JIT) access with approval workflows and clearly defined Privileged Access Thresholds (PAT) that automatically escalate elevated-risk activity. In addition we harden service accounts, decouple legacy systems and cleanly integrate all activity into SIEM and threat-detection tooling.

  • PAM target picture and operating model
  • Vault and session concepts (CyberArk, One Identity)
  • Just-in-time access and break-glass processes
  • Integration with SIEM and monitoring
  • Service account and legacy system hardening
  • PAM session recording with tamper-evident retention
  • Delegation chains and four-eyes approval for break-glass

RBAC & SoD Modelling

Clean role models are the foundation of efficient governance. We consolidate, clean up and model for the long term – with data-driven role mining and a robust SoD matrix that reflects supervisory conflict categories. The outcome is business-friendly roles, technically manageable system roles and a lifecycle with clear owners that keeps role sprawl at bay.

  • Analysis and clean-up of grown role structures
  • Role mining and business role design
  • SoD rule sets and conflict checks
  • Role ownership and lifecycle processes
  • Modelling with NEXIS Platform / IVIP
  • SoD matrix with exception handling and compensating controls
  • ABAC extensions for risk-based fine-tuning

Recertification & Audit-Readiness

We make your access landscape audit-proof – for internal audit, external auditors and supervisory bodies. We design risk-based recertification campaigns that discourage bulk approvals, anchor access reviews at the owner level and follow up findings rigorously. The outcome is auditable controls aligned with MaRisk AT 7.2, BAIT, DORA and ISO 27001:2022 with a complete evidence trail.

  • Recertification processes aligned with MaRisk and DORA
  • Ownership models and escalation logic
  • KPI and compliance dashboards (Power BI)
  • Audit preparation and findings management
  • Sustainable control documentation
  • Recertification campaigns with risk-based prioritisation
  • Access reviews with owner attestation and four-eyes principle

Connector Development

Custom integrations where standard connectors reach their limits – robust, maintainable and well documented. We apply proven patterns for idempotency, retry and rate-limiting and deliver operational documentation including a monitoring concept. This lets even complex HR triggers, cloud APIs and legacy systems integrate cleanly with IGA workflows and delegation chains.

  • SAP integration (HR, ERP, S/4HANA)
  • Active Directory and Entra ID
  • ServiceNow integrations and fulfilment
  • MIM/FIM extensions and migration paths
  • REST/SOAP connectors with error handling
  • Event-driven HR triggers for joiner-mover-leaver
  • Operations and monitoring handbook per connector

Methodology

Our 4-phase approach

  1. Analyse

    Capture of current architecture, entitlement landscape, regulatory requirements and maturity. Outcome: a solid baseline and clear fields of action.

  2. Strategy

    Definition of the IAM target architecture, selection of the right tools, operating model and governance, and a prioritised delivery roadmap.

  3. Implementation

    Setting up processes, configuring target systems, onboarding business units, migrating data, testing and delivering a controlled wave-by-wave rollout.

  4. Optimise

    Continuous improvement in operations: KPI steering, recertification cycles, performance tuning and adaptation to regulatory change.

Regulation

Regulation & compliance in detail

How we align IAM controls concretely with supervisory frameworks.

MaRisk & BAIT

The MaRisk update for 2026 and the BAIT sharpen the requirements around IT entitlement management (AT 7.2 and the IT-specific BT chapters). We anchor the principles of least privilege, segregation of duties and traceability in concrete processes: risk-based recertification intervals, SoD controls, access-request workflows and complete logging. All controls are documented in an audit-ready manner and evidenced through KPI dashboards for internal audit, external auditors and BaFin.

DORA (incl. level-2 RTS)

The Digital Operational Resilience Act has been binding since 17 January 2025 – its level-2 RTS on ICT third-party risk management, incident classification and threat-led penetration testing further concretise implementation into 2026. We provide the IAM-side foundation: governance structures, access and change logs, third-party access control, break-glass access with session recording, and reporting to the competent supervisory authorities. The outcome is an audit-ready DORA evidence trail for your critical ICT functions.

ISO 27001:2022 & NIS-2

The updated ISO 27001:2022 with Annex A and controls A.5.15 through A.5.18 puts access control, identity management, authentication information and rights revocation centre-stage. NIS-2 expands the regulated perimeter across many industry, energy and public-sector organisations and requires formalised risk, reporting and training processes. We map your IAM controls to both frameworks, close evidence gaps and prepare certification audits systematically.

References

IAM & security project experience

Selected project references by industry – without naming clients.

Banking

IAM Governance & Audit-Readiness

Build-up of a COBIT-based IAM governance with audit-ready recertification processes and Power BI dashboards for KPI steering towards auditors and supervisors.

  • Toolset: ServiceNow, Jira/XRay, Confluence, Power BI
  • Methodology: COBIT, MaRisk, requirements engineering, Scrum

Insurance

IAM Recertification & Audit Processes

Design and delivery of audit-proof recertification – including owner reviews, escalation logic and reporting – implemented in SailPoint IIQ with clear ownership structures.

  • Toolset: SailPoint IIQ, Jira/XRay, Confluence
  • Methodology: Requirements engineering, UAT, governance design

Insurance

DORA level-2 preparation

Build-up of a DORA-compliant governance, reporting and ICT third-party risk management framework: register of ICT third-party arrangements, incident classification along the RTS, access logging for critical systems, plus crisis exercises and reporting workflows to the competent authorities. The result was an audit-ready DORA evidence trail delivered on time for the level-2 RTS deadlines.

  • Toolset: ServiceNow GRC, Confluence, Power BI
  • Methodology: DORA RTS, ITIL, requirements engineering

Industry

IGA Tool Evaluation & POC Definition

Structured evaluation of IGA solutions with requirements workshops, fit/gap analysis, scoring matrix and POC design as decision basis for the management.

  • Toolset: Azure, SAP integration, Confluence, Jira
  • Methodology: Fit/gap, scoring, requirements engineering

Automotive

Global IAM rollout & role harmonisation

Consolidation of heterogeneous entitlement landscapes across multiple plants and country entities. Design of a harmonised business-role taxonomy, migration to SailPoint IIQ and introduction of SoD-based controls for SAP and engineering systems.

  • Toolset: SailPoint IIQ, SAP, Active Directory, Confluence
  • Methodology: Role mining, fit/gap, TISAX alignment

Public sector

IAM modernisation & NIS-2 readiness

Advising a public-sector organisation on the replacement of grown Active Directory structures and the build-up of a NIS-2-compliant IAM governance with clear accountabilities, incident processes and zero-trust building blocks. Focus on data-protection requirements and accessible processes.

  • Toolset: Microsoft Entra ID, Active Directory, ServiceNow
  • Methodology: NIS-2, BSI IT-Grundschutz, Zero Trust

Tools & Frameworks

Toolset & Frameworks

Related

Authorization Management

Structured role and access models, RBAC/SoD, recertification and clean-up of grown entitlement landscapes.

Managed Services

Operations, monitoring and continuous optimisation of your IAM and security platforms – reliable and SLA-backed.

Partner: NEXIS Platform

As a NEXIS Silver Partner we leverage the NEXIS Platform with IVIP for role analytics, governance visualisation and risk insights.

Lessons Learned

Common pitfalls in IAM rollouts

Anti-patterns from many programmes – and how we actively avoid them in our projects.

Role sprawl instead of consolidated business roles

Business units keep requesting new bespoke roles while existing ones are never cleaned up – the result is thousands of overlapping roles that neither owners nor auditors can penetrate. We prevent this with a strict role lifecycle, data-driven role mining and a clearly defined business-role taxonomy maintained jointly with the business.

Weak owner governance and unclear accountability

When roles, applications and entitlements have no business owner, decisions drift back to IT and governance decays. We anchor a viable ownership structure with RACI, deputy rules and periodic owner reviews, so that access reviews and recertifications are signed off by the right people – and stand up under scrutiny.

Recertification as a paper exercise (bulk approve)

Recertification campaigns where managers blanket-approve everything are worthless from a supervisory perspective and raise audit risk. We introduce risk-based prioritisation, context-rich displays (usage, criticality, peer comparison) and the four-eyes principle, so recertification becomes a real control again – not a clicking ritual.

PAM without session recording and break-glass control

A PAM tool on its own does not protect: without session recording, clear break-glass processes and delegation chains, privileged access remains opaque. We design PAM as a closed control chain – from just-in-time approval through session recording to tamper-evident retention and downstream analytics in the SIEM.

FAQ

FAQ

Which IAM tools does Vetrexa use?

We are tool-agnostic and work with SailPoint IdentityIQ, Microsoft Entra ID, CyberArk, One Identity and Microsoft MIM/FIM, depending on the client landscape. As a NEXIS Silver Partner we also use the NEXIS Platform with IVIP for role analytics and governance visualisation.

How does Vetrexa support MaRisk and DORA compliance?

We design supervisory-grade IAM governance models aligned with MaRisk AT 7.2, BAIT and DORA. This includes audit-ready recertification processes, SoD controls, break-glass access and KPI dashboards that stand up to internal audit, external auditors and BaFin.

Can you optimise existing SailPoint deployments?

Yes. We perform health checks, performance analyses and consolidations on existing SailPoint IIQ deployments – covering workflow refactoring, connector optimisation (SAP, AD, ServiceNow) and modernising recertification campaigns and role models.

How long does a typical IAM recertification project take?

A first audit-ready recertification campaign can usually be set up in 3 to 6 months. Full governance programmes with role re-modelling, tool rollout and international scaling typically run between 12 and 24 months, staggered by system and business area.

What is the difference between IAM, IGA and PAM?

IAM (Identity & Access Management) is the umbrella term for all processes around digital identities, authentication and authorisation. IGA (Identity Governance & Administration) adds governance capabilities on top of IAM: recertification, SoD checks, lifecycle management and attestation. PAM (Privileged Access Management) focuses specifically on privileged accounts – with vaulting, session recording, just-in-time access and break-glass processes. In practice we combine all three layers into a coherent identity-fabric approach.

How do RBAC and ABAC differ?

RBAC (Role-Based Access Control) grants permissions through roles aligned to tasks and organisational structures – ideal for stable processes and regulatory evidence. ABAC (Attribute-Based Access Control) decides dynamically based on attributes such as department, location, device posture or risk class, allowing fine-grained, context-aware policies. In modern zero-trust architectures we combine both: RBAC as a robust foundation, ABAC for risk-based fine-tuning and just-in-time access.

What role does Zero Trust play in our strategy?

Zero Trust is not a product but an architectural principle: never trust, always verify. Every access is evaluated in context – identity, device, network, risk signals. We anchor Zero Trust in IAM through rigorous least-privilege enforcement, strong authentication (MFA, phishing-resistant factors), microsegmentation, continuous session evaluation and deep integration with SIEM and XDR. The result is an IAM that consistently secures hybrid cloud, remote work and third-party access.

Ready for secure IAM governance?

Let's talk about your IAM and security roadmap – informal and at eye level.

Request consultation