Vetrexa Competence

IAM & Security

Identity & access management and IT security form the foundation of every modern, regulated IT landscape. Tightening regulations such as MaRisk, DORA and ISO 27001, hybrid cloud architectures and zero-trust principles turn resilient IAM into a strategic priority. Vetrexa supports you as a vendor-neutral partner – from target architecture through to day-to-day operations.

Overview

Why IAM & Security?

Digitalisation, cloud migration and zero-trust models are reshaping the logic of security. At the same time, MaRisk, BAIT, DORA and ISO 27001 sharpen expectations around evidence, control and auditability. Many organisations struggle with grown entitlement structures, heterogeneous target systems and inefficient recertification. This is exactly where we come in – as an independent consultancy without vendor lock-in, focused on sustainable governance and measurable outcomes.

Our approach covers the full value chain: from IAM strategy, through target architecture, tool selection and implementation, to continuous optimisation in operations. We bring experience from numerous programmes in EMEA, APAC and the US, with a clear industry focus on banking, insurance and industry – where regulation, scale and complexity meet.

Our services

What we deliver

IAM Target Architecture & Strategy

We derive a resilient IAM target architecture from your business and IT strategy – including operating model, sourcing strategy and roadmap.

  • IAM maturity and readiness assessments
  • Target design (IGA, PAM, authentication, federation)
  • Zero-trust framework and segmentation
  • Business case and ROI modelling
  • Roadmap with delivery waves and KPI framework

SailPoint IIQ – Implementation & Optimisation

From greenfield implementation to modernisation of existing deployments – configurable, performant and audit-ready.

  • Provisioning and workflow configuration
  • Target system integration (SAP, AD, ServiceNow)
  • Recertification campaigns and policy models
  • Performance tuning and health checks
  • UAT concepts, cutover and hypercare

Privileged Access Management (PAM)

We bring privileged access under control – from concept design to hardening critical systems.

  • PAM target picture and operating model
  • Vault and session concepts (CyberArk, One Identity)
  • Just-in-time access and break-glass processes
  • Integration with SIEM and monitoring
  • Service account and legacy system hardening

RBAC & SoD Modelling

Clean role models are the foundation of efficient governance. We consolidate, clean up and model for the long term.

  • Analysis and clean-up of grown role structures
  • Role mining and business role design
  • SoD rule sets and conflict checks
  • Role ownership and lifecycle processes
  • Modelling with NEXIS Platform / IVIP

Recertification & Audit-Readiness

We make your access landscape audit-proof – for internal audit, external auditors and supervisory bodies.

  • Recertification processes aligned with MaRisk and DORA
  • Ownership models and escalation logic
  • KPI and compliance dashboards (Power BI)
  • Audit preparation and findings management
  • Sustainable control documentation

Connector Development

Custom integrations where standard connectors reach their limits – robust, maintainable and well documented.

  • SAP integration (HR, ERP, S/4HANA)
  • Active Directory and Entra ID
  • ServiceNow integrations and fulfilment
  • MIM/FIM extensions and migration paths
  • REST/SOAP connectors with error handling

Methodology

Our 4-phase approach

  1. Analyse

    Capture of current architecture, entitlement landscape, regulatory requirements and maturity. Outcome: a solid baseline and clear fields of action.

  2. Strategy

    Definition of the IAM target architecture, selection of the right tools, operating model and governance, and a prioritised delivery roadmap.

  3. Implementation

    Setting up processes, configuring target systems, onboarding business units, migrating data, testing and delivering a controlled wave-by-wave rollout.

  4. Optimise

    Continuous improvement in operations: KPI steering, recertification cycles, performance tuning and adaptation to regulatory change.

References

IAM & security project experience

Selected project references by industry – without naming clients.

Banking

IAM Governance & Audit-Readiness

Build-up of a COBIT-based IAM governance with audit-ready recertification processes and Power BI dashboards for KPI steering towards auditors and supervisors.

  • Toolset: ServiceNow, Jira/XRay, Confluence, Power BI
  • Methodology: COBIT, MaRisk, requirements engineering, Scrum

Insurance

IAM Recertification & Audit Processes

Design and delivery of audit-proof recertification – including owner reviews, escalation logic and reporting – implemented in SailPoint IIQ with clear ownership structures.

  • Toolset: SailPoint IIQ, Jira/XRay, Confluence
  • Methodology: Requirements engineering, UAT, governance design

Industry

IGA Tool Evaluation & POC Definition

Structured evaluation of IGA solutions with requirements workshops, fit/gap analysis, scoring matrix and POC design as decision basis for the management.

  • Toolset: Azure, SAP integration, Confluence, Jira
  • Methodology: Fit/gap, scoring, requirements engineering

Tools & Frameworks

Toolset & Frameworks

Related

Authorization Management

Structured role and access models, RBAC/SoD, recertification and clean-up of grown entitlement landscapes.

Managed Services

Operations, monitoring and continuous optimisation of your IAM and security platforms – reliable and SLA-backed.

Partner: NEXIS Platform

As a NEXIS Silver Partner we leverage the NEXIS Platform with IVIP for role analytics, governance visualisation and risk insights.

FAQ

FAQ

Which IAM tools does Vetrexa use?

We are tool-agnostic and work with SailPoint IdentityIQ, Microsoft Entra ID, CyberArk, One Identity and Microsoft MIM/FIM, depending on the client landscape. As a NEXIS Silver Partner we also use the NEXIS Platform with IVIP for role analytics and governance visualisation.

How does Vetrexa support MaRisk and DORA compliance?

We design supervisory-grade IAM governance models aligned with MaRisk AT 7.2, BAIT and DORA. This includes audit-ready recertification processes, SoD controls, break-glass access and KPI dashboards that stand up to internal audit, external auditors and BaFin.

Can you optimise existing SailPoint deployments?

Yes. We perform health checks, performance analyses and consolidations on existing SailPoint IIQ deployments – covering workflow refactoring, connector optimisation (SAP, AD, ServiceNow) and modernising recertification campaigns and role models.

How long does a typical IAM recertification project take?

A first audit-ready recertification campaign can usually be set up in 3 to 6 months. Full governance programmes with role re-modelling, tool rollout and international scaling typically run between 12 and 24 months, staggered by system and business area.

Ready for secure IAM governance?

Let's talk about your IAM and security roadmap – informal and at eye level.

Request consultation