IAM Compliance and Governance
Download resourcesAbout this session
Mathieu Roy and Francois Lepire, both IAM architects and consultants at Indigo Consulting, co-present on building IAM governance rather than a specific product. They define governance as the policies, normative framework (directives, standards, guidelines) and processes, such as identity lifecycle and role management, that keep access aligned with least privilege and traceable to a justification, and they connect this directly to compliance drivers like Quebec's Law 25, cyber-insurance requirements, PCI and NIST. They stress that IAM governance protects data by proving who has access and why, push back on treating segregation of duties as purely a business-side problem, and argue that IT teams need clear, reasonably scoped procedures rather than vague expectations. For smaller organizations, their advice is to adapt scope to actual regulatory exposure, reuse what larger, more mature companies have already validated (including watching what major vendors choose), and avoid buying oversized tools for a handful of requirements. They close on staffing a dedicated governance function, common pitfalls such as writing unattainable standards or overloading teams with unrealistic deadlines, and recommend an incremental, 12-to-18-month maturity approach supported by strong change management.
Les sessions pourront se concentrer sur les clés du succès avec un cadre IAM et des processus IAM pour la conformité, les différentes stratégies d'audit et la gestion des accès privilégiés. Nous expliquerons pourquoi il est si important de mettre en place une gouvernance solide et efficace et donnerons quelques exemples tirés de notre expérience.
Key takeaways
- Separate your normative framework into a high-level 'what' (directives, policies) and a detailed 'how' (standards, guidelines) so both auditors and operational teams get what they need.
- Do not let segregation of duties become an unowned problem; work jointly with business, finance and audit teams to define what SOD actually means for each application.
- Right-size your tooling to your actual requirements; a smaller, cheaper product that meets 3-4 real needs beats an enterprise-grade suite bought for features you will not use.
- Budget roughly 35-40% of IT security spend toward IAM as a health check; a SOC-heavy, IAM-light staffing split (seen as high as 90-95% SOC) signals imbalance.
- Build your normative framework incrementally and revisit it on a 12-to-18-month cycle rather than committing to unattainable targets that erode trust with auditors and demoralize teams.
Speakers

Mathieu is a graduated Engineer and IAM leader with over 20 years of experience. Mathieu brings extensive knowledge of IAM, IGA, and PAM projects, as well as a proven track record of success in leading large-scale security and governance… Read moreRead less
Mathieu is a graduated Engineer and IAM leader with over 20 years of experience. Mathieu brings extensive knowledge of IAM, IGA, and PAM projects, as well as a proven track record of success in leading large-scale security and governance initiatives. In one of his previous roles as Director of Governance and Security Architecture at iA Financial Services, Mathieu managed tier-one projects, including the writing and implementation of a normative security framework aligned with NIST and Cobit Framewok. After this, he led a multidisciplinary IAM team to successfully deliver three main project axes: EIAM, HPAM, and CIAM. Furthermore, Mathieu redesigned the mode of service delivery and operations, resulting in increased efficiency and effectiveness.

A long-time contributor to IAM, François has worked in the various roles of IAM teams. From technician, to analyst, advisor, product owner and today, as principal architect, François has tangible experience of what the reality of each position is… Read moreRead less
A long-time contributor to IAM, François has worked in the various roles of IAM teams. From technician, to analyst, advisor, product owner and today, as principal architect, François has tangible experience of what the reality of each position is. This gives him an unparalleled perspective and experience, allowing him to brilliantly measure the impacts of governance decisions relating to the normative framework. Whether for optimizations, product management, detailed or reference architectures, François is an undeniable asset that can allow you to benefit from a trusted actor committed to your success. François specializes in roadmap development, detailed and reference architecture, as well as the deployment of PAM, IGA and CIAM solutions.


