Join our Newsletter — 33% off our NHI Course
Home› Guides› Identity Security Regulatory Map
Regulatory Map Governance, Risk & Compliance

Identity Security Regulatory Map

← All guides
By Lalit Choda, NHI Mgmt Group Updated 26 September 2026 5 min read
On this page

Almost every major security regulation and framework contains identity requirements, even when it never uses the word "identity". Access control, least privilege, authentication, logging, third-party risk and timely removal of access appear in financial services rules, critical infrastructure directives, payment card standards, privacy law and AI regulation. This guide maps the main regulations and frameworks to the identity controls they rely on, for human, non-human and AI agent identities, so you can build one control set and evidence it many times. It is a practitioner summary, not legal advice; confirm obligations with your legal and compliance teams.

Key takeaways

  • A common core of identity controls satisfies most frameworks: unique identities, strong authentication, least privilege, lifecycle management, access reviews, privileged access control, logging, third-party access control and incident response.
  • Regulations generally apply to all identities with access, including service accounts, API keys and AI agents, even when written with users in mind.
  • Map controls once to all applicable frameworks and collect evidence continuously.
  • Scope and dates vary by sector and jurisdiction. Check the current text of each regulation.

Regulations and frameworks at a glance

Regulation / frameworkApplies toIdentity-relevant themes
EU DORA (Digital Operational Resilience Act)EU financial entities and critical ICT third-party providers; applies since 17 January 2025ICT risk management, access control and least privilege, logging, incident reporting, ICT third-party risk
EU NIS2 DirectiveEssential and important entities in covered sectors (implemented through national law)Cyber risk management measures, including access control, MFA, asset management and supply chain security
EU AI Act (as amended by the 2026 Digital Omnibus)Providers and deployers of AI systems; staged dates to 2028Logging, human oversight, robustness and cybersecurity for high-risk AI; transparency. See the Agentic AI Compliance Guide
GDPR / UK GDPRProcessing of personal dataSecurity of processing, access limitation, breach notification, data minimisation
SOX (US)Public companies' internal control over financial reportingAccess to financial systems, segregation of duties, access reviews, change control
PCI DSS v4.0.1Entities handling payment card dataUnique IDs, MFA, least privilege, management of system and application accounts, logging, access reviews
HIPAA Security Rule (US)Covered entities and business associates handling health dataAccess control, unique user identification, audit controls, authentication
NIST CSF 2.0Voluntary framework, widely adoptedGovern, Identify, Protect (identity management, authentication and access control), Detect, Respond, Recover
NIST SP 800-53 Rev. 5US federal systems; widely used as a control catalogueAC (Access Control), IA (Identification and Authentication), AU (Audit), PS (Personnel Security) families
NIST SP 800-63-4Digital identity guidelinesIdentity proofing, authentication assurance, phishing resistance, federation
ISO/IEC 27001:2022Certifiable ISMS standardAccess control, identity management, authentication information, privileged access rights, logging
ISO/IEC 42001:2023Certifiable AI management system standardAI system inventory, roles, lifecycle controls and supplier management
CIS Controls v8Prioritised safeguardsControls 5 (Account Management) and 6 (Access Control Management)
ASD Essential Eight (Australia)Baseline mitigation strategiesRestrict administrative privileges; multi-factor authentication

Mapping core identity controls

ControlDORANIS2PCI DSS v4.0.1SOXISO 27001NIST CSF 2.0
Unique identity for every human, NHI and agent✓✓✓✓✓✓
Strong / multi-factor authentication✓✓✓–✓✓
Least privilege and privileged access control✓✓✓✓✓✓
Joiner-mover-leaver and timely removal✓✓✓✓✓✓
Periodic access reviews✓–✓✓✓✓
Segregation of duties✓––✓✓–
Management of system and application accounts and secrets✓✓✓–✓✓
Logging and monitoring of access✓✓✓✓✓✓
Third-party and supplier access control✓✓✓–✓✓

A tick indicates the theme is addressed by the framework's requirements or expected controls; the exact wording and strength vary. A dash indicates it is not a primary explicit requirement, though it may still be expected by auditors. Use this as a starting point for your own control mapping.

Non-human identities and AI agents under regulation

  • Requirements for unique IDs, least privilege, logging and access removal generally apply to all accounts, including service accounts, API keys and machine credentials. PCI DSS v4.0.1 explicitly addresses system and application accounts (Requirement 8.6).
  • Third-party risk requirements under DORA and NIS2 cover OAuth integrations and SaaS vendors holding access. See the SaaS and OAuth App Governance Guide.
  • AI agents with access to regulated data or systems fall under the same controls, and high-risk AI systems face additional EU AI Act obligations.

Building a unified compliance approach

  1. Identify which regulations apply to which business units and systems.
  2. Define a single identity control set covering human, non-human and AI agent identities.
  3. Map each control to applicable framework requirements.
  4. Automate evidence collection from identity systems.
  5. Test controls through internal audit and continuous monitoring.
  6. Track regulatory changes, particularly AI regulation and national NIS2 implementations.

Standards and references

This guide summarises regulatory themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Agentic AI Compliance Guide · Access Reviews Guide · Identity Security Programme Guide · Segregation of Duties Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 26 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org