By NHI Mgmt Group Editorial TeamBased on StrongDM: “The State of Compliance in Financial Institutions Report by StrongDM” (August 21, 2025)

TL;DR: A survey of 1,000 financial and fintech professionals found 88.4% are very confident they would pass a surprise audit, yet 64% of financial services companies have received an identity-related audit citation in the past two years and 49.3% still spend 10 to 25 hours a month preparing audit data, according to StrongDM. The gap is not confidence but provability: compliance programmes that cannot produce timely access evidence are already behind.


At a glance

What this is: This survey report argues that financial institutions are overconfident about audit readiness while still struggling to produce timely evidence for identity and privileged access controls.

Why it matters: IAM, PAM, and NHI programmes all depend on provable access state, so teams that cannot rapidly evidence who had access, when, and why will keep failing audits and investigations.

By the numbers:

  • 88.4% of respondents said they are very confident their organisation would pass a surprise compliance audit.
  • 64% of financial services companies have received an identity-related audit citation in the past two years.
  • 49.3% still spend 10 to 25 hours monthly preparing audit data.

Context

StrongDM’s survey shows a familiar governance pattern in regulated environments: confidence in compliance posture rises faster than the evidence needed to prove that posture. In financial services, that gap matters because auditability is not a paper exercise, it is a live control over access, logging, and privilege.

The report focuses on financial institutions and fintech firms where privileged access management, access reviews, and audit preparation remain operationally expensive. The central issue is not whether teams believe they are compliant, but whether they can produce defensible evidence quickly enough when regulators or internal audit ask for it.


Key questions

Q: What breaks when compliance teams cannot produce audit evidence quickly?

A: When teams cannot produce evidence quickly, the control may exist on paper but not in an examinable form. Auditors then see gaps in access traceability, revocation timing, and policy enforcement. That creates citations even when staff are confident the environment is compliant, because confidence is not proof.

Q: Why do financial institutions struggle with least privilege during audits?

A: They struggle because least privilege is hard to prove across changing access, delegated approvals, and multiple systems. If revocation timing and current entitlement state are not recorded consistently, auditors cannot verify that access stayed within policy. The result is a control that is described well but evidenced poorly.

Q: How do teams know whether their audit automation is actually working?

A: It is working when evidence is current, exceptions are detected in the same cycle they occur, and reconciliation errors fall rather than accumulate. If auditors still spend most of their time chasing screenshots, exporting reports, or reconciling spreadsheets, automation has only moved the work around. Effective audit automation should reduce control latency, not just reporting effort.

Q: When should organisations extend PAM controls to non-human identities?

A: Organisations should extend PAM as soon as service accounts, API keys, certificates, or automation identities can perform privileged actions. If those identities can modify infrastructure, access sensitive data, or bypass approval workflows, they need the same lifecycle discipline as human admins. Waiting until an incident creates avoidable risk.


Technical breakdown

Why audit confidence can diverge from evidence quality

Audit confidence is often a perception measure, while evidence quality is an operational one. A team can have policies, approvals, and review cadences in place and still fail to prove enforcement if logs are incomplete, access records are fragmented, or revocation timing is not captured. In regulated environments, the control is not just the rule itself but the ability to reconstruct who had access, what changed, and when it changed. That difference becomes acute when manual evidence gathering sits outside the control plane. Practical implication: treat evidence production as part of the control, not a separate reporting task.

Practical implication: design audit evidence capture into the access workflow so proof exists before the audit request arrives.

Privileged access management and least privilege under audit pressure

Privileged access management is where compliance narratives usually meet operational reality. If employees can reach 10 to 20 high-risk systems, if access revocation depends on manual approval, or if role-based access leaves only thin audit trails, then least privilege exists more as a policy than a verifiable state. The problem is not only excess access. It is the inability to show that access was scoped, monitored, and removed on time. In financial institutions, that gap turns routine identity governance into audit risk. Practical implication: measure revocation latency and evidence completeness together, because one without the other hides privilege creep.

Practical implication: align PAM controls with revocation evidence so least privilege can be demonstrated, not assumed.

Manual audit preparation remains a control weakness

When nearly half of respondents still spend 10 to 25 hours per month preparing audit data, the organisation is paying for fragmentation with analyst time. Manual compilation tends to amplify inconsistency because teams reconcile screenshots, exports, ticket trails, and access approvals after the fact. That is slow, error-prone, and difficult to defend under scrutiny. Automation here is not about convenience alone. It is about preserving a chain of custody for identity evidence across systems, especially where third-party access and privileged entitlements change frequently. Practical implication: replace manual evidence assembly with governed reporting pipelines that preserve source fidelity.

Practical implication: shift audit preparation from spreadsheet reconciliation to governed, system-generated evidence pipelines.


Threat narrative

Attacker objective: The practical attacker objective is to exploit unresolved privilege and weak access evidence to move through regulated systems without immediate detection or defensible audit traceability.

  1. Entry begins with excessive or weakly governed privileged access, especially where third-party access and high-risk systems are difficult to track consistently.
  2. Escalation occurs when access revocation is delayed, manual, or poorly evidenced, allowing privileges to persist beyond their intended scope.
  3. Impact appears as audit citations, failed evidence collection, and limited visibility into who can access regulated systems at any given time.
  • Zacks breach claim 2025: A hacker leaked 12 million Zacks accounts in 2025, claiming domain admin access in 2024; HIBP verified the data, Zacks has not confirmed.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Audit confidence is not the same as audit evidence: The report shows a programme can feel ready while remaining unable to prove access control outcomes under scrutiny. That is a governance failure because regulated environments require reconstructable evidence, not just documented intent. Financial institutions should treat proof generation as a first-class control outcome, not an afterthought.

Manual evidence collection is a control gap, not an inconvenience: Spending 10 to 25 hours a month assembling audit data signals that evidence is being stitched together after the fact. That process weakens chain of custody, increases error rates, and obscures whether access was actually revoked or only assumed to be revoked. The practitioner conclusion is simple: if evidence cannot be produced deterministically, the control is not operationally complete.

Least privilege fails when revocation is not observable: The article’s access findings show that privilege scope and privilege removal both matter, but many teams can measure neither with confidence. A least-privilege programme that cannot show timely removal or current access state is really a narrative, not a control. The implication is that governance teams need to define evidentiary thresholds for privilege, not just entitlement rules.

Governance confidence can outpace operational maturity across IAM, PAM, and NHI: The same evidentiary problem appears wherever access is dynamic, delegated, or difficult to inventory. Financial firms already know this in human access reviews, and the lesson carries directly into service accounts, workloads, and other non-human identities. The named concept here is evidence debt: the growing gap between what compliance says should be true and what the organisation can actually prove.

Regulated sectors are moving from policy-based compliance to proof-based compliance: The report’s investment intent in real-time audit logs and automated access controls points to a market shift, but the real change is conceptual. Organisations are starting to recognise that compliance is increasingly decided at the moment of access issuance, logging, and revocation, not during quarter-end review. Practitioners should align governance design with that proof-first model.

What this signals

Evidence debt: compliance programmes fail when they can describe access policy but cannot rapidly prove enforcement across systems, identities, and revocation events. In regulated environments, that debt accumulates every time evidence has to be reconstructed from tickets, spreadsheets, or point-in-time exports rather than emitted by the control itself.

Financial institutions should expect auditors to keep pressing on proof of least privilege, privileged access review, and revocation timing. The practical shift is toward controls that produce audit-ready artefacts continuously, because manual evidence assembly no longer scales with the pace of change.


For practitioners

  • Automate audit evidence capture Build evidence generation into access workflows so approvals, grants, revocations, and log events are retained as system records rather than reconstructed manually during audit prep.
  • Measure revocation latency Track how long it takes to remove access after role changes or exit events, then compare that figure to the systems and privilege levels that appear in audit findings.
  • Tighten privileged access logging Ensure elevated access to high-risk systems produces durable records that show who accessed what, when, and under which entitlement, with no reliance on screenshots or spreadsheets.
  • Expand access review scope to non-human identities Include service accounts, tokens, and automated access paths in the same review logic used for human users, because audit evidence gaps often begin where machine access is least visible.

Key takeaways

  • The report shows a clear gap between compliance confidence and the ability to produce defensible audit evidence.
  • Identity-related citations and manual audit preparation indicate that evidence quality remains a live operational problem in financial institutions.
  • Teams that want audit resilience need controls that generate proof continuously, especially for privileged and non-human access.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity and Access ManagementThe article centres on access governance, audit trails, and privileged access evidence in cloud-linked financial environments.
Recommendation — Use IAM controls to centralise access evidence and validate that entitlement records are audit ready.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe report focuses on whether organisations can prove access permissions and least privilege enforcement.
GV.RM-01 — Risk management strategy is established and agreed to by organizational stakeholdersThe survey exposes a governance gap between confidence and measurable compliance risk.
Recommendation — Tie entitlement reviews to PR.AA-05 and retain evidence that access decisions were enforced, not just approved. Define audit evidence readiness as a risk metric and report it in the governance strategy.
NIST SP 800-53 Rev 5AU-6 — Audit Record Review, Analysis, and ReportingThe report’s core issue is whether audit evidence is reviewable, complete, and timely enough for compliance use.
AC-2 — Account ManagementRevocation timing and lifecycle handling of access are central to the article’s access governance findings.
Recommendation — Use AU-6 to ensure access and privilege events are reviewable without manual reconstruction. Apply AC-2 to enforce timely account removal and make revocation evidence available for audits.

Key terms

  • Audit Evidence: Audit evidence is the record set used to prove that access was authorised, limited, and revoked according to policy. For modern identity programmes, evidence must come from runtime logs, approval events, and lifecycle records rather than from manual spreadsheets assembled after the fact.
  • Revocation Latency: Revocation latency is the time between a decision to remove access and the point at which that access is actually gone. It is a practical measure of how long stale privilege remains usable after a role change, offboarding, or contract end. Shorter latency means smaller exposure and cleaner audit evidence.
  • Privilege Access Management: Privilege Access Management is the discipline of controlling and monitoring elevated access to critical systems and data. It governs how privileged accounts, credentials, sessions, and commands are issued, used, recorded, and revoked, so administrative power is limited, traceable, and aligned to policy, risk, and operational need.
  • Evidence Debt: Evidence debt is the accumulation of missing, fragmented, or hard-to-assemble proof needed to show that identity controls are working. It becomes visible during audit, incident response, or investigation, and it usually signals that governance processes are not producing durable, auditable records.

Deepen your knowledge

NHI governance, identity lifecycle, and secrets management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org