Almost every major security regulation and framework contains identity requirements, even when it never uses the word "identity". Access control, least privilege, authentication, logging, third-party risk and timely removal of access appear in financial services rules, critical infrastructure directives, payment card standards, privacy law and AI regulation. This guide maps the main regulations and frameworks to the identity controls they rely on, for human, non-human and AI agent identities, so you can build one control set and evidence it many times. It is a practitioner summary, not legal advice; confirm obligations with your legal and compliance teams.
Key takeaways
- A common core of identity controls satisfies most frameworks: unique identities, strong authentication, least privilege, lifecycle management, access reviews, privileged access control, logging, third-party access control and incident response.
- Regulations generally apply to all identities with access, including service accounts, API keys and AI agents, even when written with users in mind.
- Map controls once to all applicable frameworks and collect evidence continuously.
- Scope and dates vary by sector and jurisdiction. Check the current text of each regulation.
Regulations and frameworks at a glance
| Regulation / framework | Applies to | Identity-relevant themes |
|---|---|---|
| EU DORA (Digital Operational Resilience Act) | EU financial entities and critical ICT third-party providers; applies since 17 January 2025 | ICT risk management, access control and least privilege, logging, incident reporting, ICT third-party risk |
| EU NIS2 Directive | Essential and important entities in covered sectors (implemented through national law) | Cyber risk management measures, including access control, MFA, asset management and supply chain security |
| EU AI Act (as amended by the 2026 Digital Omnibus) | Providers and deployers of AI systems; staged dates to 2028 | Logging, human oversight, robustness and cybersecurity for high-risk AI; transparency. See the Agentic AI Compliance Guide |
| GDPR / UK GDPR | Processing of personal data | Security of processing, access limitation, breach notification, data minimisation |
| SOX (US) | Public companies' internal control over financial reporting | Access to financial systems, segregation of duties, access reviews, change control |
| PCI DSS v4.0.1 | Entities handling payment card data | Unique IDs, MFA, least privilege, management of system and application accounts, logging, access reviews |
| HIPAA Security Rule (US) | Covered entities and business associates handling health data | Access control, unique user identification, audit controls, authentication |
| NIST CSF 2.0 | Voluntary framework, widely adopted | Govern, Identify, Protect (identity management, authentication and access control), Detect, Respond, Recover |
| NIST SP 800-53 Rev. 5 | US federal systems; widely used as a control catalogue | AC (Access Control), IA (Identification and Authentication), AU (Audit), PS (Personnel Security) families |
| NIST SP 800-63-4 | Digital identity guidelines | Identity proofing, authentication assurance, phishing resistance, federation |
| ISO/IEC 27001:2022 | Certifiable ISMS standard | Access control, identity management, authentication information, privileged access rights, logging |
| ISO/IEC 42001:2023 | Certifiable AI management system standard | AI system inventory, roles, lifecycle controls and supplier management |
| CIS Controls v8 | Prioritised safeguards | Controls 5 (Account Management) and 6 (Access Control Management) |
| ASD Essential Eight (Australia) | Baseline mitigation strategies | Restrict administrative privileges; multi-factor authentication |
Mapping core identity controls
| Control | DORA | NIS2 | PCI DSS v4.0.1 | SOX | ISO 27001 | NIST CSF 2.0 |
|---|---|---|---|---|---|---|
| Unique identity for every human, NHI and agent | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Strong / multi-factor authentication | ✓ | ✓ | ✓ | – | ✓ | ✓ |
| Least privilege and privileged access control | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Joiner-mover-leaver and timely removal | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Periodic access reviews | ✓ | – | ✓ | ✓ | ✓ | ✓ |
| Segregation of duties | ✓ | – | – | ✓ | ✓ | – |
| Management of system and application accounts and secrets | ✓ | ✓ | ✓ | – | ✓ | ✓ |
| Logging and monitoring of access | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Third-party and supplier access control | ✓ | ✓ | ✓ | – | ✓ | ✓ |
A tick indicates the theme is addressed by the framework's requirements or expected controls; the exact wording and strength vary. A dash indicates it is not a primary explicit requirement, though it may still be expected by auditors. Use this as a starting point for your own control mapping.
Non-human identities and AI agents under regulation
- Requirements for unique IDs, least privilege, logging and access removal generally apply to all accounts, including service accounts, API keys and machine credentials. PCI DSS v4.0.1 explicitly addresses system and application accounts (Requirement 8.6).
- Third-party risk requirements under DORA and NIS2 cover OAuth integrations and SaaS vendors holding access. See the SaaS and OAuth App Governance Guide.
- AI agents with access to regulated data or systems fall under the same controls, and high-risk AI systems face additional EU AI Act obligations.
Building a unified compliance approach
- Identify which regulations apply to which business units and systems.
- Define a single identity control set covering human, non-human and AI agent identities.
- Map each control to applicable framework requirements.
- Automate evidence collection from identity systems.
- Test controls through internal audit and continuous monitoring.
- Track regulatory changes, particularly AI regulation and national NIS2 implementations.
Standards and references
- Regulation (EU) 2022/2554 (DORA)
- Directive (EU) 2022/2555 (NIS2)
- Regulation (EU) 2024/1689 (AI Act)
- PCI DSS v4.0.1
- NIST Cybersecurity Framework 2.0
- NIST SP 800-53 Rev. 5
- NIST SP 800-63-4
- ISO/IEC 27001:2022 and ISO/IEC 42001:2023
- CIS Controls v8
- ASD Essential Eight
This guide summarises regulatory themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Agentic AI Compliance Guide · Access Reviews Guide · Identity Security Programme Guide · Segregation of Duties Guide