This document describes the business problem of entitlement accumulation and the impact of this IT problem on organizations in the context of a growing set of regulatory requirements.

Having defined the business problem, this document then describes the process of access certification, used to respond to entitlement accumulation in a manner consistent with regulations such as Sarbanes-Oxley, HIPAA, 21CFR11 and GLB.

The challenge

The regulatory environment


Compliance requires AAA


Problems with AAA


Addressing problems with AAA requires IAM


