Compliance Mapping

Control Requirement
NIST Control
FCA Reference
Xcavate Implementation

Audit Trails for Access

AU-2, AU-6

Principle 10

Logs monitored and reviewed monthly

Role-Based Access Control

AC-6

SMCR Role Accountability

Standardised job-role profiles with linked access

User Access Review

AC-2(4), AC-6(10)

Operational Resilience

Access recertification dashboards and action logs

Offboarding Process

AC-2(3)

Operational Risk Mgmt

Auto-deprovisioning triggered by HR system

Last updated