Identity & Access Management Risk Checklist
IAM risk checklist covering joiners, movers, leavers, privileged access, MFA, service accounts, access reviews, segregation of duties, authentication, logging, and third-party access.
Identity failures are still among the most common ways systems — including AI products — are abused: leftover admin accounts, shared API keys, missing MFA on cloud consoles, and contractors who never lost access after a project ended.
This checklist is a practical lens for technology and risk partners. It is educational and does not constitute an audit programme or certification.
How to use it
- Scope one environment first (e.g. production cloud + SSO + AI vendor consoles).
- Evidence beats intention: screenshots, IdP policies, ticket IDs, last review dates.
- Re-run after org changes, M&A, or major vendor onboarding.
- Connect findings to your AI risk and vendor assessments when the same identities unlock model keys or customer data.
Joiners
New access should be role-based and approved, not cloned from a teammate’s over-privileged account.
- Standard role catalogue for engineering, support, finance, etc.
- Time-bound exceptions
- Separated identities for humans vs automation
Movers
Internal moves silently accumulate entitlements (“access creep”).
- Triggered add/remove on role change
- Expiring project access
- Manager attestation for sensitive apps
Leavers
Last-day disablement must cover more than the laptop SSO session.
- IdP / email / chat
- Cloud consoles and AI vendor seats
- PATs, API keys, deploy tokens, shared inboxes
- Device trust and VPN
Privileged access
Treat production admin, billing owners, and break-glass accounts as high-risk assets.
- Inventory and ownership
- Just-in-time elevation where possible
- Dual control for destructive actions when feasible
- Regular review of standing privileges
MFA
MFA is necessary but not sufficient; quality matters.
- Enforce for workforce and remote access
- Prefer phishing-resistant methods for admins
- Control recovery paths (SIM swap and backup-code abuse are real)
Service accounts
Machine identities often outlive the humans who created them.
- Named owner and purpose
- Least privilege and environment separation
- Rotation, scanning for leaked keys, emergency revoke
- No long-lived keys in git or client apps
Access reviews
Periodic reviews catch what joiner/mover automation misses.
- Cadence by sensitivity
- Reviewer accountability
- Documented keep/revoke outcomes
- Focus on admins, data stores, and AI/vendor consoles
Segregation of duties
Prevent one person from requesting, approving, and concealing sensitive changes.
- Define conflicts for your critical processes (deploy + prod data; finance + admin)
- Compensating monitoring when small teams cannot fully split roles
Authentication
Centralise where you can; exception-manage where you cannot.
- SSO coverage for critical apps
- Strong password and anti-stuffing baselines for residual local accounts
- Risk-appropriate sessions and step-up authentication
Logging
You cannot investigate what you never recorded.
- Authn success/failure and privilege use
- Retention aligned to incident needs
- Alerting on anomalous admin behaviour
- Protect logs from tampering by the same admins they monitor (as far as practical)
Third-party access
Vendors, contractors, and “temporary” integrators need the same discipline.
- Distinct identities
- Time bounds and tickets
- No shared generic logins
- Offboarding checklist that includes AI and cloud vendor seats
Closing note
Strong IAM will not make an unsafe AI use case safe — but weak IAM will undermine every other control. Use this checklist alongside the AI Risk Assessment Checklist and the educational DORA primer when identity underpins critical digital services.
Interactive checklist
Checked items are stored locally in your browser only.
joiners
movers
leavers
privileged access
MFA
service accounts
access reviews
segregation of duties
authentication
logging
third-party access
Related resources
Related Cursor prompts
Security Review for an AI SaaS
Cursor prompt for a practical security review of an AI SaaS — authz, RLS, prompt injection surfaces, secret handling, and data exfiltration paths.
Production Readiness Review
Cursor prompt for a structured production readiness review of an AI SaaS — security, reliability, cost, and operability findings with severities.
AI & tech risk
AI Risk Assessment Checklist
A practical AI risk assessment checklist covering use case, data, model, privacy, security, oversight, bias, vendors, monitoring, incidents, and business impact.
AI Vendor Risk Assessment Guide
Questions and considerations for assessing AI vendors: governance, data use, training, retention, subprocessors, hosting, security, transparency, resilience, exit, and contracts.
DORA for Technology Professionals
A high-level educational overview of DORA themes for technology professionals: ICT risk, resilience, third-party dependency, testing, and incident learning — not legal advice.
RemoteGeek Builder Notes
One practical lesson each week. No hype.
AI building, automation, and technology-risk notes for professionals and solo builders. Signing up stores your email for follow-up — automated newsletter delivery may be connected later.