Funnel overlay image

Why regulation is putting identity and access governance under greater scrutiny

Steven Jones

Chief Technology Officer

Published: 05 October 2026

As regulation places identity and access governance under closer scrutiny, organisations need stronger control over human and non-human access, supported by evidence that stands up to review.

Regulators across sectors are becoming more specific about how organisations control access to critical systems. They want to know who or what has access, why it is needed and how quickly it can be removed.

Those expectations now cover suppliers, service accounts, workloads and AI agents as well as employees and administrators. Across critical infrastructure, healthcare and financial services, identity controls are being judged by their effect on service continuity, threat detection and organisational accountability.

How regulation is making identity controls more specific

Regulators have become more specific about identity and access as digital operations have grown more dependent on human, supplier and machine identities. The frameworks differ, but each links identity controls more closely to resilience, accountability and evidence.

For instance:

  • Cyber Assessment Framework (CAF) 4.0: Extends identity governance beyond employees to devices, systems and automated functions, connecting MFA, time-bound access and regular reviews to the protection of essential services.
  • Digital Operational Resilience Act (DORA): Treats identity governance as part of operational resilience, requiring lifecycle controls, least privilege and six-monthly access reviews for ICT systems supporting critical or important functions.
  • National Health Service Data Security and Protection Toolkit (NHS DSPT): Connects access governance to cyber resilience, supporting patient safety and service continuity through privileged access controls, quarterly reviews and prompt joiner, mover and leaver action.
  • Network and Information Systems Directive 2 (NIS2): Places access control and appropriate authentication within a wider governance framework covering supply-chain security and management accountability.

The frameworks are not interchangeable. Each has its own scope, enforcement model and policy objective. But the overlap in identity requirements is significant.

When weak identity controls become regulatory failures

Recent ICO enforcement shows how weak identity controls can become evidence of inadequate security governance. In one 2025 case, attackers entered through an account without MFA, exposing personal information belonging to almost 80,000 people and contributing to a fine of more than £3 million. A separate action announced the following month involved an infrequently used administrator account without MFA on a legacy system, leading to a fine of £60,000.

The lesson extends beyond MFA deployment. Every privileged or externally accessible account needs a current owner, a valid purpose, controls proportionate to its risk and a clear route to review, monitoring and withdrawal. Legacy and rarely used accounts cannot sit outside that standard.

For privileged, remote and high-impact access, phishing-resistant authentication provides stronger protection against credential theft than weaker MFA methods. Its value depends on consistent coverage across the identity estate, supported by lifecycle ownership and monitoring that show whether controls continue to work.

Third party dependencies are widening regulatory oversight

The impact of third-party failure rarely stops with the supplier. When ransomware disabled a critical NHS pathology provider in 2024, the NHS organisations that relied on it were not attacked directly. Yet more than 11,000 appointments and procedures were delayed across South-East London, disrupting patient care because a shared service had become unavailable.

Regulation is beginning to reflect that wider exposure. The proposed UK Cyber Security and Resilience Bill would bring managed service providers, data centres and designated critical suppliers into scope. In financial services, providers formally designated as critical third parties are subject to joint oversight by the FCA, PRA and Bank of England, alongside firms’ own operational resilience duties.

AI is expanding the identity perimeter

AI agents add a new layer to the identity-control challenge. Unlike conventional service accounts or workloads, they can act on instructions, call tools and take actions across connected systems with varying levels of autonomy.

The technology is developing quickly, while governance practice and regulatory guidance are still being defined. The NCSC describes its August 2026 publication as interim advice, with formal guidance expected to replace it as understanding of the risks develops.

These controls closely resemble those regulators have been strengthening for human and privileged identities. Organisations need to account for each identity with material access to a system:

  • What each identity can do
  • Why the access remains justified
  • How quickly it can be withdrawn

For organisations already struggling to govern service accounts and other non-human identities, AI increases the scale and urgency of the challenge.

Using common identity controls across regulatory regimes

The regulations differ, but they repeatedly test the same underlying capabilities: whether access is appropriate, protected, reviewed and accountable. Organisations that build those capabilities into their identity foundations can respond to changing requirements without creating a separate control environment for every regime.

Ebony fingerprint icon on transparent background

Authentication

MFA and strong authentication recur across CAF, NHS DSPT, DORA and NIS2, particularly for privileged, remote and critical access. Phishing-resistant methods offer stronger protection where compromise would have the greatest impact.

Ebony and green magnifying glass and person icon on transparent background

Lifecycle and access reviews

Review frequencies vary by framework and risk. Automated joiner, mover and leaver processes, plus reviews after role, supplier or privilege changes, reduce stale access and strengthen assurance.

Ebony and green people connected icon on transparent background

Third-party identities

Supplier access should be attributable, least privilege, time-bound where possible, monitored when privileged and reviewed at a frequency proportionate to risk.

Non-human identities

Systems, service accounts, workloads and AI agents need unique identities, clear owners, defined purposes, controlled credentials, appropriate monitoring and a reliable route to revocation.

Central logs and records of approvals, reviews, exceptions, privileged activity and revocation can support several frameworks when their integrity, retention, ownership and scope meet each regime’s requirements.

What regulation now requires from identity governance

Sector-specific regulation will continue to reflect different risks. A hospital, bank, government department and energy provider cannot be governed in exactly the same way.

But regulators are increasingly asking organisations to demonstrate stronger control over authentication, privilege, access lifecycle management, suppliers and non-human identities.

AI extends that responsibility to autonomous agents whose permissions, actions and continuing purpose must be attributable and controllable.

For organisations facing multiple regulatory regimes, the priority is to understand where requirements overlap, where they differ, and whether existing identity controls can provide the evidence regulators now expect.

Identity architecture and governance must now support the control, evidence and accountability required across each applicable regulatory regime.

Regulations may differ, but many are testing the same underlying identity capabilities. If you’d like to understand how your current controls align with regulatory expectations, get in touch.

tag icon

Microsoft Entra e-Guide

Move beyond legacy identity with Microsoft Entra

Discover how to:

  • Migrate identity services without disrupting business operations
  • Simplify provisioning with HR‑driven, API‑based workflows
  • Replace fragile on‑premises components with resilient cloud controls
  • Strengthen access decisions using Conditional Access
  • Reduce long‑term technical debt and identity risk
Butterfly overlay image

Author

Steven Jones

Chief Technology Officer

With more than 10 years’ experience in identity and security, he leads Kocho’s technology strategy, architecture, and proposition development, helping organisations build secure, scalable identity foundations aligned to the Microsoft roadmap.

tag icon

Become Greater

Keep one step ahead of the cyber attackers

Sign up to the Kocho newsletter to get exclusive news, the latest threat reports, Microsoft tech updates, and expert analysis from our cybersecurity specialists.

Plus invites to webinars and industry events.