Back to all 93 controls
    Annex A 5.16
    Organizational

    A.5.16 Identity management

    Each user has a unique, managed identity.

    What good looks like

    Identity lifecycle covering joiners, movers, leavers; no shared accounts where avoidable.

    Evidence an auditor will ask for

    IAM workflow, shared-account exception register, JML reports.

    Document template for this control

    The Access Control Policy template gives you auditor-ready wording that fulfils Annex A 5.16. Preview the full document before you download the editable version.