Back to all 93 controls
Annex A 5.16
Organizational
A.5.16 Identity management
Each user has a unique, managed identity.
What good looks like
Identity lifecycle covering joiners, movers, leavers; no shared accounts where avoidable.
Evidence an auditor will ask for
IAM workflow, shared-account exception register, JML reports.
Document template for this control
The Access Control Policy template gives you auditor-ready wording that fulfils Annex A 5.16. Preview the full document before you download the editable version.
