About a-team Marketing Services
The knowledge platform for the financial technology industry
The knowledge platform for the financial technology industry

A-Team Insight Blogs

Sallie Mae and Société Générale Select SailPoint for Identity Governance and Compliance

Subscribe to our newsletter

SailPoint today announced that Sallie Mae and Société Générale have chosen SailPoint IdentityIQ to automate and streamline their identity related compliance processes. SailPoint IdentityIQ, an identity governance solution, helps corporations of all sizes keep track of who has access to critical applications, data and IT systems while greatly reducing audit and compliance costs. A comprehensive view of user identity data enables customers like Sallie Mae and Société Générale to more easily comply with regulations that require regular audits and certification of access privileges, including SOX, FISMA, Basel II, PCI and the European Union’s Data Protection Directive.

“As a publicly-traded company and financial services provider, we are subject to a variety of regulations including FISMA, SOX, PCI, and SAS 70,” said Jerry Archer, chief security officer for Sallie Mae. “To meet these requirements, we are standardising and automating our compliance processes for identity management, so that we can centrally control who gets access to sensitive resources and maintain compliance as the organisation changes over time. This centralised and automated approach allows us to proactively address risk and more efficiently maintain a compliant, secure environment.”

Identity governance provides companies with an enterprise-wide view of who has access to sensitive or proprietary information and applications. This allows them to analyse risk, make better decisions, and implement the appropriate controls for achieving and maintaining compliance. It also reduces the cost of compliance by creating a consistent, reliable and auditable process to manage access certification and policy enforcement.

“The compliance burden that global companies face will continue to grow in 2010 through additional industry regulations and stronger enforcement of existing mandates,” said Kevin Cunningham, president and founder of SailPoint. “SailPoint IdentityIQ provides companies with the necessary visibility to better understand the risks associated with user access privileges on sensitive information systems, allowing them to strengthen controls and automate compliance processes across the enterprise.”

Subscribe to our newsletter

Related content

WEBINAR

Upcoming Webinar: Sponsored by FundGuard: NAV Resilience Under DORA, A Year of Lessons Learned

Date: 25 February 2026 Time: 10:00am ET / 3:00pm London / 4:00pm CET Duration: 50 minutes The EU’s Digital Operational Resilience Act (DORA) came into force a year ago, and is reshaping how asset managers, asset owners and fund service providers think about operational risk. While DORA’s focus is squarely on ICT resilience and third-party...

BLOG

New Data Partnership Approach Urged for Investors in SimCorp Report

Investment managers must take a fresh approach to data management, stressing trusted partnerships with outside expertise over traditional outsourcing models, as they seek to adapt to a rapidly changing economic landscape, a report has urged. The binary build-versus-buy strategy that has been the basis of innovation adoption for decades has been upended by advances in...

EVENT

TradingTech Summit New York

Our TradingTech Briefing in New York is aimed at senior-level decision makers in trading technology, electronic execution, trading architecture and offers a day packed with insight from practitioners and from innovative suppliers happy to share their experiences in dealing with the enterprise challenges facing our marketplace.

GUIDE

The DORA Implementation Playbook: A Practitioner’s Guide to Demonstrating Resilience Beyond the Deadline

The Digital Operational Resilience Act (DORA) has fundamentally reshaped the European Union’s financial regulatory landscape, with its full application beginning on January 17, 2025. This regulation goes beyond traditional risk management, explicitly acknowledging that digital incidents can threaten the stability of the entire financial system. As the deadline has passed, the focus is now shifting...