GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

IAM-015 Role-Based Access Control

Tier 2+ProviderDeployerGPAI Model ProviderManaged Service Provider

Description

Access to systems and data is granted through defined roles rather than to individual accounts. A role catalogue records each role, the permissions it carries and its owner, and is reviewed at defined intervals. Access granted outside the role model is recorded as an exception with a documented justification and an expiry date.

Rationale

Role-based assignment reduces administrative overhead and makes access reviews tractable: a reviewer certifies a role once rather than every permission on every account. Issued in S2 when IAM-006 was split (CQ-031, ADR-033). Segregation of duties between roles, including conflicting role pairs, is GOV-009. Least-privilege scoping of what each role may do is IAM-005.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (11)

IAM-15Authorization Mechanismspartial
IAM-15Authorization Mechanismspartial
HIPAA-164.308.a.4.iInformation Access Managementinformative
HIPAA-164.308.a.4.ii.BAccess Authorizationinformative
HIPAA-164.312.a.1Access Controlfull
5.15Access controlpartial
NIS2-CIR-11.3Privileged Accounts and System Administration Accountsinformative
AC-2(7)Account Management | Privileged User Accountspartial
AC-24Access Control Decisionspartial
AC-6(1)Least Privilege | Authorize Access to Security Functionsfull
CC6.3Role-Based Access Controls and Least Privilegepartial

Evidence (1)

configurationtechnicalautomated

Role catalogue export from the identity provider or authorisation platform listing each defined role, the permissions it carries, its owner and the current user-to-role assignments.

Example: Identity provider group or role export listing every defined role with its permissions and members, with the role owner and last review date recorded in the access management system.

Test: Export the role catalogue and current user-to-role assignments. Verify: (1) access is assigned through roles rather than directly to individual accounts wherever the platform supports role assignment, (2) each role has a named owner and a review date within the defined interval, (3) any direct grant outside the role model has a recorded justification and expiry date, (4) the permissions of a sample of roles match their catalogue entry.

Questions (2)

boolean

Is access to systems and data assigned through defined roles rather than granted directly to individual users?

Role-based assignment must be the default. Direct individual-level grants should be exceptions with documented justification, not the norm.

multi

Which of the following describe your role-based access model?

A role catalogue lists every role with the permissions it carriesEach role has a named ownerRole definitions are reviewed at defined intervalsAccess granted outside the role model is recorded as an exception with a justification and an expiry dateNone of the above

Direct grants to individual accounts are exceptions, not the norm; each one needs a recorded justification and expiry date. The role catalogue export is the evidence.