The Australian Prudential Regulation Authority (APRA) has issued a request for quote, seeking a partner to deliver an Identity and Access Management (IAM) solution that supports APRA’s identity security, access governance and regulatory compliance objectives.
Following a market assessment process, APRA has shortlisted SailPoint Technologies (Identity Security Cloud) and Saviynt Enterprise Identity Management as the candidate platforms for implementation.
Interested suppliers may submit a proposal for one or both platforms; however, APRA intends to appoint a single implementation partner to implement one selected IAM platform.
The successful supplier will be responsible for solution implementation, configuration, integration, testing, knowledge transfer and transition to operational support.
APRA is conducting a separate RFQ process for the procurement of the IAM software licences, which is currently underway in the market. The outcome of that procurement will determine the IAM platform to be implemented.
In the current state, APRA uses Microsoft Identity Manager (MIM) as its primary identity management platform for user account provisioning and lifecycle management. MIM integrates with several enterprise systems, including Oracle HCM, which serves as the authoritative source of workforce data and Microsoft Active Directory (AD).
As part of this project, APRA intends to replace MIM with a modern IAM platform.
APRA also utilises ServiceNow (internally referred to as SHOP) as its access request and fulfilment platform. Staff submit access requests through SHOP, which initiates the relevant approval workflows. Following approval, access requests are either provisioned automatically or in most cases, fulfilled manually by APRA's Service Desk team.
Among the benefits APRA seeks from implementing a new IAM solution are the reducition of unauthorised access by enforcing least-privilege and role-based access controls; automatically provisioning and removing access as employees join, move or leave the organisation; and automating access requests, approvals and provisioning workflows, thus reducing manual effort.
It also want the solution to provide users with timely access to required systems and applications from day one; deliver a single view of user identities, roles and entitlements across the organisation; detects and remediate orphaned accounts, excessive privileges and SoD violations; and enable regular access reviews and certification campaigns to ensure appropriate access.
The RFQ closes at 11:59pm, Canberra time on 27 August.




