Compliance audit checklists — every evidence artifact your auditor will ask for.
Practitioner-maintained audit checklists for the four regulatory frameworks that drive most regulated-enterprise IAM programs. Every IAM-specific evidence artifact an auditor will ask for, with collection-tip notes. CC BY 4.0.

FedRAMP
Every IAM-specific evidence artifact a 3PAO will request during a FedRAMP authorization or annual ConMon review.
Initial authorization + annual ConMon + monthly evidence emission
HIPAA Security Rule
IAM-specific evidence artifacts HHS-OCR and certifying auditors request under the HIPAA Security Rule (45 CFR 164).
Annual risk assessment + ongoing — no formal certification, but enforcement on breach
SOC 2
IAM-specific evidence artifacts a SOC 2 auditor (CPA firm) tests during a Type 1 or Type 2 examination.
Annual — Type 1 is point-in-time, Type 2 covers a 6-12 month observation window
FFIEC
IAM-specific evidence the FFIEC examiners (OCC, FDIC, Federal Reserve, NCUA, CFPB) request during banking-IT examinations.
12-18 month examination cycle; continuous evidence collection in between