Home icon

How OCC and AWS Architected Enterprise-Scale Identity Governance for Critical Financial Infrastructure

Industries Blog



This article details how the Options Clearing Corporation (OCC), a systemically important financial market utility, partnered with AWS to modernize identity governance using AWS IAM Identity Center, replacing complex per-account access controls with a centralized, role-based framework.

  • OCC faced governance bottlenecks managing hundreds of individual IAM roles across growing AWS footprint
  • Previous per-account model created fragmented access, redundant entitlements, and complex onboarding processes
  • AWS IAM Identity Center provided centralized identity management with consistent permission sets across accounts
  • Infrastructure as Code with Terraform enabled version-controlled, auditable access definitions
  • SCIM v2.0 integration automated user lifecycle management from existing identity provider
  • Phased migration started with view-only roles, then parallel deployment, consolidation, and validation
  • Access provisioning time reduced from weeks to days; entitlement complexity significantly decreased
  • Unified audit trails improved compliance reporting and security incident investigation
  • Single sign-on enhanced user experience while maintaining comprehensive governance controls
  • Future IAM Access Analyzer deployment will enable continuous least-privilege monitoring and unused access detection

OCC's implementation demonstrates that simplifying identity governance through centralization and standardization strengthens security while reducing operational complexity, providing a blueprint for critical financial infrastructure modernization.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Nov 24
2025
Solve customer identity fragmentation at scale with AWS Entity Resolution
Feb 13
2024
Identity-as-a-Service Using Amazon Managed Blockchain for Invisible and Embedded Banking
Apr 28
2026
How OCC Built a Governed Cloud Foundation and Then Stress-Tested It
Sep 26
2024
Apply enterprise data governance and management using AWS Lake Formation and AWS IAM Identity Center

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.