Free checklist · PDF

The post-merger IAM checklist for credit unions.

A practical, phase-by-phase guide to keeping member data secure, access clean, and examiners satisfied through every stage of a merger or acquisition.

What’s inside

Five phases, one owner per item.

Every checklist item is written to be assigned to an owner and a date before the conversion date is locked.

  • Phase 1 · Due diligence & pre-closeInventory every identity system at both institutions, catalog privileged and vendor accounts, and flag orphaned and shared logins before close.
  • Phase 2 · Planning & access mappingBuild one view of every user, system, and entitlement, define the target RBAC model, and set a hard decommission date for the non-surviving core.
  • Phase 3 · Core conversion windowProvision on least-privilege defaults, require maker/checker on admin accounts, and disable rather than delete legacy accounts to keep the audit trail.
  • Phase 4 · Post-conversion stabilizationRun a complete population access certification, remove temporary conversion access, and assemble the examiner file with evidence of sign-off.
  • Phase 5 · Steady-state governanceCalendar a recurring review cadence, formalize joiner-mover-leaver workflows, and retire spreadsheet-based access tracking.

Also in the guide

Where IAM breaks down during a merger, credit union-specific considerations for core platforms and NCUA exams, a roles-and-ownership table, and a glossary.