Fortune 100 pharmaceutical company meets regulatory compliance more efficiently with cloud-based identity

decorative image
Time to read: 7 minutes

A Fortune 100 multinational pharmaceutical company is unified around its purpose of using the power of leading-edge science to save and improve lives around the world.

Challenge

Faced with a dated on-premises identity solution, a Fortune 100 pharmaceutical company sought to reinvigorate its program with a cloud-based solution that would improve operational efficiency, simplify regulatory compliance, and scale and integrate as needed.

Solution

A Fortune 100 pharmaceutical company selected SailPoint Identity Security Cloud Business Plus suite to manage lifecycle management and compliance. SailPoint has enabled this company to meet regulatory and compliance requirements more quickly and efficiently. It has simplified their audit processes while improving the overall operational efficiency of the company’s teams.

Industry

Pharmaceuticals

Company size

72,000 employees

Partner

Ernst & Young

Previously, we had a lot of manual processes. But with SailPoint we have automated onboarding and provisioning, and significantly increased our operational efficiency.”

Senior Director, Identity & Access Management, Fortune 100 pharmaceutical company

40%

less time spent on access reviews

90%

of reviews completed in the first 2-3 days of certification launch

30%

reduction of manual tasks performed by IT Operations

A Fortune 100 multinational pharmaceutical company is unified around its purpose of using the power of leading-edge science to save and improve lives around the world. To stay secure and compliant, they must put the same diligence into their internal systems and processes which enable their innovative health solutions. This means a worldwide workforce that can collaborate securely while also ensuring compliance with regulatory requirements. As a result, identity security has become a cornerstone for their cybersecurity initiatives.

“Identity is becoming the core for everything,” said the Senior Director of Identity & Access Management. “Compliance is an ever-increasing concern for us, there is a lot of scrutiny understandably from the FDA and other regulatory bodies. And when they are doing their inspections, they are getting much more technically savvy. They want to see who did what, when, and who approved it, because those things could be critical to inspections that these folks are doing things right.”

To address identity security, this company had previously deployed Oracle Identity Manager. They were challenged with spending considerable time and resources just maintaining the on-premises solution and could not extend its use to add new capabilities and bring on business-critical applications. In addition, they faced a companywide directive to adopt a cloud-first strategy, which aided in the decision to find something new.

Because of this, they chose SailPoint IdentityNow as their identity security solution to address lifecycle management and compliance. SailPoint was a match for their cloud requirements, had a solid future roadmap, and could support and enable zero-trust initiatives. In addition, it was important to this company that their future solution would lend itself to enabling prominent levels of product quality and patient safety.

“We are much more confident now as we are building on the SailPoint installation in our environment that we are going to be able to better meet those types of regulatory requirements and inquiries,” said the Senior Director of Identity & Access Management.

Identity as we all know is one of the pillars for zero trust. We have made it as a non-negotiable prerequisite pillar for zero trust; you must do this to get to zero trust and SailPoint plays a key role in doing that for our company.”

Senior Director, Identity & Access Management, Fortune 100 pharmaceutical company

Standardizing processes and enforcing accuracy

The pharmaceutical company went live with SailPoint in 2022, initially focusing on provisioning, access requests, and access certifications. When they started looking to invest in a new identity security solution, one of the biggest areas they wanted to address was improving the overall operational efficiency of their Identity and Access Management teams. “Previously, we had a lot of manual processes,” said the Senior Director of Identity & Access Management. “But with SailPoint we have automated onboarding and provisioning, and significantly increased our operational efficiency.” The pharmaceutical company has simplified and standardized joiner, mover, leaver processes for around 195,000 identities; 135,000 human identities, (72K employees and 62K contingent workers), and another 60,000 nonpersonal accounts.

The pharmaceutical company uses the ServiceNow ServiceDesk Integration module to handle access requests for end users to assist with their provisioning actions. One of the requirements they face in the pharmaceuticals industry is revalidation for GxP applications. Before they approve access to a GxP application, they must re-enter their credentials at the time of approval. ServiceNow allows them to reauthenticate a user, which was the driving factor for them to utilize the integration module.

The pharmaceutical company has made an ongoing effort to get all their SOX applications onboarded to SailPoint. There has also been a recent mandate for all high value applications to be onboarded, about 500+ applications total. They have been able to successfully take the various connector types that SailPoint provides and connect to several of their high value applications, especially in the SOX area. Their internal audit team expressed excitement over the simplification of their processes of evidence gathering and making it easier for them to do their job in a more consistent manner. “And when you are talking about SOX, anything that gives extra credibility to the control around those platforms goes a long way with the internal and external audit, who then also report this all up to our Board of Directors,” said the Director of Identity & Access Management.

The pharmaceutical company has focused very heavily on standardizing processes and enforcing more completeness and accuracy with SailPoint. They have standardized access review processes into automated workflows and have ensured that all necessary data elements are captured so that there is proper identity governance around all identities. This has provided immense confidence to the application team when having to answer to audit. “Ensuring completeness and accuracy really gives our auditors significantly more confidence in the reporting,” said the Senior Director of Identity & Access Management.

With a solid identity security foundation in place with IdentityNow, the pharmaceutical company was ready to dive into more diverse use cases and expanded their solution to SailPoint Identity Security Cloud Business Plus suite. They began this journey with SailPoint Identity Security Cloud in 2024 and are excited to use the suite to address SOX compliance through Separation of Duties, as well as Cloud Infrastructure Entitlement Management (CIEM) to extend identity security to cloud infrastructure and govern cloud entitlements.

Driving digital transformation and increasing security through identity

As this pharmaceutical company looks to the future, one area of focus is its overall zero trust journey. “Identity as we all know is one of the pillars for zero trust. We have made it as a non-negotiable prerequisite pillar for zero trust; you must do this to get to zero trust and SailPoint plays a key role in doing that for our company.”

SailPoint is essential in providing the user identity data for the zero-trust framework. This is key especially when dealing with high-risk access to applications. It is critical because once onboarded, it becomes quite easy to start putting zero trust policies around those users for those applications. This has been a big push for the pharmaceutical company.

The pharmaceutical company is positive about the collaboration with SailPoint and looks forward to future successes. “There has always been active engagement to say we want you as a customer, we want you to be successful in adopting our product and we want to have that partnership. We have always felt that was ingrained in the relationship that we have had with SailPoint so far.”