A Config rule that checks that none of your IAM users have policies attached. IAM users must inherit permissions from IAM groups or roles.

CloudFormation Template