Skip to content
SecuriFii

Evidence

Access reviews that survive an auditor’s sample

Almost every audit tests access review, because it is where joiners, movers and leavers all become visible at once.

Facts checked2026-09-11

What does a good access review look like?

It covers a defined list of systems, it is performed by someone who can actually judge whether the access is appropriate — usually the system or data owner rather than IT — and it records the decision for each account, including the ones left unchanged.

And then something happens. A review that identifies four accounts to remove and no record of their removal is worse than no review: it documents that you knew. The revocation, with its date, is as much a part of the evidence as the review itself.

The bottom line

Record who reviewed, what they decided, and what changed as a result. All three, or the control is incomplete.

Related insights