Evidence
Access reviews that survive an auditor’s sample
Almost every audit tests access review, because it is where joiners, movers and leavers all become visible at once.
Facts checked — 2026-09-11
What does a good access review look like?
It covers a defined list of systems, it is performed by someone who can actually judge whether the access is appropriate — usually the system or data owner rather than IT — and it records the decision for each account, including the ones left unchanged.
And then something happens. A review that identifies four accounts to remove and no record of their removal is worse than no review: it documents that you knew. The revocation, with its date, is as much a part of the evidence as the review itself.
The bottom line
Record who reviewed, what they decided, and what changed as a result. All three, or the control is incomplete.
Related services
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
Related insights
Evidence
Running an internal audit that is worth the day it costs
Its job is to find things before the external auditor does, not to pass.
Evidence
Corrective action is not the same as fixing it
A fix addresses the instance. Corrective action addresses why it happened.
Evidence
Evidence that collects itself
If producing evidence is a separate task, it will be skipped in a busy quarter.