Join our Newsletter — 33% off our NHI Course

Who is accountable when finance, IT, and audit use different control evidence?

Accountability should sit with the control owners who can connect system change, identity access, and reporting evidence end to end. If finance, IT, and audit each hold separate records, no single team can prove control continuity, and SOX assurance becomes fragmented rather than defensible.

Why control accountability breaks when evidence is split

Accountability lives with the team that can prove the control worked from system change through access decisions to reporting output. If finance, IT, and audit each retain partial evidence, the control may still exist in practice, but no single owner can demonstrate continuity, exceptions, or timing. That makes the assurance story fragile, especially when a SOX control depends on multiple handoffs.

In practice, the accountable party is usually the control owner or control operator named in the process, not whichever team happens to store the final artifact. Finance may own the business assertion, IT may operate the underlying change or access control, and audit may test it, but ownership must include the ability to reconcile those records into one defensible chain.

What evidence continuity has to show

A defensible control record answers three questions at once: what changed, who had access, and what was reported or reviewed. When those pieces live in separate systems, the issue is not just inconvenience, it is loss of traceability. Evidence must be linkable across the same period, the same control, and the same population of users, systems, or transactions.

This is where access evidence often becomes the connective tissue. Identity and privilege records show whether the right people or service accounts could act, system change records show whether the environment changed in a way that affects the control, and reporting evidence shows whether the business consumed the result. Without all three, the control may be individually plausible but not audit-ready.

For teams trying to standardise that chain, NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful because it frames access governance, audit trails, and recertification as part of one control narrative rather than separate departmental tasks.

Who owns the answer when departments disagree

Disagreement usually happens because each function treats its own record as the authoritative one. Finance may view the control as a reporting obligation, IT as a technical safeguard, and audit as an evidence consumer. The practical fix is to assign one accountable owner who can convene the other custodians, define the canonical evidence set, and resolve mismatches before close or testing.

That does not mean every department loses responsibility. It means accountability is not distributed equally across the evidence fragments. If a control failure can only be proven by stitching records together, the owner must also own the stitch. Otherwise, exceptions become arguable, and remediation slips into a debate about documentation instead of control performance.

When the issue extends into identity governance or access recertification, the same discipline applies to the underlying access chain. NHIMG’s Ultimate Guide to NHIs, Regulatory and Audit Perspectives also helps practitioners think about who can prove entitlement, review, and revocation, not just who can state that a control exists.

Why fragmented evidence becomes a control failure

Fragmented evidence creates a weak point at the handoff boundary. One team may attest that the change was approved, another that access was restricted, and another that the output was reviewed, but if those claims cannot be joined into a single timeline, the control cannot be tested end to end. That is especially damaging for SOX because the control objective is not local completeness, it is demonstrable reliance.

The risk is amplified when evidence is maintained for different purposes. Audit may keep sample-based testing files, IT may retain operational logs, and finance may keep certification sign-offs. Each is useful, but none is sufficient alone. The control owner needs a retained chain that shows how the control operated in the period under review and how exceptions were handled.

For assurance and attestation contexts, the most relevant external benchmark is the SOC 2 Trust Services Criteria (AICPA), because it formalises the expectation that controls, monitoring, and evidence must support a defensible trust assertion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while SOC 2 (AICPA) and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
SOC 2 (AICPA) CC4.1 — Communication and Information Split evidence must be communicated and reconciled for a defensible control story.
Recommendation — Centralize control evidence so one owner can reconcile records across finance, IT, and audit.
NIST SP 800-53 Rev 5 AU-6 — Audit Review, Analysis, and Reporting Evidence fragments must be reviewed and correlated to support control assurance.
Recommendation — Correlate logs, approvals, and reports to prove the control operated end to end.
ISO/IEC 27001:2022 A.5.28 — Collection of Evidence Audit-ready control proof depends on gathering and preserving evidence coherently.
Recommendation — Define one evidence collection path and preserve traceability across all control owners.

Practitioner Guidance

What to verify: Confirm that one named owner can produce the full evidence chain for the control period, including the system change record, the access record, and the reporting or review artifact. If any link in that chain is owned by a different team, define the handoff and the reconciliation step explicitly.

Decision rule: If finance, IT, and audit each hold different artifacts, treat the control as unresolved until one control owner can reconcile them into a single timeline. Do not rely on parallel attestations that cannot be joined.

What good looks like: The same control can be re-performed or retested from one evidence set without chasing three teams for three different versions of the truth. That is the practical test for defensible accountability.

Practitioner takeaway: Accountability belongs to the function that can prove the control end to end, not the function that merely stores the final report.