Join our Newsletter — 33% off our NHI Course

Why do auditors still ask for screenshots and spreadsheets when governance tools are in place?

Because the evidence chain is fragmented. If approvals, SoD checks, provisioning outcomes, and remediation records are split across tools or local files, auditors cannot rely on one continuous trail and will ask for manual proof to reconcile what happened.

Why auditors still ask for manual evidence when tools already exist

Governance tools can prove that controls are configured, but auditors usually need to see that the control operated consistently over time. When approvals, segregation-of-duties checks, provisioning outcomes, and remediation records are scattered across systems, the toolset may be real, yet the audit trail is not continuous enough to trust without manual reconciliation.

That is why screenshots and spreadsheets persist: they are often used as bridge evidence when no single system can reconstruct the full chain from request to approval to access change to review outcome. If the evidence is exportable from one place but not auditable end to end, the control may exist operationally while still failing auditability.

A useful way to think about the problem is that governance tooling reduces effort, but it does not automatically solve evidence completeness. Auditors are not only asking, “Was the control present?” They are also asking, “Can I trace this specific event, decision, and outcome without relying on someone’s memory or a stitched-together explanation?”

Where the evidence chain breaks down

The common failure is fragmentation across ownership and record types. One team stores approval history in a workflow system, another keeps access changes in an identity platform, and remediation evidence lives in tickets, exports, or local files. Each source may be valid on its own, but unless timestamps, identities, objects, and outcomes line up, the audit trail remains incomplete.

This is especially visible in access governance, where auditors want to confirm that a request was approved by the right authority, that the access provisioned matched the approval, and that any exceptions or removals were handled on time. NHI governance platforms and identity governance tooling can help centralise that story, but the control evidence still has to be retained in a form that can be reassembled later. IGA Buyer’s Guide

For that reason, a pretty dashboard is not enough. If the underlying records cannot be exported, time-bounded, and linked to the exact person or workload involved, auditors will treat the dashboard as operational context rather than as primary evidence. That distinction matters most when the control is repeated many times across many accounts, because sampling depends on trust in the underlying record set.

How to make evidence auditable instead of decorative

Design evidence so it answers four questions without manual interpretation: who approved, what changed, when it changed, and where the proof of completion lives. If those fields are dispersed across tools, define a standard evidence package that can be generated consistently for reviews, provisioning, SoD exceptions, and remediation closure.

In practice, the strongest control evidence usually comes from system records, not screenshots. Screenshots can still be useful as supplementary context, but they are weak when they cannot prove completeness, chronology, or provenance. A spreadsheet is better than a narrative, yet it still depends on manual curation unless it is backed by source exports and change logs.

Teams reduce audit friction when they treat evidence as a product of the control, not an afterthought. That means retaining immutable logs where possible, preserving traceable identifiers across systems, and agreeing in advance which record is the system of record for each control step. AI Security Platform Buyer’s Guide

It also means planning for exceptions. If a control depends on a manual override, a compensating review, or a ticket-based remediation, the evidence must show the exception path just as clearly as the normal path. Otherwise the audit team will assume the process is ad hoc, even if the operational team believes it is controlled.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
CSA Cloud Controls Matrix IAM — Identity and Access Management Centralizes access governance evidence across identity and entitlement workflows.
Recommendation — Standardize IAM records so approvals, provisioning and reviews can be traced end to end.
NIST SP 800-53 Rev 5 AU-2 — Audit Events Auditability depends on recording the right control events for later reconstruction.
AU-6 — Audit Record Review, Analysis, and Reporting Auditors need reviewable records that support reconstruction and exception handling.
AC-6 — Least Privilege Access governance evidence often proves whether privileges were limited and approved.
Recommendation — Define and retain audit events that prove each control action and decision. Review logs and reports regularly to confirm evidence is complete and consistent. Validate that access changes and exceptions still enforce least-privilege intent.
ISO/IEC 27001:2022 A.5.15 — Access control Access control decisions require traceable evidence of authorization and review.
Recommendation — Keep access decisions and reviews tied to a consistent evidence trail.

Practitioner Guidance

What to verify: Confirm that every audited control has one traceable record path from request or trigger to approval, action, and closure. If that path crosses tools, define the joining fields up front, especially timestamps, object IDs, approver identity, and remediation status.

Common mistake: Treating dashboards as evidence when they are only summaries. If the underlying record cannot be exported and reconciled back to the source system, expect auditors to keep asking for screenshots, exports, or manual attestations.

What good looks like: A reviewer can sample an event and reconstruct the full story without interviewing the operator. The evidence set is consistent, time-aligned, and repeatable across controls rather than assembled differently every quarter.

Practitioner takeaway: The goal is not to eliminate all manual evidence overnight, but to reduce it by making the control chain traceable enough that manual proof becomes the exception instead of the default.