Join our Newsletter — 33% off our NHI Course

What breaks when ISO 27001 user access reviews do not produce audit evidence?

The review stops being defensible. Auditors need to see who reviewed access, what changed, when it changed, and why the decision was made. If that trail is missing, the organisation may have performed the task but cannot prove control, which is enough to create certification and governance risk.

Why an access review is not really complete until the evidence exists

An ISO 27001 access review is only defensible when the organisation can show the review record, the reviewer, the date, the decision, and the resulting change. That is why access certification is treated as a control activity, not just an administrative task. The evidence trail turns a claimed review into something an auditor can test, trace, and trust.

When the trail is weak, the problem is usually not that access was never looked at. The problem is that the review cannot be reconstructed after the fact, which makes the control fragile even if the underlying decision was sensible.

Evidence also matters because access review is not isolated from the rest of identity governance. Good programmes connect review outcomes to entitlement removal, role cleanup, and lifecycle controls such as Access Reviews and Certification Guide and IAM and IGA Basics, so the record shows both the decision and the control effect.

What actually breaks in ISO 27001 terms

The first break is auditability. If there is no durable evidence, the organisation loses the ability to prove that access reviews were performed consistently, by the right approver, against the right population, and with timely follow-up.

The second break is governance. A review without traceable outcomes cannot support certification, management assurance, or later challenge. That gap is especially visible when reviews are tied to recurring control testing, because the reviewer’s intent is no longer enough without a dated, attributable artefact.

The third break is control closure. If reviewers identify excessive access but the workflow does not preserve what changed, the organisation cannot demonstrate that the control reduced exposure. In practice, that leaves the business with a “review happened” claim but no proof that the risk was actually resolved. That is why access governance programmes often anchor evidence to remediation tracking, such as IGA Buyer’s Guide and Joiner-Mover-Leaver (JML) Guide.

For organisations with privileged or machine access in scope, the same logic applies to the review of standing access and long-lived entitlements. A review record that cannot show who approved retention and why leaves too much room for challenge, especially where higher-risk roles or accounts were involved.

How to make access reviews defensible in practice

Defensibility comes from making the review record specific enough to survive later scrutiny. The minimum useful evidence usually includes who reviewed, which access items were in scope, what was removed or retained, the reason for each exception, and when remediation was completed.

Where reviews cover broad role sets or many systems, the evidence should also show that the sample or population was complete, not hand-picked. This is where role structure and segregation logic matter, because weak role design can make the evidence look tidy while hiding poor access decisions underneath. A strong role model and SoD discipline, such as Role Mining and Role Design Guide and Segregation of Duties (SoD) Guide, makes the review output more meaningful.

Where audits ask for proof, not process narratives, teams should be ready to produce screenshots, export files, approval logs, or ticket links that are immutable enough to demonstrate the decision path. If that evidence cannot be reproduced without manual reconstruction, the control is too brittle for serious assurance.

Risk and Threat Considerations

When access reviews do not produce evidence, the immediate risk is failed auditability, but the deeper risk is unchecked privilege creep. Control owners may believe access has been cleaned up while excessive entitlements, stale access, or weak exceptions remain hidden from later review.

Failure mechanism: The organisation cannot reconstruct the review event, so it cannot prove the reviewer, the scope, the decision rationale, or the remediation status. That creates a gap between control performance and control assurance.

Impact: The result can be certification findings, governance challenge, delayed remediation, and repeated exposure to access that should have been removed. In higher-risk environments, the same gap can also weaken detection of abuse because there is no reliable baseline of what should have changed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

ISO/IEC 27001:2022 provides the primary governance reference for this topic.

Framework Control / Reference Relevance
ISO/IEC 27001:2022 A.5.15 — Access Control Access reviews must evidence who can access what under the ISMS.
A.5.28 — Collection of Evidence The question is about audit evidence needed to defend control operation.
A.5.36 — Compliance with Policies, Rules and Standards for Information Security Missing review evidence undermines proof of policy compliance.
Recommendation — Retain review evidence that proves access decisions and resulting changes. Preserve review artefacts that can be reused in audit and incident investigations. Show that access reviews were performed and closed in line with policy.

Practitioner Guidance

What to verify: Check whether every review leaves an auditable record that is tied to the exact entitlement set, not just a completed workflow status. If reviewers can approve access without leaving a reason, the control is not evidence-ready.

Common mistake: Treating a spreadsheet sign-off as sufficient proof when no durable record exists of what changed afterwards. That shortcut often passes operational review but fails when an auditor asks for reconstruction.

What good looks like: A reviewer can show the decision, the ticket or workflow record, the change record, and the closure timestamp without manual detective work. The review artefact should make it obvious why retained access stayed in place and why removed access was removed.

Practitioner takeaway: For ISO 27001, the real control is not the review meeting itself, it is the evidence chain that lets an independent party verify the decision and its effect.