ISO 27001 expects the organisation to show that access control sits inside a managed system with ownership, documentation, and continuous governance. SOC 2 focuses more on whether the chosen controls operate as described, so the evidence burden is often lighter and more selective. That difference changes what auditors expect from IAM and PAM records.
Why ISO 27001 and SOC 2 Ask for Different IAM Evidence
iso 27001 and SOC 2 are both assurance standards, but they are not asking the same question of your IAM and PAM programme. ISO 27001 evidence usually has to prove the control is part of a managed security system, while SOC 2 evidence usually has to prove the control operated effectively over the review period. That difference drives the depth, structure, and continuity of the records auditors want to see.
What ISO 27001 Is Trying to Prove About Access Control
ISO 27001 is an ISMS standard, so IAM evidence is judged in context: the organisation must show ownership, risk treatment, control design, and ongoing governance. In practice, that means auditors expect more than a screenshot or one-off approval. They look for policy, scope, control ownership, review cadence, exceptions handling, and signs that access decisions are embedded in a managed process.
For IAM and PAM, the question is not only whether access was granted correctly, but whether the organisation can explain why the rule exists, who owns it, how it is reviewed, and how exceptions are governed. This is why ISO/IEC 27001:2022 Information Security Management tends to pull in broader evidence than a point-in-time control test.
How SOC 2 Evidence Usually Differs in Practice
SOC 2 is more control-operation focused. Auditors want to know whether the stated IAM control worked consistently during the reporting period and whether the evidence supports the control description in the system narrative. That often narrows the evidence set to samples, operating effectiveness, and records that show the control was actually performed, not just designed.
For access management, that often means selected joiner-mover-leaver events, privileged access reviews, MFA enforcement, and periodic recertification samples. The logic is more selective because SOC 2 is typically looking for operating evidence tied to the control objective, rather than the full governance story around how the control was designed and managed. For a vendor or service provider, the SOC 2 Trust Services Criteria (AICPA) frame the test around whether the control is suitably designed and operating as described.
Why IAM and PAM Teams Feel the Difference
The practical gap is that ISO 27001 rewards evidence of governance maturity, while SOC 2 rewards evidence of control consistency. Under ISO 27001, an auditor may expect to see access control linked to risk ownership, documented responsibilities, and the wider ISMS. Under SOC 2, the same team may be asked for fewer artefacts, but those artefacts must line up tightly with the defined control and the audit period.
This is why the same IAM process can fail one audit and pass another. If your process exists but is poorly documented, ISO 27001 scrutiny rises. If your process is documented but sample evidence is weak or inconsistent, SOC 2 scrutiny rises. For practitioners, the difference is less about the control itself than about the evidence narrative each standard is trying to validate.
Risk and Threat Considerations
IAM evidence gaps do not just create audit friction, they can hide real access governance weakness. When ownership, review cadence, or exception handling is unclear, excess privilege can persist longer than intended, and privileged access records become harder to trust during an incident or remediation cycle.
Failure mechanism: A control may exist on paper, but without durable evidence of approvals, recertification, and exception closure, the organisation cannot demonstrate that access was governed consistently over time.
Impact: That weakens assurance around least privilege, increases the chance of stale or overprivileged access, and makes it harder to prove control effectiveness after a security event.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
ISO/IEC 27001:2022 and SOC 2 (AICPA) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| ISO/IEC 27001:2022 | A.5.15 — Access control | IAM evidence is judged as part of the ISMS access-control system. |
| A.5.18 — Access rights | The question is about what evidence proves access rights are governed over time. | |
| A.8.2 — Privileged access rights | PAM records are central to the evidence difference described in the question. | |
| Recommendation — Document access-control ownership, reviews, and exception handling inside the ISMS. Retain approval, recertification, and revocation evidence for access rights. Keep privileged-access approvals and periodic review evidence. | ||
| SOC 2 (AICPA) | CC6.1 — Logical and Physical Access Controls | IAM evidence is evaluated through access-control design and operation in the SOC 2 context. |
| CC6.2 — Authentication and Authorization | The question directly concerns evidence for IAM and privileged access controls. | |
| CC6.3 — Access Restriction | SOC 2 testing often focuses on whether access restrictions were enforced in practice. | |
| Recommendation — Show that logical access controls operated consistently during the review period. Retain records proving authentication and authorization controls worked as described. Provide samples showing access restrictions were applied and maintained. | ||
Practitioner Guidance
What to prioritise: Build one evidence model for IAM and then map it to two audit expectations. Keep the underlying control lifecycle, but separate the evidence bundles for governance-heavy ISO 27001 reviews and operating-effectiveness-focused SOC 2 testing.
What to verify: For ISO 27001, verify that the evidence shows control ownership, review frequency, exception management, and linkage to the ISMS. For SOC 2, verify that the evidence shows the control actually ran during the period and that the sample set matches the control description.
Common mistake: Teams often overproduce one type of evidence and underproduce the other. A policy pack without operating records is weak for SOC 2, while a pile of ticket screenshots without governance context is weak for ISO 27001.
Practitioner takeaway: Treat ISO 27001 as a question about managed control governance and SOC 2 as a question about demonstrated control operation, then design IAM evidence so it can answer both without being the same evidence set.
Related resources from NHI Mgmt Group
- Why do ISO 27001 and SOC 2 create different burdens for IAM teams?
- How should security teams govern non-human identities for ISO 27001?
- How should IAM teams choose between SOC 2, HIPAA, ISO 27001 and FedRAMP?
- How do organisations decide between NIST CSF, ISO 27001, SOC 2, HIPAA, and GDPR requirements?