They should include the access paths most likely to carry hidden exposure, including privileged users, delegated vendor access, service-linked accounts, and the logs or certifications that show how access was approved and removed. That gives the audit a real picture of the identity surface instead of a simplified administrative view.
What belongs in an IAM audit of identity risk?
An effective IAM audit should not stop at the neat inventory of assigned accounts. It should test where identity exposure actually concentrates, which includes privileged access, vendor pathways, service-linked accounts, stale entitlements, and the evidence trail that proves access was approved, reviewed, and removed. The audit should answer who can act, through which path, and with what proof of control.
Audit scope should also include the identity relationships that are easiest to overlook in day-to-day administration. That means inherited access, delegated administration, shared credentials, emergency access, and accounts that are technically “inactive” but still capable of reactivation or reuse. The point is to expose hidden reach, not just document the current directory state.
Where the audit needs to be defensible, it should connect access to lifecycle evidence. Teams should be able to show join, move, leave events, request and approval records, recertification results, deprovisioning timestamps, and any exception handling that allowed access to persist. If those records do not line up, the audit is really uncovering process drift rather than a clean control story.
Which identity paths deserve the most scrutiny?
The highest-value audit targets are the paths that can create disproportionate blast radius. Privileged users matter because they can change policy, entitlements, and other controls. Ultimate Guide to NHIs, Regulatory and Audit Perspectives is useful here because it frames auditability as a control question, not just a reporting exercise.
Delegated vendor access also deserves special treatment because the risk is often indirect: a third party may hold access that is legitimate on paper but broad in practice, time-limited in theory but persistent in reality. Third-Party, B2B and Contractor Access Guide supports that analysis by focusing on sponsorship, time limits, reviews, and offboarding discipline for external access paths.
Service-linked accounts and workload-style access should be audited with the same seriousness as human accounts when they can reach sensitive systems. Static credentials, reused secrets, and opaque ownership all make these paths harder to review and easier to leave behind. Cloud Workload Identity Guide is especially relevant where teams need to distinguish modern keyless patterns from long-lived credentials that are still hiding in production.
How should auditors judge whether the identity surface is complete?
A complete audit is less about counting accounts and more about verifying that each access path has an owner, a purpose, an approval basis, and a removal path. If any of those four elements is missing, the identity surface is incomplete even if the directory export looks tidy. That is why lifecycle and governance evidence matter as much as current permissions.
Teams should also compare what the access review says against what systems actually allow. Excessive permissions, dormant accounts, cross-environment reach, and exceptions that never expire are all signs that the operating model has drifted away from the documented model. Identity Security Posture Management (ISPM) Guide is a strong companion for this kind of audit because it emphasises posture checks, prioritisation, and attack-path thinking.
Where identity risk is spread across humans, vendors, and machine-style access, the audit should compare the different control expectations instead of collapsing them into one generic account review. The audit result is stronger when it can distinguish routine access from elevated access, and persistent access from temporary exception access.
Risk and Threat Considerations
Identity audits fail when they only see the formal account catalogue and miss the paths that attackers or careless insiders can actually use. The main risk is false assurance: a clean report can coexist with privileged sprawl, vendor persistence, dormant accounts, or service credentials that still authenticate in production.
Failure mechanism: Hidden or under-reviewed access paths are excluded from the audit scope, so approval, review, and removal controls are never tested against the identities most likely to create real exposure.
Impact: Organisations retain standing privilege, miss orphaned access, and understate the blast radius of a compromise or policy error, which weakens both detection and remediation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-2 — Audit Events | Identity-risk audits depend on complete, reviewable evidence of access approvals and removals. |
| AC-2 — Account Management | The question is about which accounts and access paths must be included in identity-risk audits. | |
| AC-6 — Least Privilege | Audit scope should surface excessive permissions and hidden blast radius. | |
| Recommendation — Define and retain audit events for access grants, changes, and revocations. Review account lifecycle coverage for privileged, vendor, and service-linked access. Verify that access is constrained to the minimum necessary privilege. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | Auditing identity risk requires evidence that access rights are granted, reviewed, and removed properly. |
| Recommendation — Audit access-right assignment, review, and withdrawal on a recurring basis. | ||
| CIS Controls v8 | CIS-5 — Account Management | Account inventory, review, and removal are central to the audit scope described. |
| Recommendation — Inventory, review, and remove accounts and privileges that are no longer justified. | ||
Practitioner Guidance
What to prioritise: Start with privileged access, external access, and service-linked access, then verify whether each path has a current owner, a valid business purpose, and a documented removal trigger. If an access path cannot be tied back to those three elements quickly, treat it as an audit finding rather than a documentation gap.
What to verify: Check that the evidence set includes approvals, recertifications, offboarding records, and exception expiries, not just current role assignments. If access exists but the organisation cannot prove when and why it was granted, the control is not audit-ready.
Practitioner takeaway: The best identity-risk audits expose where access still works, not just where accounts are listed, because hidden reach is what turns governance failure into operational exposure.