Because auditors assess the written control as well as the operating control. If the policy does not define cadence, reviewer roles, scope, and remediation expectations, the organisation cannot demonstrate consistent governance even if people are performing reviews informally. The gap between documented intent and executable process is enough to trigger a finding.
Why auditors can flag the policy even when reviews occur
access review findings often come from a gap in control design, not just a missed operational step. If the policy does not state who reviews, how often, what scope is covered, and what happens after exceptions are found, the written control is not testable. Auditors need evidence that the review process is defined, repeatable, and enforced, not merely performed ad hoc.
That distinction matters because a control can exist in practice and still fail governance review if it cannot be demonstrated from the policy and supporting records. A review performed by the right people at the right time is weaker evidence when the policy does not make those expectations explicit. In audit terms, the organisation is operating a habit, not a controlled process.
A useful way to think about it is that the policy is the specification for the control. The operating evidence shows behaviour, but the policy shows intent, ownership, and accountability. When those two layers do not line up, the finding is usually about inadequate governance maturity rather than a total absence of activity.
What an access review policy must define to be auditable
An auditable policy should make the review cycle explicit enough that another person can execute it consistently. That usually means stating cadence, reviewer authority, in-scope systems or entitlements, criteria for risk-based expansion, and the remediation path for revoked or disputed access. Without those elements, reviewers may act differently from one cycle to the next, which makes the control hard to evidence and even harder to defend.
This is especially important when access reviews are part of broader identity governance. The policy should distinguish between routine recertification and exception handling, and it should define how unresolved items are escalated. If reviewers can approve, defer, or ignore findings without a documented rule, the process becomes discretionary and the control loses consistency.
Audit teams also look for traceability. The policy should support clear linkage between the review event, the reviewer, the access scope, the decision made, and the follow-up action. When those links are missing, the organisation may still be doing the work, but it cannot prove that the work was governed as a control rather than handled informally.
Why informal reviews do not usually satisfy control testing
Informal reviews often fail because they depend on local knowledge, memory, or team habits. That can be sufficient for day-to-day operations, but it is not enough for a control that must survive turnover, scale, or independent testing. Access review assurance depends on repeatability, and repeatability depends on a policy that removes ambiguity.
For practitioners, the practical failure mode is not that reviews never happen, it is that the organisation cannot show they happened under a consistent rule set. If one team reviews monthly, another quarterly, and a third only after an incident, the control is fragmented even if each team believes it is compliant. That fragmentation is exactly what auditors surface as a finding.
Current good practice is to align the policy to the actual review workflow, then keep the workflow and evidence in sync. Where the workflow has matured faster than the policy, update the policy rather than assuming the operating process will speak for itself. If you need a practical model for that alignment, Access Reviews and Certification Guide and IAM and IGA Basics both map the control to the governance elements auditors expect.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Access review policies govern account and entitlement lifecycle decisions. |
| AC-6 — Least Privilege | Reviews are intended to detect excessive or unnecessary access. | |
| AU-6 — Audit Review, Analysis, and Reporting | The question concerns what evidence auditors need to see for operating controls. | |
| Recommendation — Define review cadence, ownership, and revocation handling for account and entitlement reviews. Use periodic access reviews to remove privileges that exceed current job need. Retain review logs and decisions that demonstrate the control operated as designed. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Access review policies are part of access control governance and enforcement. |
| A.5.18 — Access rights | Recertification and removal of access rights are central to the issue. | |
| Recommendation — Document access review rules and enforce them consistently across in-scope systems. Periodically recertify access rights and remove those no longer justified. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | The control is about managing access reviews and removal of excess access. |
| CIS-8 — Audit Log Management | Auditors need evidence that reviews occurred and exceptions were handled. | |
| Recommendation — Standardise access review cadence, approval, and revocation workflows. Keep review evidence and exception records that support audit testing. | ||
Practitioner Guidance
What to verify: Check whether the policy can drive the same review outcome if a different manager, analyst, or auditor applies it next quarter. If the answer depends on tribal knowledge, the policy is too vague even if the team is completing reviews.
Decision rule: If the policy does not define cadence, reviewer role, scope, and remediation, treat the control as governable only in part and fix the document before relying on the operating evidence alone.
What good looks like: The policy and the workflow produce the same review decisions, the same escalation path, and the same evidence set every cycle. That is what turns access review activity into an auditable control instead of a recurring task.
Practitioner takeaway: Auditors are not asking whether reviews happened once, they are asking whether the organisation can prove a repeatable control model that will keep happening the same way.