Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations prove access is still appropriate…
Governance, Ownership & Risk

How should organisations prove access is still appropriate between audits?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

Organisations should prove appropriateness by capturing access approvals, review decisions and revocations at the moment they occur. That creates evidence as a byproduct of operating the control, not a separate scramble before the audit. It also lets GRC, security and IT work from the same live record instead of multiple spreadsheets.

What “proof” should look like between audits

Proof of appropriate access should come from the operating record, not from a retrospective cleanup. The most reliable evidence is time-stamped approval, review, and revocation events tied to the actual identity, system, role, and business reason, so the organisation can show who changed what, when, and why without rebuilding the story later.

That matters because auditors are usually testing whether access was governed continuously, not just whether a spreadsheet said it was. If the evidence lives in workflow history, ticketing, logs, and entitlement systems, teams can demonstrate that approvals were current, exceptions were bounded, and revoked access really disappeared from production use.

Well-run access evidence also needs context, not just yes or no decisions. The record should show the reviewer, the approver if different, the date of the decision, the entitlement scope, the expiry or review date, and the revocation action where access was no longer appropriate. That gives security, IT, and GRC one operational trail instead of three interpretations of the same event.

How to build evidence as a byproduct of control operation

The control works best when evidence is generated by normal governance steps. Access request workflows, periodic recertifications, privileged access reviews, and offboarding actions should all produce durable artifacts automatically, so the organisation is documenting access decisions at the point of execution rather than after the fact.

A practical pattern is to make every access decision produce a record that can survive audit scrutiny: request, justification, reviewer identity, approval or denial, implementation timestamp, and expiry or next-review date. For revocations, retain the trigger, the removal timestamp, and confirmation that the entitlement no longer grants access in the target system.

This is where access governance becomes much easier to defend if the workflow is disciplined. The regulatory and audit perspective on non-human identities is useful because the same evidence discipline applies whether the subject is a person, a service account, or another privileged actor: the control must leave a trace at the moment the access changes.

Why live records beat audit-period reconstruction

Audit-period reconstruction usually fails in the same places: approvals are missing, reviews happened in email, and revocations are only implied by a ticket closure. Live records reduce those gaps because they preserve the control path itself, which is what makes the evidence credible when a reviewer asks whether access remained appropriate over time.

That also helps when exceptions are legitimate. Temporary access, emergency elevation, and delayed revocation can all be defensible, but only if the record shows the exception owner, the expiry condition, and the compensating review. Without that, organisations end up proving intent rather than actual control operation.

For organisations that depend heavily on vendor attestations or service-provider reports, SOC 2 Trust Services Criteria is a useful external reference point because it reinforces the expectation that control evidence must be produced consistently, not reconstructed when a control owner remembers to prepare for an audit.

Risk and Threat Considerations

When access evidence is fragmented across spreadsheets, email threads, and manual screenshots, organisations lose the ability to prove that access was appropriate during the period between reviews. That creates governance blind spots, weakens revocation assurance, and increases the chance that excessive or stale access persists unnoticed.

Failure mechanism: the approval, review, and removal steps are not captured as operational system records, so the control cannot be independently reconstructed later and may hide lingering access or unapproved privilege changes.

Impact: auditors may challenge the effectiveness of the control, security teams may miss overexposed accounts, and the organisation may be unable to demonstrate that access was restricted or removed when the business context changed.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CSA Cloud Controls Matrix and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CSA Cloud Controls MatrixIAM — Identity & Access ManagementCovers governance over access approvals, reviews, and revocations as a cloud control domain.
Recommendation — Use IAM controls to record approvals, recertifications, and removals in the operating system of record.
NIST SP 800-53 Rev 5AC-2 — Account ManagementRequires managed account lifecycle evidence for provisioning, review, and removal of access.
AU-2 — Event LoggingSupports time-stamped evidence of access decisions and revocations as they occur.
Recommendation — Maintain account lifecycle records showing creation, review, and termination actions. Log access approval and revocation events so the control can be reconstructed later.
ISO/IEC 27001:2022A.5.15 — Access controlDirectly governs how access decisions are authorised, reviewed, and evidenced over time.
Recommendation — Document access approvals, periodic reviews, and revocations in the access-control process.
SOC 2 (AICPA)CC6.2 — Change ManagementAddresses approval and tracking of access-related changes in a service organisation.
Recommendation — Track access changes through an approved workflow with retained evidence.

Practitioner Guidance

What to verify: confirm that every access decision has a durable trail linking the business justification to the entitlement changed, the reviewer or approver, the timestamp, and the resulting state in the target system. If any one of those fields lives only in email or a spreadsheet, treat the evidence as incomplete.

What good looks like: access reviews produce a closed-loop record, requests create approvals or denials with owners and dates, revocations are verified in the target system, and the same record can satisfy GRC, security, and IT without manual reconciliation.

Common mistake: relying on periodic attestations alone. A signed review says someone looked at access; it does not prove the control operated continuously unless the approval, implementation, and removal events are also captured when they happened.

Practitioner takeaway: If you cannot prove the control from the live record, you do not really have audit-ready access governance, only audit preparation.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org