Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› What should auditors expect when access evidence lives…
Governance, Ownership & Risk

What should auditors expect when access evidence lives in spreadsheets?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 8, 2026 Domain: Governance, Ownership & Risk

They should expect slow evidence gathering, inconsistent approval trails, and difficulty proving who had access at a given time. Spreadsheet records may help with inventory, but they are weak for accountability unless they are backed by systems that preserve timestamps, ownership, and revocation history.

Why spreadsheets are weak evidence for access accountability

Spreadsheets are useful as a working inventory, but they are not a strong control record unless they are anchored to a system of record that preserves who approved access, when it changed, and when it was removed. A spreadsheet can list names and roles, yet still leave auditors unable to reconstruct the actual access state at a point in time.

That gap matters because access evidence is only persuasive when it supports a clear chain from request to approval to provisioning to revocation. When the record is manually maintained, small edits, duplicate tabs, and incomplete owner fields can make the evidence look orderly without making it trustworthy.

What auditors usually find in spreadsheet-based evidence

The common failure mode is not total absence of evidence, but evidence that is hard to verify. Auditors often encounter inconsistent column formats, merged cells, stale extracts, and comments or email references that never made it into the workbook. That creates extra follow-up work because the spreadsheet shows an answer, but not the underlying event history.

For that reason, spreadsheet evidence tends to support inventory questions better than control questions. It may help identify who was supposed to have access, but it is much weaker for proving that access was approved by the right owner, granted at the right time, and removed promptly after a change in role or employment status.

Where the spreadsheet is the only artifact, the auditor usually has to test the surrounding process more aggressively. That means asking for source exports, ticket records, approval logs, and revocation evidence, not just the final worksheet. CIS Controls v8 is useful here because account and access governance depend on current, verifiable records rather than manually curated lists.

What makes the evidence defensible instead of merely readable

The strongest access evidence is the kind that can be reconciled across systems. A reviewer should be able to trace a row in a spreadsheet back to an authority for the access decision, a timestamp for the change, and a revocation trail when access ended. If any of those pieces are missing, the spreadsheet becomes a summary document rather than evidence of control.

That is why controls focused on access review, auditability, and lifecycle management matter more than the file format itself. If the workbook is generated from a ticketing, IAM, or provisioning system, it can still be useful as a presentation layer, but the underlying record should carry the accountability burden. NIST SP 800-53 Rev 5 Security and Privacy Controls is the clearest fit for this evidence model because access control and audit controls are only effective when the record is attributable and time-bound.

Good evidence also makes exception handling explicit. If access was granted temporarily, inherited through a role, or approved outside the standard workflow, the record should show that exception clearly. Otherwise auditors are left guessing whether the unusual access was deliberate, temporary, or simply undocumented.

How to read spreadsheet evidence without over-trusting it

Auditors should treat the spreadsheet as a starting point and then test whether it is supported by durable records. The practical question is not whether the file exists, but whether it can answer three things with confidence: who had access, who approved it, and when it changed. If the spreadsheet cannot answer all three, the evidence set is incomplete.

When the file is the only source, the safest interpretation is that the organisation has inventory visibility, not full access governance maturity. That distinction helps auditors focus their requests on the missing control point instead of asking for more rows in the same workbook. A better evidence package links the spreadsheet to authoritative system exports, making the workbook a report of record rather than the record itself. ISO/IEC 27001:2022 Information Security Management supports that approach because access control evidence should be traceable to operational controls, not just manually assembled documentation.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-2 — Account ManagementAccess evidence must show account approval, provisioning, review, and revocation history.
AU-2 — Event LoggingAuditors need timestamps and history that spreadsheets usually do not preserve reliably.
Recommendation — Use AC-2 to tie spreadsheet entries back to account lifecycle records and approvals. Capture access changes in logs so the spreadsheet can be verified against time-stamped events.
ISO/IEC 27001:2022A.5.15 — Access controlThe issue is whether access records can prove who was authorised at a given time.
Recommendation — Maintain access control evidence in systems that preserve decision, time, and owner data.
CIS Controls v8CIS-6 — Access Control ManagementSpreadsheet-based access tracking often fails to support continuous access governance.
Recommendation — Centralise access management so evidence comes from controlled workflows, not manual worksheets.

Practitioner Guidance

What to prioritise: Ask first for the source of truth behind the spreadsheet. If the workbook cannot be reconciled to provisioning, approval, and revocation records, treat it as supportive documentation rather than evidence of control.

What to verify: Check whether each access entry has an owner, an approval timestamp, and a removal path. Missing timestamps or owner fields are usually the fastest indicator that the evidence will not withstand audit challenge.

Common mistake: Teams often assume a neat spreadsheet equals good governance. In practice, a neat spreadsheet can hide stale access, weak approvals, and no reliable way to prove what was true on a specific date.

Practitioner takeaway: The question is not whether the spreadsheet is complete, but whether it is auditable, reproducible, and backed by records that survive challenge.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org