Join our Newsletter — 33% off our NHI Course
Home› FAQ› NHI Lifecycle Management› What should organisations record for audit evidence when…
NHI Lifecycle Management

What should organisations record for audit evidence when a user is deprovisioned?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 30, 2026 Domain: NHI Lifecycle Management

Record who was removed, when removal happened, which source triggered it, and exactly what access was revoked. A useful deprovisioning record also captures the user state at deletion, such as active or inactive, plus counts for sessions, tokens, and API keys revoked. That turns access removal into auditable evidence instead of a generic status change.

What should an audit record prove when a user is deprovisioned?

An audit record should prove that access removal was specific, timely, and complete. The useful evidence is not just that an account changed state, but that the organisation can show who was removed, what triggered the action, what access was withdrawn, and what residual access material, such as sessions or tokens, was also revoked.

What evidence belongs in the deprovisioning record?

The record should tie the event to a clear identity transition: who was removed, when it happened, and which upstream trigger initiated it. It should also show the exact scope of revocation, such as accounts, roles, entitlements, API keys, tokens, or other access-bearing material that was invalidated as part of the same action.

That level of detail matters because a generic “deactivated” status can hide partial failure. If the account was disabled but sessions remained live, or if some credentials were not rotated or revoked, the record no longer proves that access actually ended.

Why does the user state at deletion matter?

Capturing the user state at deletion, such as active, inactive, or already suspended, helps distinguish routine offboarding from cleanup of a dormant or abandoned account. It also gives reviewers context for whether the removal was expected, delayed, or corrective.

Counts for sessions, tokens, and API keys revoked add a practical control signal. They show whether the deprovisioning step reached the real access surface, not just the directory object. For organisations with shared tooling and automation, that is often the difference between a defensible audit trail and a record that only looks complete.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AU-3 — Content of Audit RecordsDeprovisioning evidence needs sufficient audit detail to reconstruct the access-removal event.
IA-5 — Authenticator ManagementUser deprovisioning must revoke or invalidate authenticators, tokens, and other access-bearing material.
Recommendation — Log the who, what, when, source, and revoked access objects for each deprovisioning event. Invalidate credential material when access is removed and retain proof of revocation.
ISO/IEC 27001:2022A.5.16 — Identity managementThe question concerns lifecycle evidence for removing a user's access and identity state.
Recommendation — Maintain identity records that show deprovisioning actions and their effective scope.
CIS Controls v8CIS-5 — Account ManagementAccount removal evidence is part of verifying that accounts and access are removed promptly and completely.
Recommendation — Document account removal and verify that all associated access is disabled or revoked.
SOC 2 (AICPA)CC6.3 — Logical Access Security Software, Infrastructure, and ArchitecturesDeprovisioning records support evidence that logical access is removed when no longer authorised.
Recommendation — Retain evidence that access was removed and residual access paths were terminated.

Practitioner Guidance

What to verify: Confirm that the record shows the initiating source, the identity removed, the timestamp, and the exact access objects revoked. If any of those fields are missing, the evidence is usually too weak to support an audit challenge or incident review.

What good looks like: A strong record lets a reviewer reconstruct the full removal path without guessing, including whether access removal was immediate, whether downstream sessions were terminated, and whether any credentials remained valid after the deprovisioning event.

Common mistake: Treating account disablement as equivalent to deprovisioning evidence. In practice, auditors and responders care about the full revocation outcome, not only the directory status change.

Practitioner takeaway: The most useful deprovisioning evidence proves closure of access, not just closure of the account. If you cannot show what was revoked and what remained live, you do not yet have complete audit evidence.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 30, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org