SOC 2 access-review evidence, explained
What auditors actually want from a quarterly access review — and how to prove it without a spreadsheet scramble.
Reviewed by AuditFetch Editorial Team · Published · Updated
An access review is not just a user export. The useful evidence shows what population was reviewed, who reviewed it, what they decided, and what changed afterward. Without those pieces, an auditor can see a list but cannot reconstruct the control's operation.
Build an evidence set, not a screenshot
For each in-scope system, retain:
- the complete active-user population and the time it was captured;
- privileged roles, groups, service accounts, and people who can grant access;
- the reviewer, review period, decision, and any exception rationale;
- removal or remediation records linked back to the reviewed identity; and
- the policy or procedure that defines cadence, ownership, and approval criteria.
Preserve the source account or organization and capture time with every artifact. A CSV renamed “Q3 access review” is weak evidence if nobody can show when or where it came from.
Reconcile the population before reviewing it
Compare the system export with the authoritative identity or HR population. Investigate accounts that exist in only one source, shared identities, dormant users, and privileged access that does not match a current job need. Do not silently exclude bots or service accounts: classify them, record an owner, and document why their access remains necessary.
The HHS HIPAA Audit Protocol illustrates the evidence pattern clearly: reviewers may be asked for user-access listings, privileged-user lists, periodic-review documentation, and termination records. Your exact scope and cadence still come from your policies, risk analysis, framework criteria, and auditor—not from this guide.
Record the decision trail
A useful review record distinguishes approved access, removed access, and a documented exception. For every removal, retain the ticket or provider event that proves completion. Sampling a few rows does not prove that the full population was reviewed; keep the reviewed input and the decision set together.
Know the limitation
Fresh source data can show current access, but it does not prove that access is appropriate. A named reviewer must evaluate business need and resolve exceptions. AuditFetch captures user and administrator lists, preserves provenance, maps evidence to requirements, and tracks review state; it does not replace that judgment or guarantee auditor acceptance.