Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Access Review Evidence & Audit File Checklist

Specifies the evidence pack to retain per campaign so an auditor can be satisfied without a reconstruction exercise months later.

Available soon

Format
Excel
Size
61 KB
Length
10 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Evidence Items
  • Campaign Checklist
  • Audit File Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Before the first campaign, read the Evidence Items sheet. Set where each item is kept (replace [[Campaign folder]] with your own location, one folder per campaign) and the retention period on the Audit File Summary sheet: [[e.g. 3 years after the campaign closes, or longer if your records retention schedule says so]]. Add your own items in the empty rows, with an EF-nn ID.
2For each campaign, save a copy of this workbook in the campaign's folder. On the Audit File Summary sheet, enter the campaign's ID and dates and its counts: systems, systems with privileged, generic or service accounts, Cannot decide decisions, Revoke and Modify decisions, process weaknesses and conflicts kept. Column G of the Campaign Checklist then shows how many of each item are expected.
3Collect each item as the campaign produces it, not at the end: the scope list, extracts and assignments at the extract date; decisions and Cannot decide resolutions by the decision deadline; removal tickets and the confirmation extract when the removal windows end; findings, the quality check, exceptions and the outcome report before close.
4For each item, enter how many were received (column H), the date (column I) and where it is kept (column J): a folder path or a record reference someone else can find.
5Check each item against What it must show on the Evidence Items sheet. Set the Result (column K): Pass when it shows everything listed; Fail with the issue in column L; N/A with the reason in column L (for example, no conflicts kept). Enter who checked it and when (columns M and N).
6Clear every Status (column O) that is not Complete or Not applicable. The Audit File Summary sheet's completeness check lists what is outstanding; a Pending item (some received, not all) stays open until the last one arrives.
7Sign off the audit file on the Audit File Summary sheet when the completeness check says Complete. If the campaign closes with items pending, sign off with the pending items named and a date for each; they are finished in the Access Review Findings & Revocation Tracker.
8Keep the file for the retention period, then delete the items that list people and their access (the extracts and decisions). Do not type over the white calculated columns.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

The EXAMPLE is campaign UAR-2026-Q3 at the example organisation, a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders: extract 2026-09-01, decision deadline 2026-09-15, closed 2026-09-29. Every item is complete. All 69 removals were confirmed before close, the 4 late ones included (EF-08). EF-12 is N/A: the one conflict was separated by a Modify, so no exception was needed. The file is kept under Access reviews/UAR-2026-Q3.

To clear the example: on the Campaign Checklist delete the contents of column A and columns H to N (not the rows); on the Audit File Summary replace every yellow cell.

Tailoring — small organisation: one folder per campaign with a numbered subfolder per phase is enough, and one person may collect everything. Keep the extracts and decision records above all: without them the review cannot be shown to have happened. Screenshots are acceptable evidence if they are dated and show the whole list.

Tailoring — regulated entity: NIS2 Art 21(2)(i) expects access control policies; DORA Art 9(4)(c) and Delegated Regulation (EU) 2024/1774 Art 21(e) expect access rights to be reviewed (at least every six months for systems supporting critical or important functions, yearly for others) and removed without undue delay, and Art 21(c) expects users to be identifiable: EF-02, EF-04, EF-07 and EF-08 show it. PCI DSS 7.2.4 expects user accounts, including third-party accounts, reviewed at least every six months with the review documented; 7.2.5.1 covers application and system accounts; 8.2.6 expects inactive accounts removed or disabled within 90 days: keep EF-06 and the dormant accounts in EF-09 for the cardholder data environment's systems.

Tailoring — IT run by a service provider: the provider often produces the extracts (EF-02), carries out the removals (EF-07) and runs the confirmation extract (EF-08). Ask for each as a dated file, not a statement that it was done, and check the counts yourself. The decisions (EF-04) and the sign-off (EF-13) stay with you.

Evidence Items

13 items in 4 phases: the evidence file every campaign keeps (AR-10). The Campaign Checklist reads columns B, C, F and G. Add your own items in the empty rows.

EF IDPhaseEvidenceWhat it must show (pass criterion)Why an auditor asksRuleHow many per campaignProvided byWhere keptRetention
EF-01Scope and extractsScope and system list as at the extract dateEvery in-scope system with its owner, review scope and frequency, saved as it stood on the extract date: a dated copy of the Access Review Scope & System Inventory.The auditor starts here: which systems should have been reviewed, and was any left out? Without the list as it stood, nobody can show the campaign covered everything.AR-01, AR-02One per campaignCampaign coordinator[[Campaign folder]]/01 ScopeThe audit file's retention period (Audit File Summary)
EF-02Scope and extractsEach extract, with its completeness proofThe file as received, named with the system, the extract date and who ran it; the entry count reconciled with the count the system itself shows; names, roles, permissions and last sign-in present.A review is only as good as its list. Auditors test that the list was complete and unchanged; the count reconciliation is the proof.AR-03One per systemSystem administrator[[Campaign folder]]/02 ExtractsThe audit file's retention period (Audit File Summary); it lists people and their access, so delete it when the period ends
EF-03Scope and extractsReviewer assignmentsWho reviewed each system or group of people, and the check that nobody reviewed their own access or the access of anyone who reviews theirs.Auditors look for self-review, and for reviewers who could not know the people they approved.AR-04One per campaignCampaign coordinator[[Campaign folder]]/03 AssignmentsThe audit file's retention period (Audit File Summary)
EF-04DecisionsDecisions, with who decided and whenEvery entry with one of the four decisions (Keep, Modify, Revoke, Cannot decide), the reviewer's name and the date. Entries decided add up to entries in the extract; none is blank or kept by default.The decision record is the review. Auditors sample entries and trace each to a named decision; blanks counted as Keep are the most common finding.AR-05One per systemLine managers and system owners[[Campaign folder]]/04 DecisionsThe audit file's retention period (Audit File Summary); it lists people and their access, so delete it when the period ends
EF-05DecisionsCannot decide resolutionsEach Cannot decide passed to the system owner, with the owner's decision and date, within 2 working days.Shows that access nobody recognised was resolved, not waved through.AR-05One per Cannot decide decisionSystem owner[[Campaign folder]]/04 DecisionsThe audit file's retention period (Audit File Summary)
EF-06DecisionsSecond review of privileged, generic and service accountsEach such account with its named owner, reviewed by the system owner and by information security, with both names and dates.Privileged and shared accounts are where auditors look hardest: the access that can do most harm, and the accounts nobody is accountable for.AR-06One per system with privileged, generic or service accountsSystem owner and information security[[Campaign folder]]/04 DecisionsThe audit file's retention period (Audit File Summary)
EF-07RemovalsRemoval ticketsA ticket, or a line on one, for each Revoke or Modify decision: date raised, date done, and its removal window (1 working day for privileged access, 5 for standard, from the decision date).Links each decision to the change that carried it out. An auditor traces a sample of Revoke decisions to their tickets and checks the dates.AR-07One per Revoke or Modify decisionSystem administrator[[Campaign folder]]/05 RemovalsThe audit file's retention period (Audit File Summary)
EF-08RemovalsConfirmation extract after removalsA fresh extract taken after the removals, showing each removed or reduced access is gone. Every removal is confirmed, late ones included; each late one is listed with its reason.A closed ticket is not proof the access has gone. The fresh extract is.AR-07One per Revoke or Modify decisionSystem administrator[[Campaign folder]]/05 RemovalsThe audit file's retention period (Audit File Summary); it lists people and their access, so delete it when the period ends
EF-09Findings and closeFindings raised: leavers, dormant and orphan accounts, conflictsEvery leaver, dormant or orphan account and segregation-of-duties conflict found, raised as a finding in the Access Review Findings & Revocation Tracker, not only removed.Shows the review fed back into the joiner, mover and leaver process instead of quietly cleaning up after it.AR-08One per campaignCampaign coordinator[[Campaign folder]]/06 FindingsThe audit file's retention period (Audit File Summary)
EF-10Findings and closeProcess weaknesses sent to their ownersEach weakness with the process owner it went to, the agreed fix and its due date.Auditors ask what changed after the last review. A weakness with an owner and a date is the answer.AR-11One per process weaknessCampaign coordinator[[Campaign folder]]/06 FindingsThe audit file's retention period (Audit File Summary)
EF-11Findings and closeQuality check recordThe rubber-stamp checks run before the campaign closed (4 signs, from the Access Review Methodology), what they found and what was done.Shows that decisions were actually made, not approved in bulk.AR-09One per campaignInformation security[[Campaign folder]]/07 CloseThe audit file's retention period (Audit File Summary)
EF-12Findings and closeExceptions for segregation-of-duties conflicts keptFor each conflict kept, its entry in the P02 Segregation of Duties Conflict Matrix and the approved exception, with its compensating control and expiry date, in the P02 Security Exception Register.A conflict kept without an approved exception is a finding in itself.AR-08One per conflict keptSystem owner[[Campaign folder]]/07 CloseThe audit file's retention period (Audit File Summary)
EF-13Findings and closeOutcome report and sign-offThe Access Review Outcome Report Template: risk removed, the four headline measures and the weaknesses found, signed off by the head of information security and the system owners.The single document an auditor reads first: what the campaign found and who accepted the result.AR-12One per campaignHead of Information Security[[Campaign folder]]/07 CloseThe audit file's retention period (Audit File Summary)

Campaign Checklist

One campaign's audit file. Expected (column G) follows the counts on the Audit File Summary. Yellow cells are yours. EXAMPLE rows: campaign UAR-2026-Q3.

RowEF IDPhaseEvidenceRuleHow many per campaignExpectedReceivedDate receivedWhere keptResultIssue, reason for N/A, or what is outstandingChecked byChecked onStatusOpen no. (calc)
EXAMPLEEF-01Scope and extractsScope and system list as at the extract dateAR-01, AR-02One per campaign111 Sep 2026Access reviews/UAR-2026-Q3/01 ScopePassCampaign coordinator29 Sep 2026Complete
EXAMPLEEF-02Scope and extractsEach extract, with its completeness proofAR-03One per system551 Sep 2026Access reviews/UAR-2026-Q3/02 ExtractsPass5 extracts, 495 entries, each reconciled to the system's own count.Campaign coordinator29 Sep 2026Complete
EXAMPLEEF-03Scope and extractsReviewer assignmentsAR-04One per campaign111 Sep 2026Access reviews/UAR-2026-Q3/03 AssignmentsPassCampaign coordinator29 Sep 2026Complete
EXAMPLEEF-04DecisionsDecisions, with who decided and whenAR-05One per system5515 Sep 2026Access reviews/UAR-2026-Q3/04 DecisionsPass495 entries decided: 424 Keep, 22 Modify, 47 Revoke, 2 Cannot decide.Campaign coordinator29 Sep 2026Complete
EXAMPLEEF-05DecisionsCannot decide resolutionsAR-05One per Cannot decide decision2217 Sep 2026Access reviews/UAR-2026-Q3/04 DecisionsPassBoth on SYS-01, resolved by the system owner.Campaign coordinator29 Sep 2026Complete
EXAMPLEEF-06DecisionsSecond review of privileged, generic and service accountsAR-06One per system with privileged, generic or service accounts4415 Sep 2026Access reviews/UAR-2026-Q3/04 DecisionsPassCampaign coordinator29 Sep 2026Complete
EXAMPLEEF-07RemovalsRemoval ticketsAR-07One per Revoke or Modify decision696915 Sep 2026Access reviews/UAR-2026-Q3/05 RemovalsPassCampaign coordinator29 Sep 2026Complete
EXAMPLEEF-08RemovalsConfirmation extract after removalsAR-07One per Revoke or Modify decision696924 Sep 2026Access reviews/UAR-2026-Q3/05 RemovalsPassAll 69 confirmed before close. Fresh extract 2026-09-23: 68 confirmed, including 3 late on SYS-01. 1 late on SYS-05 still present (nested group): removed again, confirmed 2026-09-24.Campaign coordinator29 Sep 2026Complete
EXAMPLEEF-09Findings and closeFindings raised: leavers, dormant and orphan accounts, conflictsAR-08One per campaign1129 Sep 2026Access reviews/UAR-2026-Q3/06 FindingsPass36 leaver, dormant and orphan accounts and 1 conflict (SYS-01).Campaign coordinator29 Sep 2026Complete
EXAMPLEEF-10Findings and closeProcess weaknesses sent to their ownersAR-11One per process weakness2229 Sep 2026Access reviews/UAR-2026-Q3/06 FindingsPassPW-01 to the HR Director, due 2026-11-30; PW-02 to the Chief Financial Officer, due 2026-12-15.Campaign coordinator29 Sep 2026Complete
EXAMPLEEF-11Findings and closeQuality check recordAR-09One per campaign1129 Sep 2026Access reviews/UAR-2026-Q3/07 ClosePassCampaign coordinator29 Sep 2026Complete
EXAMPLEEF-12Findings and closeExceptions for segregation-of-duties conflicts keptAR-08One per conflict kept00Access reviews/UAR-2026-Q3/07 CloseN/ANo conflict kept: the SYS-01 conflict (P02 SOD-FI-01) was separated by a Modify, confirmed 2026-09-23; no exception needed.Campaign coordinator29 Sep 2026Not applicable
EXAMPLEEF-13Findings and closeOutcome report and sign-offAR-12One per campaign1129 Sep 2026Access reviews/UAR-2026-Q3/07 ClosePassCampaign coordinator29 Sep 2026Complete

Audit File Summary

Audit file summary and sign-off

The campaign's details and counts set what the checklist expects. Completeness and the outstanding items are calculated; the sign-off is yours.

Campaign

FieldValueNote
Campaign IDUAR-2026-Q3EXAMPLE — replace with your campaign's ID.
Extract date1 Sep 2026EXAMPLE. The date every extract was taken (AR-03).
Decision deadline15 Sep 2026EXAMPLE. Removal windows count from this date.
Close date29 Sep 2026EXAMPLE. The date the campaign was closed.
Audit file locationAccess reviews/UAR-2026-Q3EXAMPLE. The campaign's folder: replaces [[Campaign folder]] on the Evidence Items sheet.
Retention period[[e.g. 3 years after the campaign closes, or longer if your records retention schedule says so]]Set it once, with your records retention schedule. The same for every campaign.
Keep until[[YYYY-MM-DD]]The close date plus the retention period.

Campaign counts (they set Expected on the checklist)

How many per campaignCountWhere the count comes from
One per campaign1Fixed.
One per system5EXAMPLE: 5. Systems in the campaign.
One per system with privileged, generic or service accounts4EXAMPLE: 4. From the Access Review Scope & System Inventory.
One per Cannot decide decision2EXAMPLE: 2. Cannot decide decisions in the campaign.
One per Revoke or Modify decision69EXAMPLE: 69. Revoke plus Modify decisions: the removals.
One per process weakness2EXAMPLE: 2. Findings sent to a process owner (AR-11).
One per conflict kept0EXAMPLE: 0. Segregation-of-duties conflicts kept under a P02 exception. The example's one conflict (SYS-01, P02 SOD-FI-01) was separated by a Modify, so none was kept.

Completeness

MeasureItemsCompleteness check
Items listed13Complete: every item is received, checked and kept.
Complete12
Not applicable1
Pending (some received)0
Not yet received0
Outstanding0

Outstanding items

EvidenceEF IDStatusWhat is outstanding

The first 8 outstanding items, in checklist order. A late removal is finished in the Access Review Findings & Revocation Tracker.

Sign-off

FieldValueNote
Campaign coordinator[[Name, role]]Confirms the file holds every item, or names what is pending.
Coordinator's signature date[[YYYY-MM-DD]]
Head of Information Security[[Name, role]]Accepts the audit file with the Access Review Outcome Report Template (AR-12).
Signature date[[YYYY-MM-DD]]
Items pending at sign-off, with dates[[None, or each pending item with its date]]Write None when the completeness check says Complete.

Each campaign must keep an evidence file: scope, extracts, decisions, changes, confirmation and sign-off. (AR-10)

Lists

PhaseUnitResult
Scope and extractsOne per campaignPass
DecisionsOne per systemFail
RemovalsOne per system with privileged, generic or service accountsN/A
Findings and closeOne per Cannot decide decision

One per Revoke or Modify decision

One per process weakness

One per conflict kept

Definitions

Definitions

TermMeaning in this workbook
Audit fileEverything kept from one access review campaign so that someone who was not there can see what was reviewed, what was decided and what changed (AR-10).
Evidence item (EF-nn)One kind of evidence the audit file holds, defined on the Evidence Items sheet.
CampaignOne round of access review across the systems due, from extract to sign-off, with an ID such as UAR-2026-Q3.
ExtractThe list of every account on a system with its permissions, taken on a stated date (AR-03).
Count reconciliationChecking that the number of entries in an extract equals the number the system itself reports. It is the proof that the extract is complete.
Confirmation extractA fresh extract taken after removals, used to confirm each removed or reduced access has gone (AR-07).
Removal windowHow long a Revoke or Modify may take: see the Access Review Methodology. Counted in working days from the decision date.
Cannot decideA reviewer's answer when they do not know the person or the permission. It goes to the system owner, never to Keep by default (AR-05).
Quality checkThe check for rubber-stamp reviews before a campaign closes (AR-09), described in the Access Review Methodology.
ExceptionAn approved, time-limited decision to keep something that breaks a rule, such as a segregation-of-duties conflict, recorded in the P02 Security Exception Register.
ExpectedHow many of an item the campaign needs, from its unit and the counts on the Audit File Summary.
StatusColumn O of the checklist: what the item still needs. Complete and Not applicable need nothing more; Pending means some, not all, have been received.
Retention periodHow long the audit file is kept before it is deleted. Set by your records retention schedule.
Working dayMonday to Friday, excluding public holidays.
EXAMPLECampaign UAR-2026-Q3 on the Campaign Checklist and the Audit File Summary. Delete before approval.
AR-nn, PW-nnRule numbers in the Access Review Methodology; process weakness numbers from the example campaign's outcome.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Clause 7.5 — Documented informationThe whole checklist: the documented information a campaign keeps, where it is kept and for how long
ISO/IEC 27001:2022Annex A 5.18 — Access rightsEF-01 to EF-08: access rights reviewed, and changes made and confirmed
NIST CSF 2.0PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties”EF-04 to EF-08 and EF-12: access permissions reviewed, least privilege and separation of duties enforced
PCI DSS v4.0.1Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six monthsEF-02, EF-04 and EF-06: user and third-party accounts reviewed, with the review documented
DORA — Delegated Regulation (EU) 2024/1774Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for othersEF-01, EF-04 and EF-07: review at the required interval, and access removed without undue delay

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1