Access Review Evidence & Audit File Checklist
Specifies the evidence pack to retain per campaign so an auditor can be satisfied without a reconstruction exercise months later.
Available soon
- Format
- Excel
- Size
- 61 KB
- Length
- 10 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Evidence Items
- Campaign Checklist
- Audit File Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Before the first campaign, read the Evidence Items sheet. Set where each item is kept (replace [[Campaign folder]] with your own location, one folder per campaign) and the retention period on the Audit File Summary sheet: [[e.g. 3 years after the campaign closes, or longer if your records retention schedule says so]]. Add your own items in the empty rows, with an EF-nn ID. |
| 2 | For each campaign, save a copy of this workbook in the campaign's folder. On the Audit File Summary sheet, enter the campaign's ID and dates and its counts: systems, systems with privileged, generic or service accounts, Cannot decide decisions, Revoke and Modify decisions, process weaknesses and conflicts kept. Column G of the Campaign Checklist then shows how many of each item are expected. |
| 3 | Collect each item as the campaign produces it, not at the end: the scope list, extracts and assignments at the extract date; decisions and Cannot decide resolutions by the decision deadline; removal tickets and the confirmation extract when the removal windows end; findings, the quality check, exceptions and the outcome report before close. |
| 4 | For each item, enter how many were received (column H), the date (column I) and where it is kept (column J): a folder path or a record reference someone else can find. |
| 5 | Check each item against What it must show on the Evidence Items sheet. Set the Result (column K): Pass when it shows everything listed; Fail with the issue in column L; N/A with the reason in column L (for example, no conflicts kept). Enter who checked it and when (columns M and N). |
| 6 | Clear every Status (column O) that is not Complete or Not applicable. The Audit File Summary sheet's completeness check lists what is outstanding; a Pending item (some received, not all) stays open until the last one arrives. |
| 7 | Sign off the audit file on the Audit File Summary sheet when the completeness check says Complete. If the campaign closes with items pending, sign off with the pending items named and a date for each; they are finished in the Access Review Findings & Revocation Tracker. |
| 8 | Keep the file for the retention period, then delete the items that list people and their access (the extracts and decisions). Do not type over the white calculated columns. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
The EXAMPLE is campaign UAR-2026-Q3 at the example organisation, a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders: extract 2026-09-01, decision deadline 2026-09-15, closed 2026-09-29. Every item is complete. All 69 removals were confirmed before close, the 4 late ones included (EF-08). EF-12 is N/A: the one conflict was separated by a Modify, so no exception was needed. The file is kept under Access reviews/UAR-2026-Q3.
To clear the example: on the Campaign Checklist delete the contents of column A and columns H to N (not the rows); on the Audit File Summary replace every yellow cell.
Tailoring — small organisation: one folder per campaign with a numbered subfolder per phase is enough, and one person may collect everything. Keep the extracts and decision records above all: without them the review cannot be shown to have happened. Screenshots are acceptable evidence if they are dated and show the whole list.
Tailoring — regulated entity: NIS2 Art 21(2)(i) expects access control policies; DORA Art 9(4)(c) and Delegated Regulation (EU) 2024/1774 Art 21(e) expect access rights to be reviewed (at least every six months for systems supporting critical or important functions, yearly for others) and removed without undue delay, and Art 21(c) expects users to be identifiable: EF-02, EF-04, EF-07 and EF-08 show it. PCI DSS 7.2.4 expects user accounts, including third-party accounts, reviewed at least every six months with the review documented; 7.2.5.1 covers application and system accounts; 8.2.6 expects inactive accounts removed or disabled within 90 days: keep EF-06 and the dormant accounts in EF-09 for the cardholder data environment's systems.
Tailoring — IT run by a service provider: the provider often produces the extracts (EF-02), carries out the removals (EF-07) and runs the confirmation extract (EF-08). Ask for each as a dated file, not a statement that it was done, and check the counts yourself. The decisions (EF-04) and the sign-off (EF-13) stay with you.
Evidence Items
13 items in 4 phases: the evidence file every campaign keeps (AR-10). The Campaign Checklist reads columns B, C, F and G. Add your own items in the empty rows.
| EF ID | Phase | Evidence | What it must show (pass criterion) | Why an auditor asks | Rule | How many per campaign | Provided by | Where kept | Retention |
|---|---|---|---|---|---|---|---|---|---|
| EF-01 | Scope and extracts | Scope and system list as at the extract date | Every in-scope system with its owner, review scope and frequency, saved as it stood on the extract date: a dated copy of the Access Review Scope & System Inventory. | The auditor starts here: which systems should have been reviewed, and was any left out? Without the list as it stood, nobody can show the campaign covered everything. | AR-01, AR-02 | One per campaign | Campaign coordinator | [[Campaign folder]]/01 Scope | The audit file's retention period (Audit File Summary) |
| EF-02 | Scope and extracts | Each extract, with its completeness proof | The file as received, named with the system, the extract date and who ran it; the entry count reconciled with the count the system itself shows; names, roles, permissions and last sign-in present. | A review is only as good as its list. Auditors test that the list was complete and unchanged; the count reconciliation is the proof. | AR-03 | One per system | System administrator | [[Campaign folder]]/02 Extracts | The audit file's retention period (Audit File Summary); it lists people and their access, so delete it when the period ends |
| EF-03 | Scope and extracts | Reviewer assignments | Who reviewed each system or group of people, and the check that nobody reviewed their own access or the access of anyone who reviews theirs. | Auditors look for self-review, and for reviewers who could not know the people they approved. | AR-04 | One per campaign | Campaign coordinator | [[Campaign folder]]/03 Assignments | The audit file's retention period (Audit File Summary) |
| EF-04 | Decisions | Decisions, with who decided and when | Every entry with one of the four decisions (Keep, Modify, Revoke, Cannot decide), the reviewer's name and the date. Entries decided add up to entries in the extract; none is blank or kept by default. | The decision record is the review. Auditors sample entries and trace each to a named decision; blanks counted as Keep are the most common finding. | AR-05 | One per system | Line managers and system owners | [[Campaign folder]]/04 Decisions | The audit file's retention period (Audit File Summary); it lists people and their access, so delete it when the period ends |
| EF-05 | Decisions | Cannot decide resolutions | Each Cannot decide passed to the system owner, with the owner's decision and date, within 2 working days. | Shows that access nobody recognised was resolved, not waved through. | AR-05 | One per Cannot decide decision | System owner | [[Campaign folder]]/04 Decisions | The audit file's retention period (Audit File Summary) |
| EF-06 | Decisions | Second review of privileged, generic and service accounts | Each such account with its named owner, reviewed by the system owner and by information security, with both names and dates. | Privileged and shared accounts are where auditors look hardest: the access that can do most harm, and the accounts nobody is accountable for. | AR-06 | One per system with privileged, generic or service accounts | System owner and information security | [[Campaign folder]]/04 Decisions | The audit file's retention period (Audit File Summary) |
| EF-07 | Removals | Removal tickets | A ticket, or a line on one, for each Revoke or Modify decision: date raised, date done, and its removal window (1 working day for privileged access, 5 for standard, from the decision date). | Links each decision to the change that carried it out. An auditor traces a sample of Revoke decisions to their tickets and checks the dates. | AR-07 | One per Revoke or Modify decision | System administrator | [[Campaign folder]]/05 Removals | The audit file's retention period (Audit File Summary) |
| EF-08 | Removals | Confirmation extract after removals | A fresh extract taken after the removals, showing each removed or reduced access is gone. Every removal is confirmed, late ones included; each late one is listed with its reason. | A closed ticket is not proof the access has gone. The fresh extract is. | AR-07 | One per Revoke or Modify decision | System administrator | [[Campaign folder]]/05 Removals | The audit file's retention period (Audit File Summary); it lists people and their access, so delete it when the period ends |
| EF-09 | Findings and close | Findings raised: leavers, dormant and orphan accounts, conflicts | Every leaver, dormant or orphan account and segregation-of-duties conflict found, raised as a finding in the Access Review Findings & Revocation Tracker, not only removed. | Shows the review fed back into the joiner, mover and leaver process instead of quietly cleaning up after it. | AR-08 | One per campaign | Campaign coordinator | [[Campaign folder]]/06 Findings | The audit file's retention period (Audit File Summary) |
| EF-10 | Findings and close | Process weaknesses sent to their owners | Each weakness with the process owner it went to, the agreed fix and its due date. | Auditors ask what changed after the last review. A weakness with an owner and a date is the answer. | AR-11 | One per process weakness | Campaign coordinator | [[Campaign folder]]/06 Findings | The audit file's retention period (Audit File Summary) |
| EF-11 | Findings and close | Quality check record | The rubber-stamp checks run before the campaign closed (4 signs, from the Access Review Methodology), what they found and what was done. | Shows that decisions were actually made, not approved in bulk. | AR-09 | One per campaign | Information security | [[Campaign folder]]/07 Close | The audit file's retention period (Audit File Summary) |
| EF-12 | Findings and close | Exceptions for segregation-of-duties conflicts kept | For each conflict kept, its entry in the P02 Segregation of Duties Conflict Matrix and the approved exception, with its compensating control and expiry date, in the P02 Security Exception Register. | A conflict kept without an approved exception is a finding in itself. | AR-08 | One per conflict kept | System owner | [[Campaign folder]]/07 Close | The audit file's retention period (Audit File Summary) |
| EF-13 | Findings and close | Outcome report and sign-off | The Access Review Outcome Report Template: risk removed, the four headline measures and the weaknesses found, signed off by the head of information security and the system owners. | The single document an auditor reads first: what the campaign found and who accepted the result. | AR-12 | One per campaign | Head of Information Security | [[Campaign folder]]/07 Close | The audit file's retention period (Audit File Summary) |
Campaign Checklist
One campaign's audit file. Expected (column G) follows the counts on the Audit File Summary. Yellow cells are yours. EXAMPLE rows: campaign UAR-2026-Q3.
| Row | EF ID | Phase | Evidence | Rule | How many per campaign | Expected | Received | Date received | Where kept | Result | Issue, reason for N/A, or what is outstanding | Checked by | Checked on | Status | Open no. (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | EF-01 | Scope and extracts | Scope and system list as at the extract date | AR-01, AR-02 | One per campaign | 1 | 1 | 1 Sep 2026 | Access reviews/UAR-2026-Q3/01 Scope | Pass | Campaign coordinator | 29 Sep 2026 | Complete | ||
| EXAMPLE | EF-02 | Scope and extracts | Each extract, with its completeness proof | AR-03 | One per system | 5 | 5 | 1 Sep 2026 | Access reviews/UAR-2026-Q3/02 Extracts | Pass | 5 extracts, 495 entries, each reconciled to the system's own count. | Campaign coordinator | 29 Sep 2026 | Complete | |
| EXAMPLE | EF-03 | Scope and extracts | Reviewer assignments | AR-04 | One per campaign | 1 | 1 | 1 Sep 2026 | Access reviews/UAR-2026-Q3/03 Assignments | Pass | Campaign coordinator | 29 Sep 2026 | Complete | ||
| EXAMPLE | EF-04 | Decisions | Decisions, with who decided and when | AR-05 | One per system | 5 | 5 | 15 Sep 2026 | Access reviews/UAR-2026-Q3/04 Decisions | Pass | 495 entries decided: 424 Keep, 22 Modify, 47 Revoke, 2 Cannot decide. | Campaign coordinator | 29 Sep 2026 | Complete | |
| EXAMPLE | EF-05 | Decisions | Cannot decide resolutions | AR-05 | One per Cannot decide decision | 2 | 2 | 17 Sep 2026 | Access reviews/UAR-2026-Q3/04 Decisions | Pass | Both on SYS-01, resolved by the system owner. | Campaign coordinator | 29 Sep 2026 | Complete | |
| EXAMPLE | EF-06 | Decisions | Second review of privileged, generic and service accounts | AR-06 | One per system with privileged, generic or service accounts | 4 | 4 | 15 Sep 2026 | Access reviews/UAR-2026-Q3/04 Decisions | Pass | Campaign coordinator | 29 Sep 2026 | Complete | ||
| EXAMPLE | EF-07 | Removals | Removal tickets | AR-07 | One per Revoke or Modify decision | 69 | 69 | 15 Sep 2026 | Access reviews/UAR-2026-Q3/05 Removals | Pass | Campaign coordinator | 29 Sep 2026 | Complete | ||
| EXAMPLE | EF-08 | Removals | Confirmation extract after removals | AR-07 | One per Revoke or Modify decision | 69 | 69 | 24 Sep 2026 | Access reviews/UAR-2026-Q3/05 Removals | Pass | All 69 confirmed before close. Fresh extract 2026-09-23: 68 confirmed, including 3 late on SYS-01. 1 late on SYS-05 still present (nested group): removed again, confirmed 2026-09-24. | Campaign coordinator | 29 Sep 2026 | Complete | |
| EXAMPLE | EF-09 | Findings and close | Findings raised: leavers, dormant and orphan accounts, conflicts | AR-08 | One per campaign | 1 | 1 | 29 Sep 2026 | Access reviews/UAR-2026-Q3/06 Findings | Pass | 36 leaver, dormant and orphan accounts and 1 conflict (SYS-01). | Campaign coordinator | 29 Sep 2026 | Complete | |
| EXAMPLE | EF-10 | Findings and close | Process weaknesses sent to their owners | AR-11 | One per process weakness | 2 | 2 | 29 Sep 2026 | Access reviews/UAR-2026-Q3/06 Findings | Pass | PW-01 to the HR Director, due 2026-11-30; PW-02 to the Chief Financial Officer, due 2026-12-15. | Campaign coordinator | 29 Sep 2026 | Complete | |
| EXAMPLE | EF-11 | Findings and close | Quality check record | AR-09 | One per campaign | 1 | 1 | 29 Sep 2026 | Access reviews/UAR-2026-Q3/07 Close | Pass | Campaign coordinator | 29 Sep 2026 | Complete | ||
| EXAMPLE | EF-12 | Findings and close | Exceptions for segregation-of-duties conflicts kept | AR-08 | One per conflict kept | 0 | 0 | Access reviews/UAR-2026-Q3/07 Close | N/A | No conflict kept: the SYS-01 conflict (P02 SOD-FI-01) was separated by a Modify, confirmed 2026-09-23; no exception needed. | Campaign coordinator | 29 Sep 2026 | Not applicable | ||
| EXAMPLE | EF-13 | Findings and close | Outcome report and sign-off | AR-12 | One per campaign | 1 | 1 | 29 Sep 2026 | Access reviews/UAR-2026-Q3/07 Close | Pass | Campaign coordinator | 29 Sep 2026 | Complete |
Audit File Summary
Audit file summary and sign-off
The campaign's details and counts set what the checklist expects. Completeness and the outstanding items are calculated; the sign-off is yours.
Campaign
| Field | Value | Note | ||||
| Campaign ID | UAR-2026-Q3 | EXAMPLE — replace with your campaign's ID. | ||||
| Extract date | 1 Sep 2026 | EXAMPLE. The date every extract was taken (AR-03). | ||||
| Decision deadline | 15 Sep 2026 | EXAMPLE. Removal windows count from this date. | ||||
| Close date | 29 Sep 2026 | EXAMPLE. The date the campaign was closed. | ||||
| Audit file location | Access reviews/UAR-2026-Q3 | EXAMPLE. The campaign's folder: replaces [[Campaign folder]] on the Evidence Items sheet. | ||||
| Retention period | [[e.g. 3 years after the campaign closes, or longer if your records retention schedule says so]] | Set it once, with your records retention schedule. The same for every campaign. | ||||
| Keep until | [[YYYY-MM-DD]] | The close date plus the retention period. | ||||
Campaign counts (they set Expected on the checklist)
| How many per campaign | Count | Where the count comes from | ||||
|---|---|---|---|---|---|---|
| One per campaign | 1 | Fixed. | ||||
| One per system | 5 | EXAMPLE: 5. Systems in the campaign. | ||||
| One per system with privileged, generic or service accounts | 4 | EXAMPLE: 4. From the Access Review Scope & System Inventory. | ||||
| One per Cannot decide decision | 2 | EXAMPLE: 2. Cannot decide decisions in the campaign. | ||||
| One per Revoke or Modify decision | 69 | EXAMPLE: 69. Revoke plus Modify decisions: the removals. | ||||
| One per process weakness | 2 | EXAMPLE: 2. Findings sent to a process owner (AR-11). | ||||
| One per conflict kept | 0 | EXAMPLE: 0. Segregation-of-duties conflicts kept under a P02 exception. The example's one conflict (SYS-01, P02 SOD-FI-01) was separated by a Modify, so none was kept. | ||||
Completeness
| Measure | Items | Completeness check | ||||
|---|---|---|---|---|---|---|
| Items listed | 13 | Complete: every item is received, checked and kept. | ||||
| Complete | 12 | |||||
| Not applicable | 1 | |||||
| Pending (some received) | 0 | |||||
| Not yet received | 0 | |||||
| Outstanding | 0 | |||||
Outstanding items
| Evidence | EF ID | Status | What is outstanding | |||
|---|---|---|---|---|---|---|
The first 8 outstanding items, in checklist order. A late removal is finished in the Access Review Findings & Revocation Tracker.
Sign-off
| Field | Value | Note | ||||
| Campaign coordinator | [[Name, role]] | Confirms the file holds every item, or names what is pending. | ||||
| Coordinator's signature date | [[YYYY-MM-DD]] | |||||
| Head of Information Security | [[Name, role]] | Accepts the audit file with the Access Review Outcome Report Template (AR-12). | ||||
| Signature date | [[YYYY-MM-DD]] | |||||
| Items pending at sign-off, with dates | [[None, or each pending item with its date]] | Write None when the completeness check says Complete. | ||||
Each campaign must keep an evidence file: scope, extracts, decisions, changes, confirmation and sign-off. (AR-10)
Lists
| Phase | Unit | Result |
|---|---|---|
| Scope and extracts | One per campaign | Pass |
| Decisions | One per system | Fail |
| Removals | One per system with privileged, generic or service accounts | N/A |
| Findings and close | One per Cannot decide decision |
One per Revoke or Modify decision
One per process weakness
One per conflict kept
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Audit file | Everything kept from one access review campaign so that someone who was not there can see what was reviewed, what was decided and what changed (AR-10). |
| Evidence item (EF-nn) | One kind of evidence the audit file holds, defined on the Evidence Items sheet. |
| Campaign | One round of access review across the systems due, from extract to sign-off, with an ID such as UAR-2026-Q3. |
| Extract | The list of every account on a system with its permissions, taken on a stated date (AR-03). |
| Count reconciliation | Checking that the number of entries in an extract equals the number the system itself reports. It is the proof that the extract is complete. |
| Confirmation extract | A fresh extract taken after removals, used to confirm each removed or reduced access has gone (AR-07). |
| Removal window | How long a Revoke or Modify may take: see the Access Review Methodology. Counted in working days from the decision date. |
| Cannot decide | A reviewer's answer when they do not know the person or the permission. It goes to the system owner, never to Keep by default (AR-05). |
| Quality check | The check for rubber-stamp reviews before a campaign closes (AR-09), described in the Access Review Methodology. |
| Exception | An approved, time-limited decision to keep something that breaks a rule, such as a segregation-of-duties conflict, recorded in the P02 Security Exception Register. |
| Expected | How many of an item the campaign needs, from its unit and the counts on the Audit File Summary. |
| Status | Column O of the checklist: what the item still needs. Complete and Not applicable need nothing more; Pending means some, not all, have been received. |
| Retention period | How long the audit file is kept before it is deleted. Set by your records retention schedule. |
| Working day | Monday to Friday, excluding public holidays. |
| EXAMPLE | Campaign UAR-2026-Q3 on the Campaign Checklist and the Audit File Summary. Delete before approval. |
| AR-nn, PW-nn | Rule numbers in the Access Review Methodology; process weakness numbers from the example campaign's outcome. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Clause 7.5 — Documented information | The whole checklist: the documented information a campaign keeps, where it is kept and for how long |
| ISO/IEC 27001:2022 | Annex A 5.18 — Access rights | EF-01 to EF-08: access rights reviewed, and changes made and confirmed |
| NIST CSF 2.0 | PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties” | EF-04 to EF-08 and EF-12: access permissions reviewed, least privilege and separation of duties enforced |
| PCI DSS v4.0.1 | Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six months | EF-02, EF-04 and EF-06: user and third-party accounts reviewed, with the review documented |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others | EF-01, EF-04 and EF-07: review at the required interval, and access removed without undue delay |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1