Auditor Asked for Access Review Evidence You Don’t Have: What to Do Next
If an auditor asks for access review evidence you never kept, do not recreate it. Recover genuine records, disclose gaps, and start a defensible routine.
Updated 26 July 2026
Run access reviews with dated evidence.
Use CertPilot to maintain a manual access register, record decisions, capture completion evidence, and export an Access Review Register PDF.
If an auditor asks for access review evidence you do not have, the worst response is to invent, backdate, or “recreate” a review that never happened. The practical answer is to separate three things: what genuine evidence you can recover, what gap you must disclose, and what repeatable review routine you will run from now on. A current export can help explain today’s access, but it is not the same as historical proof that a review was completed last quarter or last year.
This guide is for the uncomfortable moment when the request already landed. It is not legal or audit advice, and CertPilot does not guarantee auditor acceptance. It is a practical recovery workflow for lean IT teams that need to answer honestly, organize what exists, and stop the same evidence gap from happening again.
First, do not backfill fake evidence
When someone asks for a review record that was never kept, pressure appears quickly. A manager may say “can’t we just pull the list now?” or “can’t we sign something for last year?” That instinct is understandable, but it creates a bigger problem than the missing file.
A current access export proves what the system shows now. It does not prove that a named reviewer checked access during a past period, made decisions, actioned removals, and signed off. A newly created spreadsheet with an old date is not evidence; it is a credibility risk.
Use this rule:
- Recover real historical artifacts.
- Explain what each artifact can and cannot prove.
- Disclose the missing review record if it was not kept.
- Start a review process that creates dated evidence going forward.
That approach may feel weaker in the short term, but it is defensible. Pretending a missing control operated is not.
What the auditor is probably asking for
The wording varies, but an access-review evidence request usually asks for a few specific facts:
- the review period, such as Q2 or the prior fiscal year;
- the systems and accounts that were in scope;
- the user population reviewed;
- who performed or approved the review;
- what decisions were made;
- what changes or exceptions remained open;
- when the review was completed.
Those facts are stronger when they sit in a completed-review record, a register, a ticket history, or an exported report. They are weaker when they come from memory or a screenshot pulled after the request arrives.
If you need the normal version of the pack, start with Access Review Evidence for Auditors: What to Prepare. This article handles the harder case: you are missing the record and need a clean recovery path.
Step 1: Confirm the exact scope of the request
Before hunting through systems, make the request precise. Ask or document:
- Which period is being requested? A calendar quarter, fiscal year, customer contract period, or policy review period.
- Which systems are in scope? Email, identity provider, finance app, CRM, production admin consoles, customer portals, or all business systems.
- Which population is in scope? Employees, contractors, privileged users, vendors, shared/service accounts, or all active accounts.
- What evidence format is expected? Ticket export, spreadsheet, PDF report, meeting minutes, sign-off record, screenshot, or policy artifact.
- Who will judge sufficiency? Internal audit, external auditor, customer security team, insurer, or leadership.
This matters because “user access review evidence” can mean several jobs. A current Microsoft 365 export may help with today’s population. It may not satisfy a request for a signed Q3 review. A ticket list may prove removals. It may not prove the whole population was reviewed. Scope keeps the conversation honest.
Step 2: Recover only genuine historical artifacts
Look for records that already existed during or soon after the requested period. Do not edit their dates or convert them into something they were not. Useful sources can include:
- access request and removal tickets;
- offboarding tickets or checklists;
- system export files saved at the time;
- emails requesting manager confirmation;
- meeting notes from a review session;
- screenshots with visible timestamps or file metadata;
- change records showing account removals or role changes;
- quarterly governance packs;
- prior customer-security-questionnaire responses;
- old spreadsheets with version history;
- manager attestations that were actually collected.
For each artifact, write a plain label:
- what it covers;
- when it was created;
- who owned or approved it;
- which system or population it applies to;
- what it does not prove.
That last line is important. A saved export from the finance app can prove a point-in-time account list. It does not prove that every manager reviewed and approved each account unless the approval was also recorded.
Step 3: Build a gap statement
A gap statement is not an excuse. It is a clear description of what is missing and what you are changing.
A practical format:
- Request: “Evidence of quarterly user access review for Q2 2026.”
- Recovered evidence: “Finance application user export dated 2026-06-28; offboarding tickets for three leavers; two admin-access change tickets.”
- Gap: “No dated access review completion record or manager/system-owner sign-off was retained for that quarter.”
- Immediate action: “Current access list reviewed on 2026-07-26; action-required items recorded separately.”
- Preventive action: “Quarterly review cadence established with dated completion log and exported Access Review Register PDF going forward.”
Do not over-polish it. The point is to avoid ambiguity. The gap either exists or it does not.
Step 4: Run a current review without pretending it is historical
A current review is still valuable. It helps you understand today’s state, close obvious access issues, and create the first real evidence cycle. Just do not label it as proof that the past review occurred.
Run the review like this:
- Create the current population. List active people, contractors, service accounts, and known shared accounts.
- List systems in scope. Start with business-critical systems and high-impact admin consoles.
- Record current access. Use manual entry, CSV import, or known system exports.
- Assign owners. Every system needs a business or technical owner who can answer whether access is still needed.
- Record decisions. Keep, change, remove, no access, or action required.
- Make changes in the underlying systems. The register records the decision; the actual removal or downgrade happens where the account lives.
- Complete the review. Capture who completed it, the date, the period, cadence, next due date, counts, and evidence note.
- Export the evidence. Save the Access Review Register PDF for the period.
If you need a full process, use the quarterly access review guide.
Step 5: Record the evidence note carefully
The evidence note should say what happened, not what you wish had happened. A useful note is short and specific.
Good examples:
- “Current recovery review completed on 2026-07-26 after missing Q2 sign-off was identified. Scope: finance app, CRM, email admin roles. Three removals handled in source systems; two action-required items remain open.”
- “Historical artifacts recovered: finance user export dated 2026-06-28 and offboarding tickets for May leavers. No Q2 manager sign-off record retained. Quarterly completion log started from Q3 onward.”
- “Review performed from customer-maintained access register and CSV exports. CertPilot records the review evidence only; access changes were completed in the underlying systems.”
Avoid notes like:
- “Q2 review completed” if it was completed today.
- “All access verified” if some systems were out of scope.
- “Compliant” or “audit-ready” unless a qualified reviewer has made that determination outside the tool.
What CertPilot can help with now
CertPilot’s Access Reviews module is useful after the evidence gap is found because it helps you build the routine the missing evidence exposed:
- a manual access register and matrix;
- systems in scope through the Systems Catalog;
- owners and reviewers;
- access levels and review results;
- action-required and overdue states;
- reminder settings;
- an immutable completion log;
- an Access Review Register PDF;
- sample report examples in the sample reports gallery.
The honest boundary is just as important: CertPilot does not connect to Google Workspace, Microsoft 365, Entra, HR systems, or identity providers today. It does not discover accounts, calculate every effective permission, remove access, backfill historical proof, certify compliance, or guarantee an audit outcome. It records and reports the evidence your team maintains.
A recovery checklist you can use today
Use this in order:
- Confirm the exact period, systems, population, and evidence format requested.
- Search for genuine historical artifacts only.
- Label each artifact with source, date, owner, scope, and limitation.
- Write a gap statement if no completed review record exists.
- Run a current access review and clearly date it as current.
- Record action-required items and complete removals in source systems.
- Complete the review and export the PDF.
- Save all artifacts together with a short evidence note.
- Set the next review due date and reminder.
- Repeat on cadence so the next request is a retrieval job, not a recovery job.
In short
- Do not invent, backdate, or “recreate” access review evidence.
- Recover genuine artifacts, explain what they prove, and disclose what is missing.
- A current export helps with today’s state, but it is not historical sign-off evidence.
- Run a current review, complete it, and start producing dated evidence going forward.
- CertPilot can organize the access register, completion log, reminders, and Access Review Register PDF; it does not certify outcomes or repair missing past evidence.
Frequently Asked Questions
Can we recreate access review evidence after the fact?
You can recover genuine records and run a current review, but you should not create a document that pretends a past review happened if it did not. A current export is useful context, not proof of historical sign-off.
What should we give an auditor if the access review record is missing?
Give the real artifacts you can recover, a clear scope and limitation note, and the first completed current review if you have run one. The auditor or compliance owner decides whether that is sufficient; CertPilot does not provide audit or legal advice.
Is a current user export enough?
Usually not by itself. It shows who appears to have access at the export time. It does not show that a named reviewer evaluated the access during the requested period or that follow-up happened.
How do we prevent this from happening again?
Create a repeatable cadence. Maintain the access register, run the review, record decisions, complete the review, export the Access Review Register PDF, and retain the artifact for each period.
Does CertPilot pull historical access records automatically?
No. CertPilot does not connect to identity providers or SaaS systems and does not pull historical account data. Records are customer-entered or CSV-imported, and the evidence reflects what your team maintained.
Turn daily checks into management-ready evidence.
CertPilot checks SSL, DNS, domain registration, and email authentication daily — and combines them with your renewal, people, assets, and access review registers into evidence reports. 14-day free trial, no card required.