Vendor Identity Audit Evidence
Governance Confirmed. Evidence Unavailable. Both Cannot Be True for Compliance.
7 min read · 3 May 2026 · Security
A cloud services vendor serving financial institutions received a regulatory examination request that included questions about vendor identity governance. The regulator asked for evidence of identity governance controls for the vendor's staff who accessed regulated customer environments , specifically, access review output from the preceding four quarters, role definition documentation with permission scope, MFA enforcement configuration and coverage, and privileged access management records for the highest-privilege accounts. The vendor's CISO compiled a questionnaire response confirming that all required controls were in place: quarterly access reviews were conducted, roles were defined and documented, MFA was enforced, and PAM was deployed for privileged accounts. The regulator requested the evidence documents rather than the attestation. The access review output was not retained in a format suitable for examination , the IGA platform stored review completion records but not the individual review decisions made for each account. The role definitions were in a Confluence wiki that had been reorganised, and the current permission scope for each role was not documented in a standalone format. The MFA enforcement configuration had no exceptions documented. The PAM session recordings were retained, but the access workflow records were in a separate system that had not been configured for export. The governance had been conducted. The evidence had not been retained in an examination-ready format.
What are Vendor Identity Audit Evidence Requirements, Really?
Audit evidence for identity governance is the documentation that demonstrates, to an external examiner, that identity governance controls operated as described , not attestations that they exist, but records of their operation. Access review audit evidence consists of the specific review decisions made for each account (approved, revoked, scope modified), not just the completion record that shows the review was conducted. MFA enforcement audit evidence consists of the policy configuration, the coverage exceptions, and the exception justifications , not just the attestation that MFA is enforced. PAM audit evidence consists of the access workflow records, the session recordings, and the privileged access log , not just the confirmation that PAM is deployed.
The attestation-versus-evidence distinction is the governance gap that compliance examinations consistently surface. Attestations are statements about the existence and operation of controls , 'access reviews are conducted quarterly,' 'MFA is required for all users,' 'PAM governs privileged access.' These attestations are accurate and useful for understanding the control environment. Evidence is the documentation that supports those attestations , the access review output that shows what decisions were made, the configuration records that show what policy is enforced, the access logs that show what the PAM governed. Regulators and auditors increasingly require evidence rather than attestation, because attestation without evidence cannot distinguish a genuinely operating control from a claimed control.
The evidence retention gap is the operational failure that produces the scenario in the hook. Controls that operate without generating examination-ready evidence , or that generate evidence in systems not configured for retention and export , produce governance that exists in operational reality but cannot be demonstrated to an examiner. The IGA platform that records review completion but not individual decisions produces a completion record that cannot support the examiner's question about what specific accounts were reviewed and what decision was made for each. The PAM platform whose session recordings are retained but whose access workflow records are in an unconsolidated system produces evidence that is partially available and partially missing.
- Access review decisions not retained , review completion records without individual account decisions
- Role definitions not in standalone examination-ready format , permission scope embedded in systems not configured for audit export
- MFA exceptions not documented , policy without exception documentation cannot support claims of comprehensive coverage
- PAM evidence fragmented across systems , session recordings and workflow records in separate systems without consolidated export
- Evidence retention period insufficient , evidence not retained for the period regulatory examinations may cover
Why this matters
Vendor identity audit evidence matters for TPRM because customers who rely on vendor attestations of identity governance for their own regulatory compliance may find those attestations unsupportable when the regulator asks for underlying evidence. A vendor who has provided a TPRM questionnaire response confirming quarterly access reviews may be unable to produce the access review output that supports that confirmation when the customer's auditor requests it. The customer's regulatory compliance depends on the vendor's attestation being backed by evidence , and the evidence gap at the vendor may become the compliance gap for the customer.
The GDPR accountability principle and financial services regulatory requirements explicitly require that data processors can demonstrate compliance , not just claim it. Article 5(2) of GDPR requires that the controller 'shall be responsible for, and be able to demonstrate compliance.' A vendor who cannot demonstrate their identity governance controls to an examiner creates a compliance risk for the customer who relied on those controls as part of their own compliance posture.
Where most teams get this wrong
The most consistent failure is designing governance processes without simultaneously designing the evidence generation those processes produce. Controls that are implemented without evidence retention requirements produce governance that operates and cannot be demonstrated. The evidence design question , what documentation does this control need to produce, in what format, retained for how long , must be answered when the control is designed, not when the examiner asks for it.
- Designing controls without simultaneous evidence retention design
- IGA configured for completion but not decision capture
- Evidence in systems not configured for audit export
- No evidence retention period policy calibrated to examination scope
- Attestation accepted as evidence , not asking for underlying documentation
What good looks like
Mature identity governance programmes design evidence generation as a core component of each control , access reviews configured to capture individual decisions, role definitions maintained in standalone documented format, MFA configuration with exception documentation, and PAM records consolidated for examination-ready export.
- Access review decisions captured , individual account decisions (approved/revoked/scope modified) with reviewer and timestamp
- Role definitions in examination-ready format , standalone documentation of each role's permission scope
- MFA exception documentation , all exceptions to MFA requirement documented with justification
- PAM records consolidated , session recordings and workflow records in consolidated, exportable format
- Evidence retention calibrated to examination scope , retained for the periods regulatory examinations typically cover
Tooling
Compliance Automation , Drata, Vanta, Secureframe
Automated compliance platforms collect identity governance evidence continuously , capturing access review decisions, MFA configuration records, and access log summaries in examination-ready format. Drata specifically integrates with IGA platforms to collect access review completion and decision records automatically. For TPRM practitioners, asking whether the vendor uses automated compliance evidence collection for identity governance controls provides a specific evidence readiness question.
IGA with Evidence Export , SailPoint, Saviynt
Modern IGA platforms provide examination-ready access review evidence export , generating reports that show each account reviewed, the reviewer, the decision, the timestamp, and for revoked accounts, the revocation action taken. For TPRM practitioners, asking whether the vendor's IGA platform generates examination-ready access review output , individual decisions, not just completion records , provides a specific evidence quality question.
Governance challenges
The governance challenge with audit evidence is the effort investment problem. Designing evidence retention into controls requires additional configuration, additional storage, and additional process discipline beyond the minimum required to operate the control. The additional effort is justified by the examination readiness it produces , but that justification only becomes concrete when an examiner asks for documentation that is not available. Investing in evidence design before the examination is less expensive than explaining evidence gaps during it.
- Request evidence rather than attestation for vendor identity governance , ask for the documents
- Ask whether IGA captures individual review decisions , not just completion records
- Ask whether role definitions are in standalone documented format
- Ask whether MFA exceptions are documented
- Ask about evidence retention period , how long identity governance evidence is retained
If you are a small team
Ask your three highest-risk vendors for evidence rather than confirmation on two specific identity governance controls: provide the access review output from your last quarterly review showing the individual decisions made for each account , not the completion confirmation, the decision record. And provide your current role definitions showing the permission scope for the three most common roles your staff hold. Those two requests will reveal immediately whether examination-ready evidence exists or whether governance has been attested without documentation.
- Request access review decision records , individual decisions, not completion confirmation
- Request role definition documentation , permission scope for most common roles
- Request MFA configuration with exception documentation
- Ask about evidence retention period for identity governance records
What to require
Ask directly:
"Can you provide the access review output from your last quarterly review , specifically, the individual account decisions showing which accounts were reviewed, what decision was made for each, and which accounts were revoked or modified?"
"Can you provide your role definitions in a standalone document format showing the specific permission scope for each role that your staff who access our environment hold?"
Expect as evidence
- Access review decision record , individual decisions with reviewer and timestamp
- Role definition document , permission scope for each role
- MFA configuration with exception documentation
- Evidence retention period documentation
A vendor who confirms quarterly access reviews should be able to produce the decision record from the last one. If the IGA only retains completion records without individual decisions, the quarterly review occurred and cannot be evidenced at the decision level. The governance was real. The evidence was not retained. Ask for the document. The document is the difference between attestation and evidence.
How to evidence it
- Vendor access review decision records
- Role definition documentation from vendors
- MFA exception documentation
- Evidence retention period records
Key Takeaway
Governance that cannot be evidenced to an examiner is governance that cannot be relied upon for compliance purposes. The controls were real. The access reviews were conducted. The roles were defined. The MFA was enforced. None of it could be demonstrated from documentation when the examiner asked for documents rather than confirmations. Attestation says the control exists. Evidence proves it operated. Regulators are asking for evidence. Design the evidence when you design the control. Retain it for the periods examinations cover. Request it from vendors rather than accepting attestation. The compliance posture that depends on vendor attestation without evidence is a posture that will fail the examination that asks for the document.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association