Auditors ask three questions: Who has access? Who approved it? Can you show it was removed when no longer needed?
An audit-ready IGA program keeps living evidence:
- Authoritative joiner/mover/leaver events with timestamps.
- Request and approval history linked to entitlements.
- SoD policy definitions, violations, and exception register.
- Certification campaign results with reviewer identity and decisions.
- Privileged session or checkout logs from PAM where applicable.
Avoid “screenshot archaeology.” Exportable reports, immutable logs, and clear control owners beat ad-hoc spreadsheets. Map controls to frameworks (SOX ITGC, ISO 27001 A.5/A.8, NIS2, DORA) so the same evidence serves multiple assessments.
Continuing theme: reduce standing privilege so there is less high-risk access to explain.