Identity Security in Practice: What Auditors Check First

TL;DR

  • Identity is the fastest path from “we have ISO tools” to “we can prove control” — or the fastest path to a major finding.
  • Auditors sample privileged accounts, MFA exceptions and JML tickets — not your policy PDF alone.
  • Break-glass accounts must be rare, monitored and tested; standing admin is a finding waiting to happen.
  • Evidence beats narrative: access reviews, logs and ticket IDs tied to approvals.

Security programmes often lead with network diagrams and endpoint agents. External auditors — whether for ISO 27001, NIS2 readiness, DORA or customer due diligence — usually start elsewhere: who can access what, through which path, with what approval, and can you prove it for last quarter. Identity is not a subsection of IT. It is the control plane. When identity is weak, every other control becomes harder to trust: your SIEM cannot tell a legitimate admin from a stale vendor account that should have been disabled.

We have sat in audit opening meetings where the CISO presents a polished ISMS folder and the lead auditor replies, “Thank you — now show me three terminated contractors and when their access was removed.” That question sets the tone for the week. The organisations that pass smoothly are rarely the ones with the most tools. They are the ones where HR status, IAM provisioning and ticket numbers line up without improvisation.

The first three samples auditors request

Privileged access inventory comes first. Auditors do not accept “we have few admins” as evidence. They want a list of accounts with elevated rights across Active Directory, Entra ID or Azure, cloud IAM roles, database sysadmin equivalents and SaaS admin consoles — with last-use timestamps and named human owners. Standing global administrator without Privileged Identity Management or just-in-time elevation is routinely flagged. One manufacturing client discovered fourteen dormant Global Admin accounts from a 2019 migration; three had logged in within the last month with no documented reason.

MFA coverage and exceptions is the second sample. Tenant-level “MFA enabled” is not the same as enforced on every sign-in path. Auditors ask for the percentage of users with phishing-resistant MFA where the platform supports it, plus every documented exception: legacy protocols, service accounts, break-glass, integration users. Each exception needs a compensating control, an expiry date and a named approver. A spreadsheet of “temporary” exceptions that renewed quarterly for two years is a major nonconformity waiting to be written.

Joiner–mover–leaver evidence closes the opening trio. Auditors pick three random hires, role changes and terminations from the last ninety days. For each they trace HR ticket to provisioning request to access granted to access removed. Gaps between HR offboarding date and account disable — even forty-eight hours — are among the most common major findings in B2B IT. In one case a departed sales engineer retained VPN access for eleven days because “IT was waiting for laptop return.” The laptop was irrelevant to the VPN credential.

What “good” looks like without buying another portal

Mature identity security is deliberately boring. Role-based groups map to job functions, not to individuals’ convenience. Access recertification runs on a calendar with named data owners who actually click approve or revoke — not auto-approve after reminder emails. Privileged sessions are logged; break-glass accounts live offline, are counted on one hand and are exercised in a tabletop quarterly. The tooling varies: Entra ID, Okta, Keycloak, on-prem AD. The evidence model does not.

We recommend a single identity control matrix: control objective, system of record, log source, review cadence, owner. When an auditor asks “show me how you revoke vendor access within twenty-four hours of contract end,” you open one row — not five Slack threads and a manager’s memory. The matrix is not bureaucracy; it is the map that lets a new CISO or MSP take over without losing audit readiness.

Good identity also means time-to-revoke as a measured SLA, not a policy aspiration. If HR marks someone terminated at 17:00 Friday, when does IAM show disabled? Chart it monthly. Spikes correlate with reorganisations and acquisitions — exactly when auditors expect gaps.

Common failures we see in B2B IT

Shared mailbox accounts used as pseudo-users for RDP or VPN appear in almost every mid-market review. They cannot hold MFA cleanly, blur accountability and survive reorganisations because “everyone knows the password.” Vendor accounts without contract end dates in IAM are another staple: the integrator who built the warehouse API in 2021 still has production database read access because nobody owned offboarding when the project closed.

Local administrator on laptops “because helpdesk is faster” undermines entire device trust models. Cloud IAM sprawl — project-level Owner for convenience, service account keys in repos — turns up in equal measure. Each failure is fixable, but not by policy PDF alone. Automate disable on HR status change, enforce PIM for cloud admin, block legacy auth where modern protocols exist, and measure exceptions shrinking quarter over quarter.

Scenario: ISO surveillance vs customer security questionnaire

Consider two assurance events in the same month. ISO surveillance samples JML and privileged access — evidence-heavy, process-focused. A enterprise customer’s questionnaire asks about SSO, MFA enforcement on admin roles and how you manage third-party access to production. If your answers differ between the two because identity data lives in three systems, you will contradict yourself under time pressure.

The fix is one source of truth for identity evidence: exports from IdP, ticketing IDs, access review sign-offs. A fintech client unified these into a quarterly “identity pack” consumed by internal audit, customer DD and regulatory prep. Preparation time for each event dropped from weeks to days — not because they bought a GRC unicorn, but because they stopped rebuilding the same story from scratch.

How this connects to wider assurance

Identity findings cascade. Poor JML invalidates penetration test scope when the tester uses a stale vendor account that should have been removed. Weak MFA on admin paths means red-team success is attributed to “sophisticated attack” when the root cause was standing privilege. Strong identity shrinks attack surface and makes technical testing meaningful: findings reflect real control gaps, not hygiene debt.

If you are preparing for NIS2, DORA or a board risk committee, start identity evidence before you order another vulnerability scanner. Scanners find holes; identity proves you know who can walk through them. Our Audit and Information Security Consulting practice maps controls to your actual IdP and ticketing — then helps close gaps with operable runbooks, not slide decks.

Want to discuss a project?

Contact us

More from this topic