Access certification campaigns that close at 100% completion and still produce audit findings. The structural reason why.
A quarterly access review closes on schedule. Every item is certified. Completion rate: 100%.
Then the auditor asks three follow-up questions.
What information did the reviewer have when they made each decision? Which of the certified items carried an active SoD conflict at the time of review? For the access marked for revocation, when was it removed from the connected system?
In most organizations, these questions cannot be answered from the certification record. The completion is documented. The evidence that the review was meaningful is not.
This is the most consistent pattern in access certification audit findings: not the absence of a review program, but a program designed to produce completion rather than evidence.
Completion and evidence are not the same thing
A completed review proves the activity happened. It does not prove the activity was informed, that conflicts were surfaced, or that findings were acted on.
Under SOX ITGC and COBIT access control frameworks, a user access review is tested on operating effectiveness, not completion rate. Operating effectiveness means reviewers had the information to make a real decision, decisions resulted in action where action was required, and the complete record can be produced without manual reconstruction.
A completed spreadsheet fails all three tests.
The process problem that produces rubber stamps
The gap between completion and evidence is structural, not behavioral. It is produced consistently when reviewers are handed the wrong inputs.
A typical certification workflow gives a reviewer a list of technical role names, a binary certify or revoke option, and a deadline. No information about what the access permits in business language. No visibility into SoD conflicts. No account history. No indication of whether the user's role has changed since the access was granted.
Under those conditions, certifying the list is the rational response. The reviewer cannot make a meaningful decision without meaningful information. When the process withholds that information, the review produces a sign-off. The completion rate looks identical to a genuine review. The evidentiary value is entirely different.
This is also the mechanism that produces the specific finding most commonly cited in access review audits: a reviewer who approved access creating a significant SoD conflict, because the conflict was invisible in the review workflow.
What changes a review into evidence
Five things must be present for a completed review to qualify as evidence that a control operated.
Context at decision time, meaning reviewers see entitlement purpose, risk classification, SoD conflicts, recent usage, and what changed since the last review, not just a role name. A governed decision record, meaning decisions exist in a workflow system that captures who decided, when, and what the outcome was. Remediation tracked to completion, meaning revocation decisions are routed to an owner and the system confirms removal with a timestamp. Documented exceptions, meaning retained access with a risk flag carries a rationale, a compensating control, and a review date in the governance record. And an exportable trail, meaning the complete campaign record can be produced for an auditor without manual reconstruction from multiple systems.
None of these require more effort from reviewers. They require a process designed to produce evidence as a byproduct of normal operation, rather than a process designed to produce completion.
The architectural distinction that matters
Organizations that get this right do not have more disciplined reviewers or more thorough compliance teams. They have processes designed so that evidence is inseparable from the operation.
Context surfaces automatically because the system retrieves it at review time. Decisions are captured in a governed workflow because that is where reviewers work. Remediation is tracked because revocation actions move through the same system that recorded the decision. The exportable trail exists because the system records every event as it occurs.
The completion rate and the evidence rate are the same number in a well-designed process. In a poorly designed one, the completion rate is high and the evidence rate is effectively zero.
The access certification program that produces a clean completion record and fails the follow-up questions is not a control. It is a ritual that documents itself. The distinction is design.
What evidence gaps are compliance and IAM teams finding most consistently in access certification programs right now? The experiences of teams working through this would be worth hearing.
https://www.openiam.com/soluti....ons/access-governanc