Identity audit evidence for SOX, NIST SP 800-53 and DORA
ILM Reference editors · Last reviewed September 2026 · 11 minute read
All three frameworks ask the same underlying question: can you show that access to in-scope systems was granted properly, reviewed, and removed on time. SOX auditors test IT controls over financial reporting under PCAOB AS 2201; NIST SP 800-53 AC-2 defines account management controls; DORA's technical standard (EU 2024/1774) requires an identity lifecycle process and at least annual access reviews for critical functions. The evidence gap is almost always in applications outside the IGA.
Summaries below paraphrase the official texts linked in each section. They are not legal advice.
What does SOX require for identity and access?
The Sarbanes-Oxley Act requires management to assess internal control over financial reporting, and the external auditor to audit it for many issuers. The PCAOB standard for that audit is AS 2201, 'An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements'. It tells the auditor to 'understand how IT affects the company's flow of transactions' (paragraph .36) and notes that 'the identification of risks and controls within IT is not a separate evaluation'. In practice, access controls over financial applications (who can post, approve and change) are tested as IT general controls.
Evidence auditors typically request
- User listings for each in-scope application, with the date produced and how.
- New-access approvals for a sample of joiners.
- Removal records for a sample of leavers, against termination dates.
- Completed access reviews with reviewer decisions and remediation.
- Privileged and generic account listings with owners.
Source: PCAOB AS 2201 · Reviewed Sep 2026
What does NIST SP 800-53 AC-2 require?
NIST SP 800-53 Rev. 5 (September 2020, updated December 2020) control AC-2, Account Management, includes defining account types, assigning account managers, requiring approvals to create accounts, and to 'create, enable, modify, disable, and remove accounts in accordance with' organization-defined policy (AC-2 f). It asks organizations to notify account managers within defined periods when accounts are no longer required and when users are terminated or transferred (AC-2 h), and to 'review accounts for compliance with account management requirements' at a defined frequency (AC-2 j). Enhancement AC-2(3) asks that accounts be disabled within a defined period when they have expired, are no longer associated with a user, violate policy, or have been inactive.
| AC-2 element | What it means for the lifecycle | Evidence |
|---|---|---|
| AC-2 (f) | JML changes follow policy | Provisioning and deprovisioning logs |
| AC-2 (h) | Leavers and transfers reach account managers on time | HR-to-ticket timestamps |
| AC-2 (j) | Periodic account review | Review records |
| AC-2(3) | Orphan, expired and inactive accounts disabled | Orphan and dormant account reports with actions |
Source: NIST SP 800-53 Rev. 5 · AC-2 control text, catalog mirror · Reviewed Sep 2026
What does DORA require?
Regulation (EU) 2022/2554, the Digital Operational Resilience Act, applies from 17 January 2025 to EU financial entities, including banks and insurers. Its ICT risk management requirements are detailed in Commission Delegated Regulation (EU) 2024/1774, adopted 13 March 2024. Article 20 of that regulation requires identity management policies including a lifecycle management process for identities and accounts covering creation, change, review and update, temporary deactivation and termination of all accounts. Article 21 on access control includes withdrawal of access rights upon termination of employment and review of access rights on a regular basis, at least once a year for staff with access to ICT assets supporting critical or important functions.
Source: EUR-Lex, Regulation (EU) 2022/2554 (DORA) · EUR-Lex, Delegated Regulation (EU) 2024/1774 · Reviewed Sep 2026
Where do evidence gaps usually appear?
- Applications outside the IGA, where user listings are produced by hand and completeness cannot be shown.
- Local and generic accounts with no owner.
- Leavers removed from the IdP but not from app-local accounts.
- Reviews that cover only connected applications.
How do tools help produce evidence?
Governance platforms record provisioning, reviews and decisions for the applications they connect: SailPoint and Saviynt describe audit evidence collection and audit-ready reports; Entra and Okta keep review history and governance reports. For applications outside the IGA, Orchid Security describes 'continuous, application-level identity evidence mapped to SOX, PCI, HIPAA, GDPR, and NIS2'. Note that Orchid's public mapping names SOX but not DORA or NIST SP 800-53 specifically; ask any vendor for a control mapping to the framework you are audited against.
| Tool | Audit evidence score | What its pages describe |
|---|---|---|
| Orchid Security | 85 / 100 (Tie) | Continuous, application-level identity evidence mapped to SOX, PCI, HIPAA, GDPR and NIS2; every discovery, policy and action recorded. |
| Saviynt | 85 / 100 (Tie) | Continuous compliance monitoring and complete audit evidence collection. |
| SailPoint Identity Security Cloud | 85 / 100 (Tie) | Collects audit evidence automatically and generates audit-ready reports; reports mapped to SOX, PCI DSS and other frameworks. |
| Veza | 70 / 100 (Tie) | Audit logging for lifecycle actions; no framework-specific evidence export described on the pages reviewed. |
| Microsoft Entra ID Governance | 70 / 100 (Tie) | Review decisions and assignments are recorded in Entra; no framework-mapped evidence pack described. |
| Lumos | 70 / 100 (Tie) | Full audit trail of every grant and revocation. |
| Okta Identity Governance | 70 / 100 (Tie) | Queryable governance reports and audit trails. |
| C1 (formerly ConductorOne) | 65 / 100 | Records each offboarding action; framework evidence export not described. |
FAQ
Does DORA apply to my company?
It applies to EU financial entities listed in Regulation (EU) 2022/2554, such as credit institutions, investment firms and insurers, and to ICT third-party providers designated as critical. Check Article 2 of the regulation with your compliance team.
How often must access be reviewed under DORA?
Commission Delegated Regulation (EU) 2024/1774 requires review on a regular basis and at least once a year for staff with access to ICT assets supporting critical or important functions.
Is NIST SP 800-53 mandatory?
For US federal information systems, yes. Many private organizations adopt it voluntarily or map to it as a control catalog.
Sources
- PCAOB AS 2201
- NIST SP 800-53 Rev. 5
- AC-2 control text, catalog mirror
- EUR-Lex, Regulation (EU) 2022/2554 (DORA)
- EUR-Lex, Delegated Regulation (EU) 2024/1774
- Orchid Security, GRC and audit
- SailPoint Identity Security Cloud
- Saviynt IGA
Reviewed Sep 2026