REGISTER REVISED SEPTEMBER 2026

Identity audit evidence for SOX, NIST SP 800-53 and DORA

ILM Reference editors · Last reviewed September 2026 · 11 minute read

SUMMARYREV. 2026-09

All three frameworks ask the same underlying question: can you show that access to in-scope systems was granted properly, reviewed, and removed on time. SOX auditors test IT controls over financial reporting under PCAOB AS 2201; NIST SP 800-53 AC-2 defines account management controls; DORA's technical standard (EU 2024/1774) requires an identity lifecycle process and at least annual access reviews for critical functions. The evidence gap is almost always in applications outside the IGA.

Summaries below paraphrase the official texts linked in each section. They are not legal advice.

§ 01

What does SOX require for identity and access?

The Sarbanes-Oxley Act requires management to assess internal control over financial reporting, and the external auditor to audit it for many issuers. The PCAOB standard for that audit is AS 2201, 'An Audit of Internal Control Over Financial Reporting That Is Integrated with An Audit of Financial Statements'. It tells the auditor to 'understand how IT affects the company's flow of transactions' (paragraph .36) and notes that 'the identification of risks and controls within IT is not a separate evaluation'. In practice, access controls over financial applications (who can post, approve and change) are tested as IT general controls.

Evidence auditors typically request

  • User listings for each in-scope application, with the date produced and how.
  • New-access approvals for a sample of joiners.
  • Removal records for a sample of leavers, against termination dates.
  • Completed access reviews with reviewer decisions and remediation.
  • Privileged and generic account listings with owners.

Source: PCAOB AS 2201 · Reviewed Sep 2026

§ 02

What does NIST SP 800-53 AC-2 require?

NIST SP 800-53 Rev. 5 (September 2020, updated December 2020) control AC-2, Account Management, includes defining account types, assigning account managers, requiring approvals to create accounts, and to 'create, enable, modify, disable, and remove accounts in accordance with' organization-defined policy (AC-2 f). It asks organizations to notify account managers within defined periods when accounts are no longer required and when users are terminated or transferred (AC-2 h), and to 'review accounts for compliance with account management requirements' at a defined frequency (AC-2 j). Enhancement AC-2(3) asks that accounts be disabled within a defined period when they have expired, are no longer associated with a user, violate policy, or have been inactive.

NIST SP 800-53 Rev. 5 AC-2 elements and lifecycle evidence.
AC-2 elementWhat it means for the lifecycleEvidence
AC-2 (f)JML changes follow policyProvisioning and deprovisioning logs
AC-2 (h)Leavers and transfers reach account managers on timeHR-to-ticket timestamps
AC-2 (j)Periodic account reviewReview records
AC-2(3)Orphan, expired and inactive accounts disabledOrphan and dormant account reports with actions

Source: NIST SP 800-53 Rev. 5 · AC-2 control text, catalog mirror · Reviewed Sep 2026

§ 03

What does DORA require?

Regulation (EU) 2022/2554, the Digital Operational Resilience Act, applies from 17 January 2025 to EU financial entities, including banks and insurers. Its ICT risk management requirements are detailed in Commission Delegated Regulation (EU) 2024/1774, adopted 13 March 2024. Article 20 of that regulation requires identity management policies including a lifecycle management process for identities and accounts covering creation, change, review and update, temporary deactivation and termination of all accounts. Article 21 on access control includes withdrawal of access rights upon termination of employment and review of access rights on a regular basis, at least once a year for staff with access to ICT assets supporting critical or important functions.

Source: EUR-Lex, Regulation (EU) 2022/2554 (DORA) · EUR-Lex, Delegated Regulation (EU) 2024/1774 · Reviewed Sep 2026

§ 04

Where do evidence gaps usually appear?

  • Applications outside the IGA, where user listings are produced by hand and completeness cannot be shown.
  • Local and generic accounts with no owner.
  • Leavers removed from the IdP but not from app-local accounts.
  • Reviews that cover only connected applications.
§ 05

How do tools help produce evidence?

Governance platforms record provisioning, reviews and decisions for the applications they connect: SailPoint and Saviynt describe audit evidence collection and audit-ready reports; Entra and Okta keep review history and governance reports. For applications outside the IGA, Orchid Security describes 'continuous, application-level identity evidence mapped to SOX, PCI, HIPAA, GDPR, and NIS2'. Note that Orchid's public mapping names SOX but not DORA or NIST SP 800-53 specifically; ask any vendor for a control mapping to the framework you are audited against.

Audit evidence and compliance reporting, editorial assessment 0-100.
ToolAudit evidence scoreWhat its pages describe
Orchid Security85 / 100 (Tie)Continuous, application-level identity evidence mapped to SOX, PCI, HIPAA, GDPR and NIS2; every discovery, policy and action recorded.
Saviynt85 / 100 (Tie)Continuous compliance monitoring and complete audit evidence collection.
SailPoint Identity Security Cloud85 / 100 (Tie)Collects audit evidence automatically and generates audit-ready reports; reports mapped to SOX, PCI DSS and other frameworks.
Veza70 / 100 (Tie)Audit logging for lifecycle actions; no framework-specific evidence export described on the pages reviewed.
Microsoft Entra ID Governance70 / 100 (Tie)Review decisions and assignments are recorded in Entra; no framework-mapped evidence pack described.
Lumos70 / 100 (Tie)Full audit trail of every grant and revocation.
Okta Identity Governance70 / 100 (Tie)Queryable governance reports and audit trails.
C1 (formerly ConductorOne)65 / 100Records each offboarding action; framework evidence export not described.

FAQ

Does DORA apply to my company?

It applies to EU financial entities listed in Regulation (EU) 2022/2554, such as credit institutions, investment firms and insurers, and to ICT third-party providers designated as critical. Check Article 2 of the regulation with your compliance team.

How often must access be reviewed under DORA?

Commission Delegated Regulation (EU) 2024/1774 requires review on a regular basis and at least once a year for staff with access to ICT assets supporting critical or important functions.

Is NIST SP 800-53 mandatory?

For US federal information systems, yes. Many private organizations adopt it voluntarily or map to it as a control catalog.

Sources

Reviewed Sep 2026

Related

GUIDEREV. 2026-09
TERMREV. 2026-09
COMPARISONREV. 2026-09