Resource library

    Expert insight / Evidence and review

    What Counts as Good Evidence in an IAM Assessment?

    Learn what policies, tickets, exports and logs can establish, and where each has limits.

    AIdentX Editorial · · 3 min read

    At a glance

    A folder full of documents is not the same as a supported answer. Good evidence is relevant to a particular claim, comes from an understandable source and covers the system and period being assessed.

    • Match the evidence to the claim.
    • Check the source, scope and date.
    • Keep contradictions and missing records visible.

    Start with the claim you need to support

    Suppose a participant says that temporary supplier access is removed when an engagement ends. The reviewer needs to establish the authorised end date and the actual removal event. A general access policy explains the intended rule, but it cannot show what happened to the selected account.

    This example is illustrative, not a customer case study. A useful evidence set could include the approved request, the engagement end date and a record showing when access was removed. The relationship between the records matters more than the number of attachments.

    Understand what each record tells you

    EvidenceCan help establishDoes not establish alone
    Approved policyThe intended requirement.That the requirement operated in every case.
    Request or ticketThe recorded approval or action.The resulting effective access.
    Configuration exportSettings at the captured time.Unchanged operation throughout the period.
    Activity or removal logA recorded event.Coverage beyond the recorded system or period.

    Check context before drawing a conclusion. A screenshot without an application name or capture date may need supporting information. An export with filtered rows may be suitable for a selected sample but unsuitable for a claim about the entire population. Ask how the material was produced.

    Use a small evidence description

    For each important item, record its source, owner, observation period and the claim it supports. If the record is redacted, explain what has been removed and whether that affects the review. Keep unnecessary personal information and secrets out of the assessment material.

    Where a document is analysed by AI, check the key statements against the source. A summary may be useful for navigation, but the reviewer still needs to understand the original evidence. If the analysis misses a table or qualification, correct the interpretation before accepting the answer.

    NIST SP 800-53A provides assessment procedures using examination, interviews and tests. The methods support evidence gathering; an attachment alone does not determine the assessment conclusion. NIST SP 800-53A Rev. 5: Assessing Security and Privacy Controls.

    Treat disagreement as a review task

    If a ticket says an account was removed and a later export shows it enabled, check timestamps, account identifiers and effective permissions. The records may refer to different accounts or different stages of the process. Do not choose the record that produces the preferred answer.

    In AssessX, participant answers and uploaded documents form part of the review workflow. A useful reviewer comment explains precisely what remains unresolved: “Please provide the removal record for this account and confirm the observation date.” This is easier to act on than a generic request for more evidence.

    References

    Primary guidance used for the specific points cited above. The examples, templates and recommended working practices are AIdentX editorial guidance.

    Sources reviewed September 2026.

    Published by AIdentX Editorial. Illustrative scenarios are fictional and do not represent customer results.

    Continue reading

    See the workflow in practice. Watch the AssessX product demonstrations.