At first glance, most audit requests seem straightforward.

Provide a user access listing.

Share change management records.

Submit a privileged access review.

On paper, these requests appear simple. In practice, however, they often become the very reason an audit engagement slows down.

The challenge is rarely the evidence itself. More often, it is the process required to collect, review, and track that evidence across different systems, departments, and stakeholders.

Figure 1. Five audit requests that commonly create bottlenecks during evidence collection

1. User Access Listings

Access listings are among the most common audit requests, but they are not always easy to produce.

Many organisations manage identities across multiple applications, directories, and business systems. As a result, auditors may receive data in different formats, from different owners, and at different points in time.

Before testing can even begin, teams often need to verify that the information is complete, accurate, and relevant for the audit period.

2. Privileged Access Reviews

Privileged accounts require additional scrutiny because they provide elevated access to critical systems.

Reviewing these accounts often involves several stakeholders, including IT administrators, system owners, and managers responsible for approving access.

The review itself may not be complicated, but coordinating approvals across departments can introduce unnecessary delays when responsibilities and deadlines are not clearly defined.

3. Change Management Records

A change record is only valuable when it tells the complete story.

Auditors typically need to confirm that changes were properly requested, approved, tested, and implemented according to established procedures.

When documentation is incomplete or approvals are missing, additional follow-up becomes necessary, extending the audit process and increasing administrative effort for everyone involved.

4. Vendor and Third-Party Evidence

As organisations increasingly rely on external service providers, audit evidence often extends beyond internal teams.

Security reports, compliance certifications, or contractual documentation may need to be obtained from third parties, each with their own processes and response times.

Without a structured approach to managing these requests, collecting external evidence can quickly become one of the longest stages of an audit.

5. Policy Exception Documentation

Policy exceptions are rarely static.

They change over time, require periodic reviews, and often involve multiple approvals before they can be accepted or renewed.

When exception records are maintained across emails, spreadsheets, or separate documents, it becomes difficult to verify which exceptions remain valid and whether the appropriate approvals are still in place.

The Request Isn’t the Bottleneck

Looking at these examples, a common pattern emerges.

None of these requests are unusual. None of them are inherently difficult.

What creates delays is the lack of a structured process behind them.

When evidence is stored across different locations, ownership is unclear, and progress is tracked manually, even routine requests can take far longer than expected.

On the other hand, when evidence requests follow a consistent workflow, responsibilities are clearly assigned, and documentation is managed in a central location, audit teams gain better visibility into the entire process.

The result is not simply faster evidence collection. It is a more predictable audit, fewer unnecessary follow-ups, and more time for auditors to focus on evaluating risks rather than coordinating documentation.

Because in most IT audits, the request itself is rarely the problem. The process behind it is.