Scope: evaluate every access request submitted for one outsourced work lane and one system during a fixed quarter. Include approved, rejected, returned, withdrawn, emergency, and pending requests. Define required evidence from the policy in force when each request was submitted.

Methodology: before viewing disposition, reviewers score whether each request records business purpose, named person, requested permission, accountable sponsor, duration or review date, and revocation path. Double-code a random subset, reconcile disagreements, and report missing fields by request outcome without treating approval as proof of completeness.

Inference boundaries: NIST and GAO support access governance, accountability, and control evidence. They do not prescribe this exact checklist, certify a request, or prove that incomplete documentation caused an incident. The analysis describes record completeness within the selected system and period.

Limitations: emergency procedures, inherited access, bundled roles, policy changes, and evidence stored outside the request can cause misclassification. Complete paperwork does not show that access was appropriate or used safely. A system-level sample cannot be generalized to all outsourced work. References are listed below.