We run a US-based e-commerce infrastructure startup and are undergoing our first comprehensive third-party security and compliance audit. The auditing firm asked us to create an IAM role in our AWS account with the AWS-managed "SecurityAudit" policy attached so they can inspect our cloud infrastructure using automated scanners and manual checks. We budgeted 8,500 dollars for the audit and they said the process would take two weeks.
My concern is whether this policy could grant them even indirect access to our production data or encryption keys. "Audit" sounds passive but you hear stories about cloud environments where even read-only permissions end up exposing secrets in configuration files or database snapshots.
How safe is it to hand this policy directly to an external auditor and should we add extra guardrails? Also, once the audit wraps up, what's the best way to make sure access is completely revoked with zero backdoors left behind?