If the account review involves screen sharing or someone watching you log in, the safest method changes slightly: do not turn it into a password-recitation exercise. Ask what the reviewer actually needs to verify. They may only need confirmation that accounts have unique credentials, multifactor authentication, approved storage, and a valid recovery process. Nobody should need to see or hear the passwords themselves.
Before the review, make an inventory that contains account names, usernames, owners, and authentication methods, but no passwords. Mark which accounts use single sign-on, which have separate credentials, which are shared or service accounts, and which may no longer be needed. Reducing abandoned and duplicate accounts can remove part of the memory problem without weakening security.
I agree with the managed-vault advice, but I would be cautious about changing every credential immediately before the review. First confirm that the vault works on the devices and browsers you are expected to use. Test a normal login, a device restart, and whatever happens when you have no network connection. A password manager that you cannot access from the locked-down work laptop is not much help, even if it is technically approved.
For the small number of secrets you genuinely must remember, such as the vault passphrase or workstation login, rehearse them over several days. Type the passphrase from memory once, verify it, then leave it alone for a while. Repeatedly entering it twenty times can create false confidence because you are relying on short-term repetition. Do not keep a “temporary” clue such as the first letters of each word unless company policy explicitly permits that form of storage.
Be careful about changing the master passphrase under deadline pressure too. A long passphrase you can reliably recall is safer in practice than a new, elaborate construction you forget on review day. If you are unsure of it, use the approved recovery process before migrating more accounts rather than improvising predictable variations.
I would go into the review with the account inventory, the name of the approved credential system, and a clear explanation of where recovery material is held. That demonstrates a controlled process. Being able to recite a pile of passwords from memory does not.