An access review is a recurring check of who can reach which systems, applications and data, carried out by people who can judge whether that access is still needed. Reviewers, typically managers or application owners, confirm or revoke each person’s access, and the decisions are recorded as evidence. Access reviews are also called user access reviews or access recertifications, and they are one of the most commonly tested controls in security and financial audits.
At a glance
- A periodic or event-driven check that each user’s access still matches their job.
- Reviewers are usually managers or system owners; IT or security runs the process and removes access.
- Common scope: privileged accounts, financially significant systems, sensitive data and SaaS applications.
- The output is a decision per user or entitlement, plus evidence that removals actually happened.
- Often run manually at first, then automated with identity governance or similar tools as the estate grows.
What problem it solves
Access accumulates. People change roles and keep their old permissions, projects end without anyone removing the shared folder rights, contractors leave without their accounts being closed, and admin rights granted “temporarily” stay for years. Each of these widens what an attacker can do with a stolen account and what an insider can do by mistake. A joiner-mover-leaver (JML) process is meant to prevent this, but it misses things, especially in applications that are not connected to central identity.
An access review is the safety net. It forces a regular look at what people actually hold against what they need, which supports least privilege and gives auditors evidence that access is controlled. Frameworks and audits such as SOX IT general controls (ITGC), SOC 2 and ISO/IEC 27001 commonly expect some form of periodic access review, although the exact expectation varies by framework and auditor.
How it works
Scope. The organization decides which systems and accounts are in scope and how often each is reviewed. High-risk access, such as admin accounts and systems that feed financial reporting, is usually reviewed more often.
Data collection. Current users and their entitlements are pulled from each application, directory or cloud platform. This is often the hardest step: applications that are not connected to central identity may need manual exports, and account names may not match a real person.
Assignment. Each item is routed to a reviewer, usually the user’s manager, the application owner, or both in sequence.
Decision. The reviewer certifies (keep) or revokes (remove) each user or entitlement, sometimes with a comment. Good reviews show what an entitlement allows in plain language, not just a cryptic group name.
Remediation. Revoked access is removed, either automatically through a connector or by a ticket to the system owner. The process tracks each removal to completion.
Evidence. The organization keeps a record of who reviewed what, when, what they decided and when removals were completed. Auditors typically sample this record.
Variations include campaigns focused on privileged accounts, reviews of a single sensitive application, and event-driven reviews after a reorganization, merger or security incident.
When it matters for buyers
- Before an audit or certification. If SOX, SOC 2, ISO/IEC 27001, HIPAA or a customer contract applies, check what evidence of access review is expected and whether you can produce it.
- When reviews are spreadsheet-driven and late. A growing SaaS estate usually means more applications, more reviewers and more chasing. Automation tools are worth evaluating at this point.
- When reviewers rubber-stamp. If managers approve everything, the control exists on paper only. Role design, such as role-based access control (RBAC), and clearer entitlement descriptions make reviews more meaningful.
- When standing admin rights are common. Reducing permanent privileges with just-in-time access (JIT) and privileged access management (PAM) shrinks what needs reviewing.
Our governance, risk and compliance overview covers how access review fits into a broader controls program.
Questions to ask vendors
- Which applications can you connect to directly, and how do you handle ones you can’t connect to?
- Can reviewers see a plain-language description of what each entitlement allows?
- Can you remove revoked access automatically, and how do you track manual removals to completion?
- What evidence do you export for auditors, and in what format?
- Can you run different review frequencies and reviewers for privileged, financial and general access?
- How do you flag risky patterns, such as orphaned accounts, users with no manager or conflicting permissions?
How it differs from identity governance and administration (IGA)
An access review is one control. Identity governance and administration (IGA) is the broader discipline, and the category of tools, that manages identities and access across their lifecycle: provisioning and deprovisioning, access requests and approvals, role management, policy such as separation of duties, and access certification. Access reviews are often among the first problems that lead organizations to look at IGA tools, but you can run access reviews without one, and an IGA tool does far more than reviews.
