What Is an Access Review?

Also called: User access review, Access recertification, Access certification

Related problems: Auditors asking for evidence that someone checks who has access; Former employees and contractors still holding accounts; Managers rubber-stamping access lists they don't understand; Review cycles that take weeks of spreadsheets and email

An access review is a recurring check of who can reach which systems, applications and data, carried out by people who can judge whether that access is still needed. Reviewers, typically managers or application owners, confirm or revoke each person’s access, and the decisions are recorded as evidence. Access reviews are also called user access reviews or access recertifications, and they are one of the most commonly tested controls in security and financial audits.

At a glance

  • A periodic or event-driven check that each user’s access still matches their job.
  • Reviewers are usually managers or system owners; IT or security runs the process and removes access.
  • Common scope: privileged accounts, financially significant systems, sensitive data and SaaS applications.
  • The output is a decision per user or entitlement, plus evidence that removals actually happened.
  • Often run manually at first, then automated with identity governance or similar tools as the estate grows.

What problem it solves

Access accumulates. People change roles and keep their old permissions, projects end without anyone removing the shared folder rights, contractors leave without their accounts being closed, and admin rights granted “temporarily” stay for years. Each of these widens what an attacker can do with a stolen account and what an insider can do by mistake. A joiner-mover-leaver (JML) process is meant to prevent this, but it misses things, especially in applications that are not connected to central identity.

An access review is the safety net. It forces a regular look at what people actually hold against what they need, which supports least privilege and gives auditors evidence that access is controlled. Frameworks and audits such as SOX IT general controls (ITGC), SOC 2 and ISO/IEC 27001 commonly expect some form of periodic access review, although the exact expectation varies by framework and auditor.

How it works

Scope. The organization decides which systems and accounts are in scope and how often each is reviewed. High-risk access, such as admin accounts and systems that feed financial reporting, is usually reviewed more often.

Data collection. Current users and their entitlements are pulled from each application, directory or cloud platform. This is often the hardest step: applications that are not connected to central identity may need manual exports, and account names may not match a real person.

Assignment. Each item is routed to a reviewer, usually the user’s manager, the application owner, or both in sequence.

Decision. The reviewer certifies (keep) or revokes (remove) each user or entitlement, sometimes with a comment. Good reviews show what an entitlement allows in plain language, not just a cryptic group name.

Remediation. Revoked access is removed, either automatically through a connector or by a ticket to the system owner. The process tracks each removal to completion.

Evidence. The organization keeps a record of who reviewed what, when, what they decided and when removals were completed. Auditors typically sample this record.

Variations include campaigns focused on privileged accounts, reviews of a single sensitive application, and event-driven reviews after a reorganization, merger or security incident.

When it matters for buyers

  • Before an audit or certification. If SOX, SOC 2, ISO/IEC 27001, HIPAA or a customer contract applies, check what evidence of access review is expected and whether you can produce it.
  • When reviews are spreadsheet-driven and late. A growing SaaS estate usually means more applications, more reviewers and more chasing. Automation tools are worth evaluating at this point.
  • When reviewers rubber-stamp. If managers approve everything, the control exists on paper only. Role design, such as role-based access control (RBAC), and clearer entitlement descriptions make reviews more meaningful.
  • When standing admin rights are common. Reducing permanent privileges with just-in-time access (JIT) and privileged access management (PAM) shrinks what needs reviewing.

Our governance, risk and compliance overview covers how access review fits into a broader controls program.

Questions to ask vendors

  • Which applications can you connect to directly, and how do you handle ones you can’t connect to?
  • Can reviewers see a plain-language description of what each entitlement allows?
  • Can you remove revoked access automatically, and how do you track manual removals to completion?
  • What evidence do you export for auditors, and in what format?
  • Can you run different review frequencies and reviewers for privileged, financial and general access?
  • How do you flag risky patterns, such as orphaned accounts, users with no manager or conflicting permissions?

How it differs from identity governance and administration (IGA)

An access review is one control. Identity governance and administration (IGA) is the broader discipline, and the category of tools, that manages identities and access across their lifecycle: provisioning and deprovisioning, access requests and approvals, role management, policy such as separation of duties, and access certification. Access reviews are often among the first problems that lead organizations to look at IGA tools, but you can run access reviews without one, and an IGA tool does far more than reviews.

Frequently Asked Questions

How often should access reviews happen?
It depends on risk and on what your auditors or frameworks expect. Many organizations review high-risk and privileged access quarterly and other access every six or twelve months, with event-driven reviews after a reorganization or acquisition. Agree the frequency with your auditors before you design the process.
Who should do the review?
Usually the person who can judge whether the access is still needed: the user's manager, the owner of the application or data, or both. IT runs the process and removes access, but it is usually not the right party to decide whether a finance user still needs the general ledger.
Is an access review the same as an audit?
No. An access review is a control your organization runs itself. An audit is an independent check, internal or external, that often tests whether your access reviews happened, were done properly and led to removals.
Do we need special software to run access reviews?
Not necessarily. Small environments often run them from exported user lists and spreadsheets. As the number of applications and users grows, identity governance tools, some privileged access and SaaS management platforms, and some identity providers can automate the collection, reminders, decisions and evidence.
What happens if a reviewer revokes access by mistake?
The user requests it again through the normal access request process. That is why reviewers should be able to see what each entitlement actually allows, and why removals are usually tracked to completion with a record of who decided.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.