Back to blog
Audit

User access reviews: the control auditors fail you on most

Access reviews are the most-sampled and most-failed control in security audits. How to run one that holds up - scope, cadence, reviewer selection, evidence, and closing the loop on revocations.
GRC Copilot Team
User access reviews: the control auditors fail you on most

A user access review is a periodic check that everyone who has access to a system still needs it, approved by someone who can judge that. It is the single most sampled control in ISO 27001, SOC 2, the NCA ECC and SAMA CSF audits - and the one organisations fail most often, usually not because access is wrong but because the review was never evidenced.

Why it fails so often

  • The review happened in a meeting and left no record.
  • IT reviewed the list instead of the business owner who understands the roles.
  • Revocations were decided but never actioned - and nobody checked.
  • Only the easy systems were reviewed; the finance or production database was skipped.
  • The export has no date, so it cannot be tied to the audit period.

Scope: what must be reviewed

Prioritise by what an attacker or a mistake could reach:

  • Systems holding customer, personal or financial data.
  • Production infrastructure and cloud consoles.
  • Privileged and administrative accounts everywhere - these deserve a tighter cadence.
  • Source code repositories and CI/CD pipelines.
  • Third-party and contractor access.
  • Service and machine accounts - routinely forgotten and rarely expired.

Cadence that satisfies most frameworks

  • Privileged accounts: quarterly, at minimum.
  • Critical systems: quarterly.
  • General business applications: semi-annually or annually.
  • On change: immediately for a leaver, and on any role change or transfer.

Whatever you choose, write it in your policy and then actually do it at that frequency. Auditors test you against your own stated cadence, so promising quarterly and delivering annually manufactures a finding.

Running a review that holds up

  1. Export the full user list from the system itself, with a visible date and the roles or permissions each user holds.
  2. Send it to the right reviewer - the business or data owner, not the IT administrator who provisions access.
  3. Require an explicit decision per user: retain, modify or revoke. A blanket "all fine" reply is weak evidence.
  4. Capture approval with the reviewer's name and date.
  5. Action the revocations and record when each was completed.
  6. Close the loop - re-export afterwards to prove the removals took effect. This step is what separates a passing review from a finding.
  7. Retain everything for the audit period.

Run access reviews without the spreadsheet chase

GRC Copilot pulls user lists from your systems, routes each review to the right owner, tracks revocations to completion, and files the evidence against every framework that requires it.

The leaver reconciliation auditors love

Expect this test: the auditor takes your HR leaver list for the period, picks five names, and checks when each account was actually disabled. Any account still active, or disabled weeks later, is an exception.

Get ahead of it by running the same reconciliation yourself every month - HR leavers against active accounts across all systems - and fixing the gaps before someone else finds them.

The strongest access review evidence is boring: a dated export, a named reviewer, a decision per line, and a second export showing the revocations landed.

Frequently asked questions

Who should perform the review?

The business or data owner who understands what each role needs. IT provides the data and executes changes but should not be the sole approver of its own provisioning.

How often are access reviews required?

Frameworks rarely mandate an exact interval; they require it to be periodic and risk-based. Quarterly for privileged and critical access is the widely accepted norm.

What about service accounts?

Review them too. Assign each one a human owner and a purpose, and check whether it is still needed and appropriately scoped. Orphaned service accounts are a common audit finding and a genuine risk.

Is a screenshot enough evidence?

Rarely. Auditors want the full population export with a date, the reviewer decisions, and proof that revocations were completed - not a cropped image of a user list.

Key takeaways

  • Access reviews are the most-sampled control in most audits.
  • Business owners review; IT supplies data and executes changes.
  • A decision per user, with a named approver and date, is the evidence.
  • Prove revocations actually happened - that is where most reviews fail.
#access-review #certification #least-privilege #identity #audit