User Access Review Pack — Guide
- Version 1.0
- Updated
- Next review
User Access Review Pack
A manager receives a list of 200 accounts, half of them named after roles nobody recognises. The deadline is Friday, so everything is approved in four minutes. Nobody checks the few removals requested. This pack helps you run an access review that produces genuine decisions, not bulk approvals under time pressure.
Is this for you?
This pack is for you if:
- reviewers approve whole lists without opening them;
- you cannot show that a removal was actually made;
- leavers and administrator accounts turn up in audits.
How often
| Access | Every | Why |
|---|---|---|
| Privileged and administrator access, all systems | 3 months | The access that can do most harm, and changes most often |
| Systems supporting a critical service | 6 months | Regulated minimum for these systems |
| All other in-scope systems | 12 months | Regulated minimum for all other systems |
The regulated minimums: six months for systems supporting a DORA critical or important function or cardholder data in PCI DSS scope; a year for the rest.
Four decisions, and no default
Every entry gets one of four decisions (AR-05): Keep, Modify, Revoke or Cannot decide. Line managers judge need; system owners judge permissions.
“Cannot decide” beats a guess. A reviewer who does not know the person or the permission passes it to the system owner within two working days. It never becomes Keep by default, and neither does silence. Nobody reviews their own access (AR-04).
What a rubber stamp looks like
Before closing a campaign, check for the signs (AR-09):
- a reviewer keeps every entry of a list longer than 25 in one sitting;
- decisions average under five seconds each;
- leavers, or accounts with no sign-in for 90 days, are marked Keep;
- privileged or generic accounts are kept without a named owner.
The evidence auditors test
Auditors pick a Revoke and ask to see that the access is gone. The proof is a fresh extract, taken after the change, that no longer shows it (AR-07). Privileged access must go within one working day of the decision, other access within five.
Start with these three
- Access Review Scope & System Inventory — every system, its owner and how to extract who has access.
- Access Review Methodology — the twelve rules, the frequencies and the four decisions.
- Access Review Campaign Workbook — one campaign’s extracts and decisions, system by system.
Your first campaign
Day 0 is the extract date; list systems and owners before it.
| Working days | What to do | You’re done when |
|---|---|---|
| 0–1 | Take every extract on one stated date; check it is complete. | Each list shows names, roles, permissions and last sign-in. |
| 2 | Assign reviewers and launch. | Nobody has their own access to review. |
| 3–10 | Reviewers decide; chase the silent. | Every entry has a decision by day 10. |
| 11–20 | Remove, confirm against a fresh extract, check quality and close. | Removals are confirmed; the evidence file is signed off. |
Four numbers to report
| Number | Target |
|---|---|
| Systems reviewed within their frequency | All |
| Removals confirmed within their window | 95% or more |
| Leaver, dormant and orphan accounts found | Falling campaign on campaign |
| Process weaknesses open | None past their date |
Report risk removed and weaknesses found, not just percentage completed (AR-12). A process weakness, such as leavers never removed, goes to that process’s owner with a fix and a date (AR-11). Privileged access findings belong in the risk register. A segregation-of-duties conflict is handled with the exceptions pack’s conflict matrix.
Everything in the pack
| Document | What it does | Format |
|---|---|---|
| Access Review Methodology | The rules management approves | Word |
| Access Review Campaign Operating Procedure | From extract to sign-off | Word |
| Access Review Scope & System Inventory | Systems, owners and frequencies | Excel |
| Reviewer Instruction Pack & Campaign Communications | What reviewers are told, and when | Word |
| Access Review Campaign Workbook | Every entry and its decision | Excel |
| Access Review Findings & Revocation Tracker | Removals, confirmations and findings | Excel |
| Access Review Evidence & Audit File Checklist | What the evidence file must hold | Excel |
| Access Review Outcome Report Template | Results for management | Word |
Adapting it
- Small organisation: start with administrator access and your one or two critical systems.
- Regulated entity: NIS2 Article 21(2)(i) names access control policies. DORA Article 9(4)(c) limits access to what approved functions require; RTS Article 21(e) sets review at least every six months for systems supporting critical or important functions and yearly for others. PCI DSS Requirement 7.2.4 asks for a six-monthly review of user accounts in scope, third-party accounts included.
- Access managed by an IT provider or SaaS vendor: you still decide; they make the change. Agree extracts and removal times, then confirm their removals against a fresh extract.
Where it maps
- ISO/IEC 27001:2022 — Annex A 5.18 and 8.2.
- NIST CSF 2.0 — PR.AA-05.
- NIS2 — Article 21(2)(i).
- DORA — Article 9(4)(c); Delegated Regulation (EU) 2024/1774, Article 21(e).
- PCI DSS v4.0.1 — Requirement 7.2.4.