Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Access Review Findings & Revocation Tracker

Tracks every revoke decision through to confirmed removal, which is the evidence auditors actually test.

Available soon

Format
Excel
Size
123 KB
Length
11 sheets
Version
1.0
Updated

What's inside

  • Instructions
  • Removals
  • System Totals
  • Process Weaknesses
  • Summary
  • Lists
  • Definitions
  • Framework References

Preview

The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.

Instructions

How to use this workbook

StepWhat to do
1Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30; replace it with today's date, or type =TODAY() to keep it current. Due dates, status and lateness are measured against it. Enter your public holidays on the Lists sheet so working days are counted correctly.
2At the decision deadline, copy columns B to L of the Access Review Campaign Workbook's Removals Export and paste them as values into the Removals sheet from the Removal ID column. Each row is one Revoke or Modify: every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract.
3Check the Privileged column: Yes for any entry on a privileged system and any privileged account. The window and Removal due then calculate: 1 working day for privileged access and 5 working days for other access, counted from the campaign's decision deadline (AR-07).
4Send each change to the system administrator ([[IT operations, or the supplier's support team]]) as a ticket and enter its number. When the administrator reports the access removed, enter Removed on.
5Take a fresh extract from the system after the removals (the EXAMPLE takes it on 2026-09-23). Look for every removed entry in it. When it is gone, enter Confirmed on and the extract's reference. Only a confirmed removal counts towards ARM-02.
6Raise every leaver, dormant or orphan account and every segregation-of-duties conflict as a finding (AR-08): record where it was raised in Finding raised. A conflict is handled with the P02 Segregation of Duties Conflict Matrix and, if it must stay, a P02 exception.
7Where findings show that a process is broken (for example, leavers not removed), add a process weakness on the Process Weaknesses sheet with its owner, a fix and a date (AR-11), and put its PW number on the removals it explains.
8Clear every Record check that does not say OK. Before the close date, every row should be Confirmed. Rows with a Late flag stay late after they are confirmed: explain each in Notes.
9Report the Summary figures in the Access Review Outcome Report Template as risk removed and weaknesses found, not only as percentage complete (AR-12). File this tracker with the fresh extracts in the campaign's evidence file (AR-10; Access Review Evidence & Audit File Checklist). Delete the EXAMPLE rows on every sheet before use.

Legend

Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.

EXAMPLERows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval.

Status: Open (not yet removed, still within its window); Late (not removed and past its due date); Removed, not confirmed; Confirmed. The Late flag shows any row removed after its due date or still open past it, even once confirmed.

EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. Campaign UAR-2026-Q3: decisions due 2026-09-15, fresh extracts on 2026-09-23, closed 2026-09-29; as at 2026-09-30.

Sample plus totals. The Removals sheet holds every removal in a real campaign. To keep the EXAMPLE readable, only the privileged systems SYS-03 and SYS-04 are there in full (their 4 and 2 Revoke and Modify decisions, all confirmed on time). The other systems (SYS-01, SYS-02, SYS-05) are counts on the System Totals sheet, with their late removals: SYS-01 3 (finance administrator role removed from 3 accounts (2 Modify, 1 Revoke)); SYS-05 1 (a leaver's access to the shared finance drive (Revoke)). The Summary adds the two: 69 removals, 4 late, 94.2% on time against a target of ≥ 95%.

In the EXAMPLE, SYS-03 holds the administrator groups linked to P05 risk R-07 (administrator misuses privileged access), and SYS-01 is the hosted ERP run by P06 supplier SUP-004, whose 5-working-day turnaround is PW-02.

Tailoring — small organisation: one sheet row per removal is enough; the ticket can be an email reference. Still take the fresh extract: it is the only proof the access has gone.

Tailoring — regulated entity: DORA Art 9(4)(c) expects access limited to what is required, with sound administration of access rights, and Delegated Regulation 2024/1774 Art 21(e) expects rights removed without undue delay; this tracker is that evidence. PCI DSS 8.2.6 expects inactive accounts removed or disabled within 90 days: dormant accounts on cardholder data systems belong here with their confirmation.

Tailoring — IT run by a service provider: the provider makes the change, so put its ticket number here and its turnaround in the contract. Where it cannot meet your windows, record a process weakness with the manager of that contract as owner (the EXAMPLE's PW-02).

Removals

One row per Revoke or Modify, pasted from the Access Review Campaign Workbook's Removals Export. Yellow columns are inputs; white columns calculate. Every colour sits beside a word.

ExampleRemoval IDCampaignEntry IDSystem IDAccountPersonDecisionTypePrivilegedDecided onDecision deadlineWindow, working days (calc)Removal due (calc)TicketRemoved onConfirmed onFresh extract referenceStatus (calc)Late flag (calc)Working days late (calc)Finding raised (AR-08)Process weakness (PW ID)Record check (calc)Notes
EXAMPLEUAR-2026-Q3-R01UAR-2026-Q3S03-05SYS-03adm-dmorganDan MorganModifyExcess permissionYes8 Sep 202615 Sep 2026116 Sep 2026IT-248179 Sep 202623 Sep 2026SYS-03 extract 2026-09-23ConfirmedNot neededOK
EXAMPLEUAR-2026-Q3-R02UAR-2026-Q3S03-12SYS-03adm-kwalshKieran WalshRevokeLeaverYes8 Sep 202615 Sep 2026116 Sep 2026IT-248189 Sep 202623 Sep 2026SYS-03 extract 2026-09-23ConfirmedYesOKLeaver's administrator account missed at leaving; raised with HR and the Head of IT.
EXAMPLEUAR-2026-Q3-R03UAR-2026-Q3S03-13SYS-03adm-migrationNo match in HRRevokeOrphanYes8 Sep 202615 Sep 2026116 Sep 2026IT-248199 Sep 202623 Sep 2026SYS-03 extract 2026-09-23ConfirmedYesOKOrphan administrator account; raised with the Head of IT. Linked to P05 R-07.
EXAMPLEUAR-2026-Q3-R04UAR-2026-Q3S03-14SYS-03adm-rpatelRavi PatelRevokeNo longer neededYes8 Sep 202615 Sep 2026116 Sep 2026IT-248209 Sep 202623 Sep 2026SYS-03 extract 2026-09-23ConfirmedNot neededOK
EXAMPLEUAR-2026-Q3-R05UAR-2026-Q3S04-08SYS-04marta.silvaMarta SilvaRevokeDormantYes10 Sep 202615 Sep 2026116 Sep 2026IT-2484111 Sep 202623 Sep 2026SYS-04 extract 2026-09-23ConfirmedYesOKDormant since April; raised with the Chief Operating Officer.
EXAMPLEUAR-2026-Q3-R06UAR-2026-Q3S04-09SYS-04j.harperNo match in HRRevokeOrphanYes10 Sep 202615 Sep 2026116 Sep 2026IT-2484211 Sep 202623 Sep 2026SYS-04 extract 2026-09-23ConfirmedYesOKOrphan console account; raised with the Chief Operating Officer.

System Totals

Counts for a system whose removals are tracked elsewhere (a supplier's ticket system, say). The Summary adds them to the Removals sheet. Never enter a system on both.

ExampleSystem IDRevokeModifyRemoved lateNot yet confirmed (not late)LeaversDormantOrphanSoD conflictsLate removals: what and whyWhere the detail is keptCheck (calc)
EXAMPLESYS-011211303611Finance administrator role removed from 3 accounts (2 Modify, 1 Revoke), privileged access; removed 2026-09-22, confirmed 2026-09-23. The ERP provider (P06 SUP-004) acts on a removal ticket in 5 working days; privileged access must go in 1 (PW-02).EXAMPLE: the ERP provider's ticket history (P06 SUP-004) and its fresh user report. The SoD conflict: the accounts payable supervisor (P02 SOD-FI-01, High); separated by a Modify; no exception: requested 2026-09-15, removed 2026-09-22, confirmed 2026-09-23.OK
EXAMPLESYS-02186007900None.EXAMPLE: IT operations tickets and the fresh console export. The 7 leavers led to PW-01.OK
EXAMPLESYS-05124102400A leaver's access to the shared finance drive (Revoke), standard access; removed 2026-09-24, confirmed 2026-09-24. The access also came through a nested group. The fresh extract showed it still present, so it was removed a second time. A one-off: nested groups are now on the administrator's removal checklist.EXAMPLE: IT operations tickets and the fresh permissions report.OK

Process Weaknesses

Findings that show a process is broken, sent to that process's owner with a fix and a date (AR-11). ARM-04 counts those still open.

ExamplePW IDWeakness foundSystem IDFound in campaignProcess ownerFix agreedDueStatusFixed onEvidence the fix worksRemovals linked (calc)Calendar days to due (calc)Past due (calc)
EXAMPLEPW-01Warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its ownerSYS-02UAR-2026-Q3HR Director[[e.g. HR adds the warehouse system owner to the leaver notice; checked monthly]]30 Nov 2026Open061
EXAMPLEPW-02The ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privilegedSYS-01UAR-2026-Q3Chief Financial Officer[[e.g. contract change: privileged removals within 1 working day; interim: disable the account ourselves the same day]]15 Dec 2026Open076

Summary

Tracker summary

Every figure is calculated from the Removals, System Totals and Process Weaknesses sheets as at the date shown. Report them in the Access Review Outcome Report Template (AR-12).

As-at date30 Sep 2026EXAMPLE date. Replace it with today's date, or type =TODAY() to keep it current.
ARM-02 target95%From the Access Review Methodology: ≥ 95% of removals confirmed within their window.
Removal window: privileged (working days)1From the campaign's decision deadline (AR-07).
Removal window: other access (working days)5From the campaign's decision deadline (AR-07).
ARM-03 at the last campaign[[number]]Type the last campaign's figure to see whether access that should not have existed is falling.

Removals by system

System IDSystemRemovals on the trackerTyped removalsRemovalsRemoved lateNot yet confirmedConfirmed on timeOn time (%)ARM-03 accountsSoD conflicts
SYS-01ERP (hosted; P06 SUP-004)02323302087.0%101
SYS-02Warehouse management system024240024100.0%160
SYS-03Directory administrator groups404004100.0%20
SYS-04Online ordering admin console202002100.0%20
SYS-05Shared finance drive01616101593.8%60
All systems66369406594.2%361

EXAMPLE: SYS-03 and SYS-04 from the Removals sheet, the others from the System Totals sheet. System IDs are yellow: list the systems in the campaign.

Headline measures (AR-12)

MeasureResultTargetStatusWhat it means
ARM-02 Removals confirmed on time94.2%≥ [[95%]]Below targetRevoke and Modify decisions confirmed removed within their window, out of all such decisions. 4 of 69 were late in the EXAMPLE.
ARM-03 Access that should not have existed36Falling campaign on campaignEnter last campaignLeaver, dormant and orphan accounts found in the campaign. Each is raised as a finding (AR-08).
ARM-04 Process weaknesses open2Zero past their dateOn targetFindings sent to a process owner (AR-11) not yet fixed. Past their due date: shown on the Process Weaknesses sheet.
Removals late (flag)40Explain eachRemoved after the due date, or still not removed past it. Explain each in Notes.
Rows with a record check to resolve00On targetAny row on the Removals sheet whose Record check does not say OK.

Removals by type (tracker rows)

TypeRowsOf which lateFinding needed (AR-08)
Leaver10Yes
Dormant10Yes
Orphan20Yes
Excess permission10No
SoD conflict00Yes
No longer needed10No

Typed systems are not broken down by type; their leavers, dormant and orphan accounts and conflicts are in the table above.

Lists

RemovalDecisionRemovalTypeYesNoFindingRaisedPWStatusSysIdListSysNameListHolidays
RevokeLeaverYesYesOpenSYS-01ERP (hosted; P06 SUP-004)
ModifyDormantNoNot neededFixedSYS-02Warehouse management system
OrphanSYS-03Directory administrator groups
Excess permissionSYS-04Online ordering admin console
SoD conflictSYS-05Shared finance drive

No longer needed

Yellow: your public holidays (dates). Working days skip them.

Definitions

Definitions

TermMeaning in this workbook
RemovalA Revoke or Modify decision from an access review, carried out as a change to the system.
Removal IDThe campaign ID and a number, for example UAR-2026-Q3-R01. It comes from the Access Review Campaign Workbook.
TypeLeaver, dormant or orphan (together ARM-03); excess permission (a Modify that removes permissions the job does not need); SoD conflict (two duties one person should not hold, P02 Segregation of Duties Conflict Matrix); no longer needed (a Revoke that is none of these, such as a mover's old access).
PrivilegedYes for any entry on a system whose scope is privileged and administrator access, and any privileged account.
Decision deadlineThe campaign's deadline for decisions. Removal windows are counted from it.
Removal window1 working day for privileged access and 5 working days for other access, counted from the campaign's decision deadline (AR-07). Working days are Monday to Friday, less the holidays on the Lists sheet.
Removal dueThe decision deadline plus the window, in working days.
Fresh extractA new list of who has access, taken from the system after the removals. A removal is confirmed when its entry is no longer in it (AR-07).
StatusOpen: not removed, within its window. Late: not removed, past its due date. Removed, not confirmed: the administrator reports it done but no fresh extract shows it yet. Confirmed: the fresh extract shows it gone.
Late flagA removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract. Late: removed after its due date, or not removed and past it. The flag stays after the removal is confirmed.
FindingLeavers, dormant accounts and segregation-of-duties conflicts found in review must be raised as findings, not just removed. Record where it was raised: to whom and when, in Notes.
Process weaknessFindings that show a process weakness (for example, leavers not removed) must go to the owner of that process with a fix and a date. Numbered PW-nn.
ARM-02Removals confirmed on time: revoke and Modify decisions confirmed removed within their window, out of all such decisions. Target ≥ 95%.
ARM-03Access that should not have existed: leaver, dormant and orphan accounts found in the campaign. Target: falling campaign on campaign.
ARM-04Process weaknesses open: findings sent to a process owner (AR-11) not yet fixed. Target: zero past their date.
Typed totalsCounts for a system whose removals are tracked elsewhere. Used in the EXAMPLE for SYS-01, SYS-02, SYS-05.
As-at dateThe date status and lateness are measured against. Set on the Summary sheet.
EXAMPLE rowA worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, campaign UAR-2026-Q3, as at 2026-09-30. People and tickets are fictional. Delete before use.
AR-nn, ARM-nn, SYS-nn, PW-nnRule, measure, system and process weakness numbers in the Access Review Methodology and the pack's EXAMPLE.
(calc)A column or cell the workbook calculates. Do not type or paste over it.

Framework References

Framework references

These references indicate relevance only and do not reproduce the text of any standard.

FrameworkReferenceSupported by
ISO/IEC 27001:2022Annex A 5.18 — Access rightsEvery Revoke and Modify tracked to a confirmed removal
ISO/IEC 27001:2022Annex A 8.2 — Privileged access rightsPrivileged removals: 1-working-day window, late flag
NIST CSF 2.0PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties”Excess permissions and SoD conflicts removed and confirmed
DORA — Delegated Regulation (EU) 2024/1774Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for othersRemoval due, late flag and confirmation: access removed without undue delay
PCI DSS v4.0.1Requirement 8.2.6 — inactive user accounts removed or disabled within 90 daysDormant accounts removed and confirmed against a fresh extract
DORA — Regulation (EU) 2022/2554Article 9(4)(c) — policies that limit access to information and ICT assets to what is required for legitimate and approved functions, with controls that ensure sound administration of access rightsARM-02 and the Process Weaknesses sheet: evidence that access rights are soundly administered

Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1