Access Review Findings & Revocation Tracker
Tracks every revoke decision through to confirmed removal, which is the evidence auditors actually test.
Available soon
- Format
- Excel
- Size
- 123 KB
- Length
- 11 sheets
- Version
- 1.0
- Updated
What's inside
- Instructions
- Removals
- System Totals
- Process Weaknesses
- Summary
- Lists
- Definitions
- Framework References
Preview
The workbook's sheets as you will receive them, with its example rows and the values its formulas calculate. Highlighted [[text]] is for you to replace; rows marked EXAMPLE are for you to delete. Wide sheets scroll sideways. The cover, document control and changelog sheets are in the file.
Instructions
How to use this workbook
| Step | What to do |
|---|---|
| 1 | Set the As-at date on the Summary sheet. The EXAMPLE uses 2026-09-30; replace it with today's date, or type =TODAY() to keep it current. Due dates, status and lateness are measured against it. Enter your public holidays on the Lists sheet so working days are counted correctly. |
| 2 | At the decision deadline, copy columns B to L of the Access Review Campaign Workbook's Removals Export and paste them as values into the Removals sheet from the Removal ID column. Each row is one Revoke or Modify: every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. |
| 3 | Check the Privileged column: Yes for any entry on a privileged system and any privileged account. The window and Removal due then calculate: 1 working day for privileged access and 5 working days for other access, counted from the campaign's decision deadline (AR-07). |
| 4 | Send each change to the system administrator ([[IT operations, or the supplier's support team]]) as a ticket and enter its number. When the administrator reports the access removed, enter Removed on. |
| 5 | Take a fresh extract from the system after the removals (the EXAMPLE takes it on 2026-09-23). Look for every removed entry in it. When it is gone, enter Confirmed on and the extract's reference. Only a confirmed removal counts towards ARM-02. |
| 6 | Raise every leaver, dormant or orphan account and every segregation-of-duties conflict as a finding (AR-08): record where it was raised in Finding raised. A conflict is handled with the P02 Segregation of Duties Conflict Matrix and, if it must stay, a P02 exception. |
| 7 | Where findings show that a process is broken (for example, leavers not removed), add a process weakness on the Process Weaknesses sheet with its owner, a fix and a date (AR-11), and put its PW number on the removals it explains. |
| 8 | Clear every Record check that does not say OK. Before the close date, every row should be Confirmed. Rows with a Late flag stay late after they are confirmed: explain each in Notes. |
| 9 | Report the Summary figures in the Access Review Outcome Report Template as risk removed and weaknesses found, not only as percentage complete (AR-12). File this tracker with the fresh extracts in the campaign's evidence file (AR-10; Access Review Evidence & Audit File Checklist). Delete the EXAMPLE rows on every sheet before use. |
Legend
Yellow cells are inputs. Everything else is calculated or fixed — do not overwrite formulas.
| EXAMPLE | Rows marked EXAMPLE in the first column show how a completed row looks. Delete them before approval. |
Status: Open (not yet removed, still within its window); Late (not removed and past its due date); Removed, not confirmed; Confirmed. The Late flag shows any row removed after its due date or still open past it, even once confirmed.
EXAMPLE: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. Campaign UAR-2026-Q3: decisions due 2026-09-15, fresh extracts on 2026-09-23, closed 2026-09-29; as at 2026-09-30.
Sample plus totals. The Removals sheet holds every removal in a real campaign. To keep the EXAMPLE readable, only the privileged systems SYS-03 and SYS-04 are there in full (their 4 and 2 Revoke and Modify decisions, all confirmed on time). The other systems (SYS-01, SYS-02, SYS-05) are counts on the System Totals sheet, with their late removals: SYS-01 3 (finance administrator role removed from 3 accounts (2 Modify, 1 Revoke)); SYS-05 1 (a leaver's access to the shared finance drive (Revoke)). The Summary adds the two: 69 removals, 4 late, 94.2% on time against a target of ≥ 95%.
In the EXAMPLE, SYS-03 holds the administrator groups linked to P05 risk R-07 (administrator misuses privileged access), and SYS-01 is the hosted ERP run by P06 supplier SUP-004, whose 5-working-day turnaround is PW-02.
Tailoring — small organisation: one sheet row per removal is enough; the ticket can be an email reference. Still take the fresh extract: it is the only proof the access has gone.
Tailoring — regulated entity: DORA Art 9(4)(c) expects access limited to what is required, with sound administration of access rights, and Delegated Regulation 2024/1774 Art 21(e) expects rights removed without undue delay; this tracker is that evidence. PCI DSS 8.2.6 expects inactive accounts removed or disabled within 90 days: dormant accounts on cardholder data systems belong here with their confirmation.
Tailoring — IT run by a service provider: the provider makes the change, so put its ticket number here and its turnaround in the contract. Where it cannot meet your windows, record a process weakness with the manager of that contract as owner (the EXAMPLE's PW-02).
Removals
One row per Revoke or Modify, pasted from the Access Review Campaign Workbook's Removals Export. Yellow columns are inputs; white columns calculate. Every colour sits beside a word.
| Example | Removal ID | Campaign | Entry ID | System ID | Account | Person | Decision | Type | Privileged | Decided on | Decision deadline | Window, working days (calc) | Removal due (calc) | Ticket | Removed on | Confirmed on | Fresh extract reference | Status (calc) | Late flag (calc) | Working days late (calc) | Finding raised (AR-08) | Process weakness (PW ID) | Record check (calc) | Notes |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | UAR-2026-Q3-R01 | UAR-2026-Q3 | S03-05 | SYS-03 | adm-dmorgan | Dan Morgan | Modify | Excess permission | Yes | 8 Sep 2026 | 15 Sep 2026 | 1 | 16 Sep 2026 | IT-24817 | 9 Sep 2026 | 23 Sep 2026 | SYS-03 extract 2026-09-23 | Confirmed | Not needed | OK | ||||
| EXAMPLE | UAR-2026-Q3-R02 | UAR-2026-Q3 | S03-12 | SYS-03 | adm-kwalsh | Kieran Walsh | Revoke | Leaver | Yes | 8 Sep 2026 | 15 Sep 2026 | 1 | 16 Sep 2026 | IT-24818 | 9 Sep 2026 | 23 Sep 2026 | SYS-03 extract 2026-09-23 | Confirmed | Yes | OK | Leaver's administrator account missed at leaving; raised with HR and the Head of IT. | |||
| EXAMPLE | UAR-2026-Q3-R03 | UAR-2026-Q3 | S03-13 | SYS-03 | adm-migration | No match in HR | Revoke | Orphan | Yes | 8 Sep 2026 | 15 Sep 2026 | 1 | 16 Sep 2026 | IT-24819 | 9 Sep 2026 | 23 Sep 2026 | SYS-03 extract 2026-09-23 | Confirmed | Yes | OK | Orphan administrator account; raised with the Head of IT. Linked to P05 R-07. | |||
| EXAMPLE | UAR-2026-Q3-R04 | UAR-2026-Q3 | S03-14 | SYS-03 | adm-rpatel | Ravi Patel | Revoke | No longer needed | Yes | 8 Sep 2026 | 15 Sep 2026 | 1 | 16 Sep 2026 | IT-24820 | 9 Sep 2026 | 23 Sep 2026 | SYS-03 extract 2026-09-23 | Confirmed | Not needed | OK | ||||
| EXAMPLE | UAR-2026-Q3-R05 | UAR-2026-Q3 | S04-08 | SYS-04 | marta.silva | Marta Silva | Revoke | Dormant | Yes | 10 Sep 2026 | 15 Sep 2026 | 1 | 16 Sep 2026 | IT-24841 | 11 Sep 2026 | 23 Sep 2026 | SYS-04 extract 2026-09-23 | Confirmed | Yes | OK | Dormant since April; raised with the Chief Operating Officer. | |||
| EXAMPLE | UAR-2026-Q3-R06 | UAR-2026-Q3 | S04-09 | SYS-04 | j.harper | No match in HR | Revoke | Orphan | Yes | 10 Sep 2026 | 15 Sep 2026 | 1 | 16 Sep 2026 | IT-24842 | 11 Sep 2026 | 23 Sep 2026 | SYS-04 extract 2026-09-23 | Confirmed | Yes | OK | Orphan console account; raised with the Chief Operating Officer. |
System Totals
Counts for a system whose removals are tracked elsewhere (a supplier's ticket system, say). The Summary adds them to the Removals sheet. Never enter a system on both.
| Example | System ID | Revoke | Modify | Removed late | Not yet confirmed (not late) | Leavers | Dormant | Orphan | SoD conflicts | Late removals: what and why | Where the detail is kept | Check (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | SYS-01 | 12 | 11 | 3 | 0 | 3 | 6 | 1 | 1 | Finance administrator role removed from 3 accounts (2 Modify, 1 Revoke), privileged access; removed 2026-09-22, confirmed 2026-09-23. The ERP provider (P06 SUP-004) acts on a removal ticket in 5 working days; privileged access must go in 1 (PW-02). | EXAMPLE: the ERP provider's ticket history (P06 SUP-004) and its fresh user report. The SoD conflict: the accounts payable supervisor (P02 SOD-FI-01, High); separated by a Modify; no exception: requested 2026-09-15, removed 2026-09-22, confirmed 2026-09-23. | OK |
| EXAMPLE | SYS-02 | 18 | 6 | 0 | 0 | 7 | 9 | 0 | 0 | None. | EXAMPLE: IT operations tickets and the fresh console export. The 7 leavers led to PW-01. | OK |
| EXAMPLE | SYS-05 | 12 | 4 | 1 | 0 | 2 | 4 | 0 | 0 | A leaver's access to the shared finance drive (Revoke), standard access; removed 2026-09-24, confirmed 2026-09-24. The access also came through a nested group. The fresh extract showed it still present, so it was removed a second time. A one-off: nested groups are now on the administrator's removal checklist. | EXAMPLE: IT operations tickets and the fresh permissions report. | OK |
Process Weaknesses
Findings that show a process is broken, sent to that process's owner with a fix and a date (AR-11). ARM-04 counts those still open.
| Example | PW ID | Weakness found | System ID | Found in campaign | Process owner | Fix agreed | Due | Status | Fixed on | Evidence the fix works | Removals linked (calc) | Calendar days to due (calc) | Past due (calc) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| EXAMPLE | PW-01 | Warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner | SYS-02 | UAR-2026-Q3 | HR Director | [[e.g. HR adds the warehouse system owner to the leaver notice; checked monthly]] | 30 Nov 2026 | Open | 0 | 61 | |||
| EXAMPLE | PW-02 | The ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged | SYS-01 | UAR-2026-Q3 | Chief Financial Officer | [[e.g. contract change: privileged removals within 1 working day; interim: disable the account ourselves the same day]] | 15 Dec 2026 | Open | 0 | 76 |
Summary
Tracker summary
Every figure is calculated from the Removals, System Totals and Process Weaknesses sheets as at the date shown. Report them in the Access Review Outcome Report Template (AR-12).
| As-at date | 30 Sep 2026 | EXAMPLE date. Replace it with today's date, or type =TODAY() to keep it current. | |
| ARM-02 target | 95% | From the Access Review Methodology: ≥ 95% of removals confirmed within their window. | |
| Removal window: privileged (working days) | 1 | From the campaign's decision deadline (AR-07). | |
| Removal window: other access (working days) | 5 | From the campaign's decision deadline (AR-07). | |
| ARM-03 at the last campaign | [[number]] | Type the last campaign's figure to see whether access that should not have existed is falling. | |
Removals by system
| System ID | System | Removals on the tracker | Typed removals | Removals | Removed late | Not yet confirmed | Confirmed on time | On time (%) | ARM-03 accounts | SoD conflicts |
|---|---|---|---|---|---|---|---|---|---|---|
| SYS-01 | ERP (hosted; P06 SUP-004) | 0 | 23 | 23 | 3 | 0 | 20 | 87.0% | 10 | 1 |
| SYS-02 | Warehouse management system | 0 | 24 | 24 | 0 | 0 | 24 | 100.0% | 16 | 0 |
| SYS-03 | Directory administrator groups | 4 | 0 | 4 | 0 | 0 | 4 | 100.0% | 2 | 0 |
| SYS-04 | Online ordering admin console | 2 | 0 | 2 | 0 | 0 | 2 | 100.0% | 2 | 0 |
| SYS-05 | Shared finance drive | 0 | 16 | 16 | 1 | 0 | 15 | 93.8% | 6 | 0 |
| All systems | 6 | 63 | 69 | 4 | 0 | 65 | 94.2% | 36 | 1 |
|---|
EXAMPLE: SYS-03 and SYS-04 from the Removals sheet, the others from the System Totals sheet. System IDs are yellow: list the systems in the campaign.
Headline measures (AR-12)
| Measure | Result | Target | Status | What it means | ||||||
|---|---|---|---|---|---|---|---|---|---|---|
| ARM-02 Removals confirmed on time | 94.2% | ≥ [[95%]] | Below target | Revoke and Modify decisions confirmed removed within their window, out of all such decisions. 4 of 69 were late in the EXAMPLE. | ||||||
| ARM-03 Access that should not have existed | 36 | Falling campaign on campaign | Enter last campaign | Leaver, dormant and orphan accounts found in the campaign. Each is raised as a finding (AR-08). | ||||||
| ARM-04 Process weaknesses open | 2 | Zero past their date | On target | Findings sent to a process owner (AR-11) not yet fixed. Past their due date: shown on the Process Weaknesses sheet. | ||||||
| Removals late (flag) | 4 | 0 | Explain each | Removed after the due date, or still not removed past it. Explain each in Notes. | ||||||
| Rows with a record check to resolve | 0 | 0 | On target | Any row on the Removals sheet whose Record check does not say OK. | ||||||
Removals by type (tracker rows)
| Type | Rows | Of which late | Finding needed (AR-08) | |
|---|---|---|---|---|
| Leaver | 1 | 0 | Yes | |
| Dormant | 1 | 0 | Yes | |
| Orphan | 2 | 0 | Yes | |
| Excess permission | 1 | 0 | No | |
| SoD conflict | 0 | 0 | Yes | |
| No longer needed | 1 | 0 | No | |
Typed systems are not broken down by type; their leavers, dormant and orphan accounts and conflicts are in the table above.
Lists
| RemovalDecision | RemovalType | YesNo | FindingRaised | PWStatus | SysIdList | SysNameList | Holidays |
|---|---|---|---|---|---|---|---|
| Revoke | Leaver | Yes | Yes | Open | SYS-01 | ERP (hosted; P06 SUP-004) | |
| Modify | Dormant | No | Not needed | Fixed | SYS-02 | Warehouse management system | |
| Orphan | SYS-03 | Directory administrator groups | |||||
| Excess permission | SYS-04 | Online ordering admin console | |||||
| SoD conflict | SYS-05 | Shared finance drive |
No longer needed
Yellow: your public holidays (dates). Working days skip them.
Definitions
Definitions
| Term | Meaning in this workbook |
|---|---|
| Removal | A Revoke or Modify decision from an access review, carried out as a change to the system. |
| Removal ID | The campaign ID and a number, for example UAR-2026-Q3-R01. It comes from the Access Review Campaign Workbook. |
| Type | Leaver, dormant or orphan (together ARM-03); excess permission (a Modify that removes permissions the job does not need); SoD conflict (two duties one person should not hold, P02 Segregation of Duties Conflict Matrix); no longer needed (a Revoke that is none of these, such as a mover's old access). |
| Privileged | Yes for any entry on a system whose scope is privileged and administrator access, and any privileged account. |
| Decision deadline | The campaign's deadline for decisions. Removal windows are counted from it. |
| Removal window | 1 working day for privileged access and 5 working days for other access, counted from the campaign's decision deadline (AR-07). Working days are Monday to Friday, less the holidays on the Lists sheet. |
| Removal due | The decision deadline plus the window, in working days. |
| Fresh extract | A new list of who has access, taken from the system after the removals. A removal is confirmed when its entry is no longer in it (AR-07). |
| Status | Open: not removed, within its window. Late: not removed, past its due date. Removed, not confirmed: the administrator reports it done but no fresh extract shows it yet. Confirmed: the fresh extract shows it gone. |
| Late flag | A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract. Late: removed after its due date, or not removed and past it. The flag stays after the removal is confirmed. |
| Finding | Leavers, dormant accounts and segregation-of-duties conflicts found in review must be raised as findings, not just removed. Record where it was raised: to whom and when, in Notes. |
| Process weakness | Findings that show a process weakness (for example, leavers not removed) must go to the owner of that process with a fix and a date. Numbered PW-nn. |
| ARM-02 | Removals confirmed on time: revoke and Modify decisions confirmed removed within their window, out of all such decisions. Target ≥ 95%. |
| ARM-03 | Access that should not have existed: leaver, dormant and orphan accounts found in the campaign. Target: falling campaign on campaign. |
| ARM-04 | Process weaknesses open: findings sent to a process owner (AR-11) not yet fixed. Target: zero past their date. |
| Typed totals | Counts for a system whose removals are tracked elsewhere. Used in the EXAMPLE for SYS-01, SYS-02, SYS-05. |
| As-at date | The date status and lateness are measured against. Set on the Summary sheet. |
| EXAMPLE row | A worked example: a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, campaign UAR-2026-Q3, as at 2026-09-30. People and tickets are fictional. Delete before use. |
| AR-nn, ARM-nn, SYS-nn, PW-nn | Rule, measure, system and process weakness numbers in the Access Review Methodology and the pack's EXAMPLE. |
| (calc) | A column or cell the workbook calculates. Do not type or paste over it. |
Framework References
Framework references
These references indicate relevance only and do not reproduce the text of any standard.
| Framework | Reference | Supported by |
|---|---|---|
| ISO/IEC 27001:2022 | Annex A 5.18 — Access rights | Every Revoke and Modify tracked to a confirmed removal |
| ISO/IEC 27001:2022 | Annex A 8.2 — Privileged access rights | Privileged removals: 1-working-day window, late flag |
| NIST CSF 2.0 | PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties” | Excess permissions and SoD conflicts removed and confirmed |
| DORA — Delegated Regulation (EU) 2024/1774 | Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others | Removal due, late flag and confirmation: access removed without undue delay |
| PCI DSS v4.0.1 | Requirement 8.2.6 — inactive user accounts removed or disabled within 90 days | Dormant accounts removed and confirmed against a fresh extract |
| DORA — Regulation (EU) 2022/2554 | Article 9(4)(c) — policies that limit access to information and ICT assets to what is required for legitimate and approved functions, with controls that ensure sound administration of access rights | ARM-02 and the Process Weaknesses sheet: evidence that access rights are soundly administered |
Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1