Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Access Review Outcome Report Template

Reports campaign results in terms of risk removed and control weaknesses found rather than percentage completed.

Available soon

Format
Word
Size
61 KB
Length
17 pages
Version
1.0
Updated

What's inside

  • How to use this template
  • The report
  • Worked example — a completed report
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

How to use this template

Use this report to close every access review campaign at [[Organisation Name]]. One report covers one campaign. It says what the review removed, what should never have existed, how quickly removals were made, what the review found wrong with the processes that grant and remove access, and what management must decide. The Access Review Campaign Operating Procedure governs it; the rules (AR-nn) and measures (ARM-nn) are in the Access Review Methodology.

Guidance — delete before approval

Do not lead with "100% complete". Every entry must get a decision (AR-05), so completion says nothing about risk. Lead with what was removed and why it was there (AR-12).

Take every figure from the Access Review Campaign Workbook and the Access Review Findings & Revocation Tracker; do not retype them from memory. The totals in Part B must add up to the entries reviewed.

Part

Who completes it

When

A — Campaign and scope

Campaign coordinator

At close

B, C — Access removed; removals on time

Campaign coordinator

When every removal is confirmed against a fresh extract

D, E — Conflicts; quality signals

Campaign coordinator, with head of Information Security

Before the campaign is closed (AR-09)

F — Process weaknesses

Campaign coordinator, agreed with each process owner

Before the report is sent

G, H — What it means; decisions

Head of Information Security

Before the report is sent

I — Sign-off

Head of Information Security; the forum reported to

At the meeting the report goes to

Steps

  1. Close the campaign in the Access Review Campaign Workbook: every entry has a decision, and every Revoke and Modify is confirmed against a fresh extract in the Access Review Findings & Revocation Tracker.
  2. Complete Parts A to C from those two workbooks. Name every late removal and why.
  3. Complete Parts D and E with information security: the conflicts found and the quality checks run.
  4. Agree each process weakness with its owner, and a fix date, before the report goes out (Part F).
  5. Write Part G in plain words. Where a finding bears on a risk in the P05 Information Security Risk Register, name the risk and say whether its rating still holds.
  6. List the decisions needed (Part H), sign, and file the report with the campaign's evidence (Part I).

Field guidance

Field

What a good answer looks like

Common reason a report is returned

B Access removed

Counts per system that add up, with leavers, dormant and orphan accounts shown separately.

One total, with no system and no leavers.

C Late removals

Every late one named, with its due date, confirmation date and cause.

"A few were late".

E Quality signals

Each check stated, even when nothing was seen.

Blank: the reader cannot tell if the check was run.

F Process weaknesses

The cause, its owner and a date the owner agreed.

The finding repeated, with no cause and no owner.

G Risk view

What changed in the organisation's risk, linked to the risk register.

"The campaign went well; 100% complete".

H Decisions

A decision someone can take, with options.

"Management to note".

The report

Guidance — delete before approval

Replace the placeholders when you adopt the template, or leave them as prompts. Keep the measure names and targets identical to the Access Review Methodology.

Part A — Campaign and scope

Completed by the campaign coordinator from the Access Review Campaign Workbook.

A1 Campaign

Campaign ID

[[UAR-YYYY-Qn]]

Report date

as at

[[YYYY-MM-DD — today's date]]

Extract date

AR-03

[[YYYY-MM-DD]]

Decision deadline

removal windows start

[[YYYY-MM-DD]]

Close date

[[YYYY-MM-DD]]

Reported to

[[e.g. Executive Committee]]

Prepared by

[[Name, Campaign coordinator]]

ARM-01 reviews on time

target: all

[[n of N in-scope systems reviewed within their frequency]]

Systems in this campaign, from the Access Review Scope & System Inventory.

System

Name

Owner

Reviewed every

How access was extracted

[[SYS-nn]]

[[System]]

[[Role]]

[[3 / 6 / 12]] months

[[Export, report or supplier request]]

[[SYS-nn]]

[[System]]

[[Role]]

[[3 / 6 / 12]] months

[[Export, report or supplier request]]

Part B — Access removed

What the review took away. Leavers, dormant and orphan accounts are within Revoke; they are the access that should not have existed at all (ARM-03 access that should not have existed).

System

Reviewed

Keep

Modify

Revoke

Cannot decide

Removals

Leavers

Dormant

Orphan

[[SYS-nn]]

[[n]]

[[n]]

[[n]]

[[n]]

[[n]]

[[Modify + Revoke]]

[[n]]

[[n]]

[[n]]

Total

B1 Access that should not have existed (ARM-03)

Access that should not have existed

leaver + dormant + orphan

[[n accounts: n leavers, n dormant, n orphan — n% of entries reviewed]]

Against the last campaign

target: falling campaign on campaign

[[Up / down from n last campaign, and why]]

Part C — Removals confirmed on time

Every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. Windows count in working days from the decision deadline: 1 working day for privileged access, 5 working days for all other access (ARM-02 removals confirmed on time, target ≥ [[95%]]). A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract.

System

Removals

Confirmed on time

Late

On time

[[SYS-nn]]

[[n]]

[[n]]

[[n]]

[[n%]]

Total

[[n% — against the target]]

Every late removal, named: what it was, when it was due, removed and confirmed, and why it was late. Working days late count from the end of the window to the removal.

System

Late removal

Due

Removed

Confirmed

Days late

Why

[[SYS-nn]]

[[What was removed; privileged or standard]]

[[YYYY-MM-DD]]

[[YYYY-MM-DD]]

[[YYYY-MM-DD]]

[[n]]

[[Cause; the PW-nn it points to, if any]]

Part D — Segregation-of-duties conflicts

Leavers, dormant accounts and segregation-of-duties conflicts found in review must be raised as findings, not just removed. Each conflict is checked against the P02 Segregation of Duties Conflict Matrix; one that cannot be separated needs a compensating control and a P02 exception.

System

Who

Duties held together

P02 conflict and rating

Action

Removed / confirmed

[[SYS-nn]]

[[Role]]

[[Duty and duty]]

[[SOD-xx-nn, rating]]

[[Separated / mitigated with exception ref]]

[[YYYY-MM-DD / YYYY-MM-DD]]

Part E — Quality signals seen

Campaign quality must be checked for rubber-stamping before the campaign is closed. The check runs on day 17 of the campaign timetable in the Access Review Campaign Operating Procedure — after the decision deadline and before close — so a list re-reviewed because of it is re-decided in that time. State each check, whether it was seen, and what was done.

Signal

Seen?

What was done

A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting

[[No / Yes — where, how many]]

[[Sample taken, re-review, decision changed]]

Decisions made faster than [[5]] seconds each on average

[[No / Yes — where, how many]]

[[Sample taken, re-review, decision changed]]

Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep

[[No / Yes — where, how many]]

[[Sample taken, re-review, decision changed]]

Privileged or generic accounts marked Keep without a named owner

[[No / Yes — where, how many]]

[[Sample taken, re-review, decision changed]]

Part F — Process weaknesses

Findings that show a process weakness (for example, leavers not removed) must go to the owner of that process with a fix and a date. A weakness is the cause behind findings, not the findings themselves (ARM-04 process weaknesses open).

ID

Weakness

Owner

Fix due

Status

[[PW-nn]]

[[The process that failed, and the findings that show it]]

[[Process owner]]

[[YYYY-MM-DD]]

[[Open / Fixed]]

F1 Headline measures

ARM-02 removals confirmed on time

target ≥ [[95%]]

[[n of N (n%) — against the target; n late]]

ARM-04 process weaknesses open

target: zero past their date

[[n open, n past their date]]

Part G — What it means

Campaign results must be reported as risk removed and weaknesses found, not only as percentage completed. Write for a reader who will not open the workbook. Link each point to the risk it changes.

G1 Risk view (AR-12)

In three sentences

risk removed and weaknesses found

[[What was removed, what should never have existed, and why — not the percentage completed]]

Privileged access

P05 Information Security Risk Register

[[Privileged findings and late removals; the P05 risk they bear on, and whether its rating still holds]]

Leavers and dormant accounts

[[Where they were, and the process weakness behind them]]

Supplier-run systems

P06 Supplier Security Risk Register

[[Any supplier that could not meet the removal windows, and the effect]]

Segregation of duties

[[Conflicts found; separated or mitigated]]

Part H — Decisions needed

What the forum is asked to decide. Each decision has an owner; a decision not taken is recorded as not taken.

Ref

Decision needed

Owner

Outcome

[[DN-nn]]

[[What must be decided, and the options]]

[[Role]]

[[Agreed / not agreed — minute ref]]

Part I — Sign-off

Each campaign must keep an evidence file: scope, extracts, decisions, changes, confirmation and sign-off. This report closes the campaign's evidence file.

I1 Signatures

Prepared by

[[Name, Campaign coordinator]]

Signature and date

[[Signature, date]]

Reviewed by

Head of Information Security

[[Name, role]]

Signature and date

[[Signature, date]]

Accepted by

the forum reported to

[[Forum, chair]]

Meeting and minute

[[Date, minute reference]]

Evidence file

AR-10

[[Location / campaign ID]]

Worked example — a completed report

The report on campaign UAR-2026-Q3 for a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders. It uses the campaign's results exactly as in the other P07 documents; the organisation, roles and dates are fictional. The report date is fixed at 2026-09-30 so the example does not change; in your report, use today's date.

Guidance — delete before approval

How the figures are derived: removals are Modify plus Revoke (22 + 47 = 69); on time is removals less late (69 − 4 = 65, 94.2%); access that should not have existed is leavers plus dormant plus orphan (13 + 20 + 3 = 36). Due dates are the decision deadline, 2026-09-15, plus 1 working day (privileged, 2026-09-16) or 5 working days (all others, 2026-09-22).

Note what the report leads with: not that all 495 entries were decided, but that 36 accounts should never have existed and why. The 4 privileged ones are linked to P05 risk R-07 because they bear on the likelihood its owner assumed.

Delete this worked example from your adopted template.

Part A — Campaign and scope

Completed by the campaign coordinator from the Access Review Campaign Workbook.

A1 Campaign — EXAMPLE

Campaign ID

UAR-2026-Q3

Report date

as at

2026-09-30 (EXAMPLE — replace with today's date)

Extract date

AR-03

2026-09-01

Decision deadline

removal windows start

2026-09-15

Close date

2026-09-29

Reported to

Executive Committee

Prepared by

Information Security Manager (campaign coordinator)

ARM-01 reviews on time

target: all

5 of 5 in-scope systems reviewed within their frequency (target: all)

Systems in this campaign, from the Access Review Scope & System Inventory.

System

Name

Owner

Reviewed every

How access was extracted

SYS-01

ERP (hosted; P06 SUP-004)

Chief Financial Officer

6 months

Supplier-run user report, requested by ticket

SYS-02

Warehouse management system

Head of Logistics

6 months

Admin console export

SYS-03

Directory administrator groups

Head of IT

3 months

Group membership export

SYS-04

Online ordering admin console

Chief Operating Officer

3 months

Admin console export

SYS-05

Shared finance drive

Chief Financial Officer

12 months

Permissions report

Part B — Access removed

What the review took away. Leavers, dormant and orphan accounts are within Revoke; they are the access that should not have existed at all (ARM-03 access that should not have existed).

System

Reviewed

Keep

Modify

Revoke

Cannot decide

Removals

Leavers

Dormant

Orphan

SYS-01

164

139

11

12

2

23

3

6

1

SYS-02

212

188

6

18

0

24

7

9

0

SYS-03

14

10

1

3

0

4

1

0

1

SYS-04

9

7

0

2

0

2

0

1

1

SYS-05

96

80

4

12

0

16

2

4

0

Total

495

424

22

47

2

69

13

20

3

B1 Access that should not have existed (ARM-03) — EXAMPLE

Access that should not have existed

leaver + dormant + orphan

36 accounts: 13 leavers, 20 dormant, 3 orphan — 7.3% of the 495 entries reviewed

Against the last campaign

target: falling campaign on campaign

First campaign reported this way: these figures are the baseline for the next

Part C — Removals confirmed on time

Every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. Windows count in working days from the decision deadline: 1 working day for privileged access, 5 working days for all other access (ARM-02 removals confirmed on time, target ≥ [[95%]]). A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract.

System

Removals

Confirmed on time

Late

On time

SYS-01

23

20

3

87.0%

SYS-02

24

24

0

100.0%

SYS-03

4

4

0

100.0%

SYS-04

2

2

0

100.0%

SYS-05

16

15

1

93.8%

Total

69

65

4

94.2%

Every late removal, named: what it was, when it was due, removed and confirmed, and why it was late. Working days late count from the end of the window to the removal.

System

Late removal

Due

Removed

Confirmed

Days late

Why

SYS-01

Finance administrator role removed from 3 accounts (2 Modify, 1 Revoke) (privileged)

2026-09-16

2026-09-22

2026-09-23

4

The ERP provider (P06 SUP-004) acts on a removal ticket in 5 working days; privileged access must go in 1 (PW-02).

SYS-05

A leaver's access to the shared finance drive (Revoke) (standard)

2026-09-22

2026-09-24

2026-09-24

2

The access also came through a nested group. The fresh extract showed it still present, so it was removed a second time. A one-off: nested groups are now on the administrator's removal checklist.

Part D — Segregation-of-duties conflicts

Leavers, dormant accounts and segregation-of-duties conflicts found in review must be raised as findings, not just removed. Each conflict is checked against the P02 Segregation of Duties Conflict Matrix; one that cannot be separated needs a compensating control and a P02 exception.

System

Who

Duties held together

P02 conflict and rating

Action

Removed / confirmed

SYS-01

Accounts payable supervisor

Create or change suppliers and their bank details; approve payments

SOD-FI-01, rated High

Separated by a Modify; no exception. Supplier-maintenance permission removed. Raised as a finding (AR-08).

2026-09-22 / 2026-09-23

Part E — Quality signals seen

Campaign quality must be checked for rubber-stamping before the campaign is closed. The check runs on day 17 of the campaign timetable in the Access Review Campaign Operating Procedure — after the decision deadline and before close — so a list re-reviewed because of it is re-decided in that time. State each check, whether it was seen, and what was done.

Signal

Seen?

What was done

A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting

Yes — one SYS-02 reviewer kept all 38 entries in one sitting

Found in the quality check on 2026-09-24, after the decision deadline. Information security sampled 10 of the 38; the reviewer re-reviewed the whole list before close.

Decisions made faster than [[5]] seconds each on average

Yes — the same reviewer, about 3 seconds a decision

As above.

Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep

Yes — 2 dormant accounts in the same list, marked Keep

Found in the sample; corrected to Revoke in the re-review. The 2 are in SYS-02's Revoke and dormant counts.

Privileged or generic accounts marked Keep without a named owner

No

Every privileged and generic account kept has a named owner. SYS-04's orphan privileged account (j.harper, in the Access Review Campaign Workbook) was revoked by the reviewer, not kept.

Part F — Process weaknesses

Findings that show a process weakness (for example, leavers not removed) must go to the owner of that process with a fix and a date. A weakness is the cause behind findings, not the findings themselves (ARM-04 process weaknesses open).

ID

Weakness

Owner

Fix due

Status

PW-01

Warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner

HR Director

2026-11-30

Open

PW-02

The ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged

Chief Financial Officer

2026-12-15

Open

F1 Headline measures — EXAMPLE

ARM-02 removals confirmed on time

target ≥ [[95%]]

65 of 69 (94.2%) — below the 95% target; 4 late

ARM-04 process weaknesses open

target: zero past their date

2 open, 0 past their date (target: zero past their date)

Part G — What it means

Campaign results must be reported as risk removed and weaknesses found, not only as percentage completed. Write for a reader who will not open the workbook. Link each point to the risk it changes.

G1 Risk view (AR-12) — EXAMPLE

In three sentences

risk removed and weaknesses found

The review removed or reduced 69 pieces of access (47 revoked, 22 modified) out of 495 reviewed. 36 accounts should not have existed at all, 4 of them with administrator access. The main cause is a leaver process that does not reach the warehouse system (PW-01). Removals were 94.2% on time against 95%, ; of the 4 late removals, 3 were privileged ERP access the provider cannot remove fast enough (PW-02) and 1 was a standard SYS-05 removal missed through a nested group.

Privileged access

P05 Information Security Risk Register

4 privileged accounts that should not have existed on SYS-03 and SYS-04, and 3 privileged ERP removals made 4 working days after their window. P05 R-07 administrator misuses privileged access — owner Head of IT; residual impact 3 Major, likelihood 1 Unlikely, score 3 (Low). The likelihood rating assumes privileged access is kept to people who need it; this campaign shows it was not, until now (DN-02).

Leavers and dormant accounts

13 leavers still had access, 7 of them on SYS-02, the warehouse management system. Removing them fixes this quarter; PW-01 fixes the cause.

Supplier-run systems

P06 Supplier Security Risk Register

The ERP (SYS-01, P06 SUP-004) is run by a supplier whose removal time is longer than our window for privileged access. Until PW-02 is fixed, privileged ERP access stays for up to 4 working days longer than it should after a decision (DN-01).

Segregation of duties

1 High conflict (P02 SOD-FI-01) found and separated by a Modify, removed 2026-09-22 and confirmed on the fresh extract 2026-09-23. No compensating control or exception is needed.

Part H — Decisions needed

What the forum is asked to decide. Each decision has an owner; a decision not taken is recorded as not taken.

Ref

Decision needed

Owner

Outcome

DN-01

Agree a 1-working-day removal time for privileged ERP access with the ERP provider (P06 SUP-004), or approve a P02 exception with a compensating control until the contract is changed (PW-02).

Chief Financial Officer

[[Agreed / not agreed — minute ref]]

DN-02

Reassess P05 risk R-07 (administrator misuses privileged access): the review found privileged accounts that should not have existed, so the control its rating relies on was weaker than assumed.

Head of IT

[[Agreed / not agreed — minute ref]]

DN-03

Approve the next campaign: privileged and administrator access, extract on 2026-12-01.

Head of Information Security

[[Agreed / not agreed — minute ref]]

Part I — Sign-off

Each campaign must keep an evidence file: scope, extracts, decisions, changes, confirmation and sign-off. This report closes the campaign's evidence file.

I1 Signatures — EXAMPLE

Prepared by

Information Security Manager (campaign coordinator)

Signature and date

Signed, 2026-09-30

Reviewed by

Head of Information Security

Head of Information Security

Signature and date

Signed, 2026-09-30

Accepted by

the forum reported to

Executive Committee, chaired by [[Chief Executive]]

Meeting and minute

[[Meeting date and minute reference]]

Evidence file

AR-10

[[Evidence file location]] / UAR-2026-Q3

Related documents

Document

Relationship

Access Review Methodology

The rules (AR-01 to AR-12) and measures (ARM-01 to ARM-04) this report applies

Access Review Campaign Operating Procedure

The procedure that governs this report

Access Review Scope & System Inventory

The systems in scope, their owners and frequency (Part A)

Access Review Campaign Workbook

Decisions per system (Part B)

Access Review Findings & Revocation Tracker

Removals, confirmation dates and findings (Parts B to D)

Access Review Evidence & Audit File Checklist

The evidence file this report closes (Part I)

Reviewer Instruction Pack & Campaign Communications

The closure note that tells reviewers what the campaign found

P02 Segregation of Duties Conflict Matrix

Conflicts found in review (Part D)

P05 Information Security Risk Register

The risks a finding bears on (Part G)

P06 Supplier Security Risk Register

Suppliers that run in-scope systems and their removal times (Part G)

Adapting this template

Guidance — delete before approval

Small organisation: Parts A, B, C, F and I on one or two pages are enough; keep Part C's list of late removals even if it is one line. Where the person who ran the campaign is also the one who reviews the report, have it accepted by a director who did not review access in the campaign.

Regulated entity: NIS2 Article 21(2)(i) expects access control to be applied and its effectiveness assessed; this report is that assessment for each campaign. Under DORA Article 9(4)(c) and Delegated Regulation (EU) 2024/1774 Article 21(e), show in Part A that systems supporting critical or important functions were reviewed within six months and others within a year, and in Part C that access was removed without undue delay; report generic and shared accounts found (Article 21(c)). For PCI DSS, show in Part A that user accounts in scope, including third-party accounts, were reviewed within six months (7.2.4) and application and system accounts at the frequency your targeted risk analysis sets (7.2.5.1), and in Part B that inactive accounts were removed or disabled within 90 days (8.2.6).

IT run by a service provider: the provider's extracts and removal times drive Parts A and C. Report its late removals by name, as the EXAMPLE does for the ERP provider (PW-02), and take them to the supplier review in the P06 Supplier Security Risk Register rather than absorbing them.

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Clause 9.1 — Monitoring, measurement, analysis and evaluation

Parts B, C and F1: the headline measures ARM-01 to ARM-04, measured and evaluated each campaign

ISO/IEC 27001:2022

Annex A 5.18 — Access rights

Parts B to D: access rights reviewed, removed and confirmed

NIST CSF 2.0

ID.IM-01 — “Improvements are identified from evaluations”

Parts F and H: improvements identified from the campaign, with owners and dates

NIST CSF 2.0

PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties”

Parts B and D: least privilege and separation of duties reviewed and enforced

DORA — Delegated Regulation (EU) 2024/1774

Article 21(e) — account management: roles for granting, reviewing and revoking access; privileged access on a need-to-use basis; removal without undue delay; review at least every six months for systems supporting critical or important functions and at least yearly for others

Parts A and C: review frequency by system, and removal without undue delay

NIS2 — Directive (EU) 2022/2555

Article 21(2)(i) — “human resources security, access control policies and asset management”

Part G: the effectiveness of access control assessed and reported

Definitions

Term

Meaning in this report

Access that should not have existed

Leaver, dormant and orphan accounts found in the campaign (ARM-03).

Dormant account

An account with no sign-in for more than [[90]] calendar days, or never used.

Late removal

A removal is late when the access is removed after its window, which counts from the decision deadline (or from the quality check, for a decision the quality check changed); every removal is then confirmed against a fresh extract.

Leaver

Someone who has left the organisation, or whose contract has ended, but still has access.

Orphan account

An account that matches no current person and has no named owner.

Process weakness

The cause behind findings, such as a leaver notice that does not reach a system owner; sent to that process's owner with a fix and a date (AR-11).

Removal window

The time allowed to carry out a Revoke or Modify, from the decision deadline: 1 working day for privileged access, 5 working days for all other access.

Removals

Modify plus Revoke decisions.

Segregation-of-duties conflict

One person holding two duties that should be split, so they could make and hide a wrong change or payment.

AR-nn, ARM-nn, PW-nn

Rule and measure numbers in the Access Review Methodology; process weaknesses (PW-nn) numbered campaign by campaign in this report.