Reviewer Instruction Pack & Campaign Communications
Equips reviewers to make real decisions by telling them what they are looking at, what to question and what happens after they click.
Available soon
- Format
- Word
- Size
- 62 KB
- Length
- 22 pages
- Version
- 1.0
- Updated
What's inside
- Purpose and audience
- Reviewer guide
- Quick card
- Campaign communications
- Required inputs with owners
- Questions and escalations log
- Related documents
- Adapting this template
- Framework references
- Definitions
Preview
The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.
Purpose and audience
An access review is only as good as the decisions reviewers make. This pack gives reviewers what they need to make real ones — what they are looking at, what to question and what happens after they decide — and gives the campaign coordinator [[e.g. Information Security Manager]] the messages that run a campaign from launch to close.
It is used with the Access Review Campaign Operating Procedure, which sets the campaign steps, and the Access Review Campaign Workbook, where reviewers record their decisions. The rules it quotes (AR-nn) are in the Access Review Methodology.
Part | Audience | Use |
|---|---|---|
Reviewer guide | Reviewers: line managers and system owners | Read once before the first campaign; sent with every launch email |
Quick card | Every reviewer | One page to keep open while reviewing |
Campaign communications | Campaign coordinator | Seven messages, each on its day of the campaign timetable, as a template and as an EXAMPLE |
Required inputs; questions and escalations log | Campaign coordinator | What must be ready before launch, and the record of what reviewers asked |
Guidance — delete before approval
Send the reviewer guide as it stands, with your placeholders filled in. Keep it short: a reviewer who has to read ten pages will not. The quick card is what most reviewers will actually use.
The EXAMPLE messages are for a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, running campaign UAR-2026-Q3 (extract 2026-09-01, decisions due 2026-09-15, closed 2026-09-29). The organisation, roles and figures are fictional.
Reviewer guide
You have been asked to review who has access to one or more of our systems. For each entry, decide whether that person still needs that access for the job they do today. It takes most reviewers about [[30]] minutes for [[40]] entries. Your decisions are acted on: access you revoke is removed.
What you are looking at
Your list is an extract from the system, taken on a stated date, with one row for each account and its permissions. The extract must be complete and taken on a stated date; the reviewer must see names, roles, permissions and last sign-in.
Column | What it shows |
|---|---|
Entry ID | A unique number for the row. Quote it in any question. |
Person | The name the account belongs to, taken from HR records — or "No match in HR" if the account matches nobody. |
Job title and department | The person's current job, from HR, on the extract date. |
Employment status | Active, leaver (with leaving date), on long-term leave, contractor (with end date), third party, or "No match in HR". |
Account | The user name in the system. |
Account type | Personal, privileged (administrator), generic or shared, service (used by software, not a person), or third-party (a supplier's staff). |
Permissions | The roles or groups the account holds, in the system's own words, with a plain description where the system gives one. |
Last sign-in | The date the account last signed in, and the number of calendar days since the extract date. Blank means never. |
Decision | Where you choose Keep, Modify, Revoke or Cannot decide. |
Reason | Required for Modify, Revoke and Cannot decide: what should change, or what you do not know. |
If a column is missing or clearly wrong — for example, every last sign-in is blank — stop and tell the campaign coordinator. A decision made on a wrong extract is not a decision.
The four decisions
Every entry must get one of the four decisions; nothing is kept by default when a reviewer does not answer. Choose one of these for every entry:
Decision | What it means | Example |
|---|---|---|
Keep | Access is needed and the permissions are right. | A warehouse team leader with pick-and-dispatch permissions in the warehouse management system, who signed in yesterday. |
Modify | Access is needed but some permissions are not: remove the excess. | An accounts assistant who moved to credit control still holds the supplier-payments role in the ERP. Keep the account; remove the payments role. Say which permission goes in the Reason column. |
Revoke | Access is not needed: remove it. | A picker who left in July still has a warehouse system account: Employment status shows leaver. |
Cannot decide | The reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default. | An account called "scanner-03" that you do not recognise. Say so in the Reason column; the system owner (for the warehouse system, the Head of Logistics) decides. |
Guidance — delete before approval
Replace the examples with ones from your own systems. Keep one per decision: reviewers remember an example better than a definition.
What to question
Most access that should not exist hides in five places. Look for each one on every list.
Look for | How it shows in your list | What to do |
|---|---|---|
Leavers | Employment status: leaver; or Person: "No match in HR". | Revoke. It will also be raised as a finding (AR-08) so the leaver process can be fixed; you have done nothing wrong by finding it. |
Dormant accounts | Last sign-in more than [[90]] calendar days before the extract date, or blank. | Revoke, unless there is a known reason — long-term leave, seasonal work — and then Keep with that reason written in. |
Access that does not fit the role | Permissions that do not match the job title or department, or that belong to a job the person used to do. | Modify: remove what does not fit. If you do not know what a permission does, choose Cannot decide. |
Privileged and generic accounts | Account type: privileged, generic or shared, or service. | Keep only if a named person owns it and it is still needed. Privileged, generic and service accounts must each have a named owner and must be reviewed by the system owner and information security. |
Segregation-of-duties conflicts | One person who can both set something up and approve it — for example, create or change a supplier's bank details and also approve payments. | Modify, and say in the Reason column which two permissions clash. Information security checks it against the P02 Segregation of Duties Conflict Matrix. |
What happens after you decide
Every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. Removal windows count in working days from the campaign's decision date.
Your decision | What happens | By when |
|---|---|---|
Keep | Nothing changes. Information security samples Keep decisions for quality. | — |
Modify or Revoke, privileged access | The system administrator removes the permission or the account; the removal is confirmed against a fresh extract. | 1 working day from the decision date |
Modify or Revoke, all other access | As above. | 5 working days from the decision date |
Cannot decide | The entry goes to the system owner, who decides it. | [[2]] working days |
Leaver, dormant, no owner, conflict | Removed as above, and also raised as a finding (AR-08). If it shows a process is failing, that process's owner gets a fix and a date (AR-11). | With the removal |
You will not be asked to confirm removals yourself. You may be asked why you chose a decision: the Reason column is your answer.
Why "Keep all" is noticed
Campaign quality must be checked for rubber-stamping before the campaign is closed. Before a campaign closes, information security looks for these signs of a review that was clicked through rather than done:
- A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting
- Decisions made faster than [[5]] seconds each on average
- Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep
- Privileged or generic accounts marked Keep without a named owner
Being noticed is not an accusation. Information security looks at a sample of your decisions and may ask you to look again. A list where everything genuinely should be kept is fine — say so in the Reason column for the entries that looked doubtful.
You never review your own access
Nobody may review their own access or the access of anyone who reviews theirs. If your own name, or the name of someone who reviews your access, appears on your list, do not decide that entry. Tell the campaign coordinator and it will be reassigned. The same applies to an account you use but that is not in your name, such as a shared administrator account.
Your deadline, and who to ask
Decide every entry by [[decision deadline]]. Your manager is copied on the second reminder. Entries without a decision are not kept by default: at the deadline they go to the system owner to decide, and then to the Head of Information Security, and you are named in the campaign report. Questions go to [[access-review mailbox or named contact]].
Quick card
One page for every reviewer. Print it, or attach it to the launch email. Replace the placeholders first.
Access review — quick card | [[Campaign ID]] · decide by [[decision deadline]] |
|---|---|
Your job | For each entry: does this person still need this access for the job they do today? |
Decide | Keep — access is needed and the permissions are right. Modify — access is needed but some permissions are not: remove the excess. Revoke — access is not needed: remove it. Cannot decide — the reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default. |
Question | • Leavers, and anyone with no match in HR • No sign-in for more than [[90]] days, or never • Permissions that do not fit the job title or department • Privileged, generic and shared accounts: who owns them? • One person who can both set up and approve the same thing |
Then | Revoke and Modify are carried out within 1 working day (privileged) or 5 working days (all others), and checked against a fresh extract. |
Never | Keep something because you are unsure — choose Cannot decide. Decide your own access, or the access of anyone who reviews yours. Keep a whole list in one go without looking. |
Help | [[access-review mailbox or named contact]] |
Campaign communications
Seven messages run a campaign. Each has a template, with placeholders, and an EXAMPLE for UAR-2026-Q3. Each is sent on a day of the campaign timetable in the Access Review Campaign Operating Procedure, counted in working days from the extract date (day 0); change the days there, and here to match.
Timeline
EXAMPLE dates are for UAR-2026-Q3: extract 2026-09-01 (day 0), decision deadline 2026-09-15 (day 10), close 2026-09-29 (day 20).
Message | When | To | From | EXAMPLE date |
|---|---|---|---|---|
Launch email | Day [[2]] | Every reviewer | Campaign coordinator | 2026-09-03 |
First reminder | Day [[5]] | Reviewers with entries still open | Campaign coordinator | 2026-09-08 |
Second reminder | Day [[8]] | Reviewers with entries still open, copied to each one's own manager | Campaign coordinator | 2026-09-11 |
Removals note to system owners | Day [[10]], the decision deadline | Each system owner and system administrator | Campaign coordinator | 2026-09-15 |
Unanswered entries to the system owner | Day [[10]], the decision deadline | The system owner, for entries left without a decision at the deadline | Campaign coordinator | 2026-09-15 |
Escalation to the Head of Information Security | Day [[12]] | Head of Information Security, for entries the system owner has not decided | Campaign coordinator | 2026-09-17 — not needed |
Thank-you and closure note | Day [[20]], close | Every reviewer and system owner | Campaign coordinator | 2026-09-29 |
Guidance — delete before approval
Send from a named person, not a no-reply address: reviewers answer the person, and their answers are part of the campaign's record.
Keep every message sent, with its date and recipients, in the campaign's evidence file (AR-10). The escalations and the removals notes are what an auditor asks for first.
Where the removal windows (1 working day privileged, 5 working days other) cannot be met by a system's administrator — often a supplier-run system — agree that before launch, not after the decision date.
Launch email
Sent to every reviewer once the extracts are loaded and checked. It carries the reviewer guide, or the quick card, as an attachment.
Template | Launch email |
|---|---|
When | Day [[2]] — working days from the extract date (day 0) |
To | [[Reviewer name]] |
From | [[Name]], Campaign coordinator |
Subject | Action needed by [[decision deadline, e.g. Tuesday 15 September]]: review who has access to [[System name(s)]] ([[Campaign ID]]) |
Message | Dear [[Reviewer name]], You are asked to review [[n]] entries: the people who have access to [[System name(s)]], as recorded on [[extract date]]. For each entry, decide whether that person still needs that access for the job they do today. What to do 1. Open your list: [[where the review is done: the workbook, tool or form, and how to open it]]. 2. Give every entry one decision: Keep, Modify, Revoke or Cannot decide. For anything other than Keep, say why in the Reason column. 3. Finish by [[decision deadline, e.g. Tuesday 15 September]]. Most reviewers need about [[30]] minutes for [[40]] entries. Look hard at leavers, accounts not used for more than [[90]] days, access that does not fit the person's job, administrator and shared accounts, and anyone who can both set something up and approve it. What happens next: every Revoke and Modify is carried out within 1 working day for administrator access and 5 working days for everything else, then checked. If you do not know a person or a permission, choose Cannot decide — do not keep it to be safe. If your own name is on your list, do not decide it: tell us and it will be reassigned. The one-page reviewer guide is attached. Questions: [[access-review mailbox or named contact]]. Thank you, [[Name]], Campaign coordinator |
EXAMPLE — UAR-2026-Q3 | Launch email |
|---|---|
When | Thursday 3 September 2026 (day 2) |
To | Warehouse Manager, North site |
From | [[Name]], Information Security Manager (Campaign coordinator) |
Subject | Action needed by Tuesday 15 September 2026: review who has access to the warehouse management system (SYS-02) (UAR-2026-Q3) |
Message | Dear Warehouse Manager, North site, You are asked to review 41 entries: the people who have access to the warehouse management system (SYS-02), as recorded on Tuesday 1 September 2026. For each entry, decide whether that person still needs that access for the job they do today. What to do 1. Open your list: [[Access Review Campaign Workbook — your tab, on the shared site]]. 2. Give every entry one decision: Keep, Modify, Revoke or Cannot decide. For anything other than Keep, say why in the Reason column. 3. Finish by Tuesday 15 September 2026. Most reviewers need about [[30]] minutes for [[40]] entries. Look hard at leavers, accounts not used for more than [[90]] days, access that does not fit the person's job, administrator and shared accounts, and anyone who can both set something up and approve it. What happens next: every Revoke and Modify is carried out within 1 working day for administrator access and 5 working days for everything else, then checked. If you do not know a person or a permission, choose Cannot decide — do not keep it to be safe. If your own name is on your list, do not decide it: tell us and it will be reassigned. The one-page reviewer guide is attached. Questions: [[access-review mailbox or named contact]]. Thank you, [[Name]], Information Security Manager (Campaign coordinator) |
First reminder
Sent only to reviewers with entries still open. Give the number: it is more persuasive than a general reminder.
Template | First reminder |
|---|---|
When | Day [[5]] — working days from the extract date (day 0) |
To | [[Reviewer name]] |
From | [[Name]], Campaign coordinator |
Subject | Reminder: [[n]] access-review entries still open, due [[decision deadline, e.g. Tuesday 15 September]] ([[Campaign ID]]) |
Message | Dear [[Reviewer name]], [[n]] of your [[n]] entries for [[System name(s)]] have no decision yet. The deadline is [[decision deadline, e.g. Tuesday 15 September]]. An entry without a decision is not kept by default: it is escalated. Please finish your list: [[where the review is done: the workbook, tool or form, and how to open it]]. If you are unsure about an entry, choose Cannot decide and say what you do not know. It goes to the system owner, and it counts as done for you. Questions: [[access-review mailbox or named contact]]. Thank you, [[Name]], Campaign coordinator |
EXAMPLE — UAR-2026-Q3 | First reminder |
|---|---|
When | Tuesday 8 September 2026 (day 5) |
To | Warehouse Manager, North site |
From | [[Name]], Information Security Manager (Campaign coordinator) |
Subject | Reminder: 23 access-review entries still open, due Tuesday 15 September 2026 (UAR-2026-Q3) |
Message | Dear Warehouse Manager, North site, 23 of your 41 entries for the warehouse management system (SYS-02) have no decision yet. The deadline is Tuesday 15 September 2026. An entry without a decision is not kept by default: it is escalated. Please finish your list: [[Access Review Campaign Workbook — your tab, on the shared site]]. If you are unsure about an entry, choose Cannot decide and say what you do not know. It goes to the system owner, and it counts as done for you. Questions: [[access-review mailbox or named contact]]. Thank you, [[Name]], Information Security Manager (Campaign coordinator) |
Second reminder
To reviewers with entries still open, copied to each one's own manager. It says what happens after the deadline, plainly.
Template | Second reminder |
|---|---|
When | Day [[8]] — working days from the extract date (day 0) |
To | [[Reviewer name]]; copy [[Reviewer's manager]] |
From | [[Name]], Campaign coordinator |
Subject | Second reminder: your access review is due [[decision deadline, e.g. Tuesday 15 September]] ([[Campaign ID]]) |
Message | Dear [[Reviewer name]], [[n]] of your [[n]] entries for [[System name(s)]] still have no decision, and the deadline is [[decision deadline, e.g. Tuesday 15 September]]. Your manager, [[Reviewer's manager]], is copied. Entries still open at the deadline go to the system owner to decide, and then to the Head of Information Security; you are named in the campaign report. Nothing is kept without a decision. It usually takes under a minute an entry. The quick card attached lists what to look for. [[Name]], Campaign coordinator |
EXAMPLE — UAR-2026-Q3 | Second reminder |
|---|---|
When | Friday 11 September 2026 (day 8) |
To | Warehouse Manager, North site; copy Head of Logistics |
From | [[Name]], Information Security Manager (Campaign coordinator) |
Subject | Second reminder: your access review is due Tuesday 15 September 2026 (UAR-2026-Q3) |
Message | Dear Warehouse Manager, North site, 14 of your 41 entries for the warehouse management system (SYS-02) still have no decision, and the deadline is Tuesday 15 September 2026. Your manager, Head of Logistics, is copied. Entries still open at the deadline go to the system owner to decide, and then to the Head of Information Security; you are named in the campaign report. Nothing is kept without a decision. It usually takes under a minute an entry. The quick card attached lists what to look for. [[Name]], Information Security Manager (Campaign coordinator) |
Removals note to system owners
Sent on the decision date to each system owner, with the list of Revoke and Modify decisions for their system from the Access Review Campaign Workbook. The removal windows start today.
Template | Removals note to system owners |
|---|---|
When | Day [[10]], the decision deadline — working days from the extract date (day 0) |
To | [[System owner]]; copy [[system administrator]] |
From | [[Name]], Campaign coordinator |
Subject | Access to remove on [[System name]]: privileged by [[decision date + 1 working day]], all others by [[decision date + 5 working days]] ([[Campaign ID]]) |
Message | Dear [[System owner]], Reviewers' decisions for [[System name]] are in. The attached list has [[n]] Revoke and [[n]] Modify decisions to carry out, [[n]] of them privileged. Deadlines count from today, the decision date: privileged access by [[decision date + 1 working day]] (1 working day); everything else by [[decision date + 5 working days]] (5 working days). Please: 1. Pass the list to [[IT operations, or the supplier's support team]] today. 2. Record the date each change was made against its Entry ID. 3. When the last change is made, send us a fresh extract, so that every removal can be confirmed against it. 4. Tell us at once if a change cannot be made in time, so it is tracked rather than missed. Also yours to decide: [[n]] Cannot decide entries, by [[decision date + 2 working days]]. Leavers, dormant accounts, accounts with no owner and segregation-of-duties conflicts are raised as findings as well as removed; you will hear about any on your system separately. [[Anything particular to this system, e.g. the supplier runs removals and needs a ticket]] [[Name]], Campaign coordinator |
EXAMPLE — UAR-2026-Q3 | Removals note to system owners |
|---|---|
When | Tuesday 15 September 2026 (day 10, the decision deadline) |
To | Chief Financial Officer; copy Head of IT |
From | [[Name]], Information Security Manager (Campaign coordinator) |
Subject | Access to remove on the ERP (SYS-01): privileged by Wednesday 16 September 2026, all others by Tuesday 22 September 2026 (UAR-2026-Q3) |
Message | Dear Chief Financial Officer, Reviewers' decisions for the ERP (SYS-01) are in. The attached list has 12 Revoke and 11 Modify decisions to carry out, 3 of them privileged. Deadlines count from today, the decision date: privileged access by Wednesday 16 September 2026 (1 working day); everything else by Tuesday 22 September 2026 (5 working days). Please: 1. Pass the list to the ERP provider's support team (P06 SUP-004), by ticket today. 2. Record the date each change was made against its Entry ID. 3. When the last change is made, send us a fresh extract, so that every removal can be confirmed against it. 4. Tell us at once if a change cannot be made in time, so it is tracked rather than missed. Also yours to decide: 2 Cannot decide entries, by Thursday 17 September 2026. Leavers, dormant accounts, accounts with no owner and segregation-of-duties conflicts are raised as findings as well as removed; you will hear about any on your system separately. SYS-01 is run by the ERP provider (P06 SUP-004). Its removals are made by ticket: raise the tickets today, and ask the provider to confirm each removal the day it is made. The 3 privileged removals (finance administrator roles) are due in 1 working day. [[Name]], Information Security Manager (Campaign coordinator) |
Unanswered entries to the system owner
The first step of the escalation ladder in the Access Review Campaign Operating Procedure: entries still without a decision at the deadline go to the system owner, who decides them within [[2]] working days. Short and factual.
Template | Unanswered entries to the system owner |
|---|---|
When | Day [[10]], the decision deadline — working days from the extract date (day 0) |
To | [[System owner]]; copy [[Reviewer name]] and [[Reviewer's manager]] |
From | [[Name]], Campaign coordinator |
Subject | [[n]] unanswered access-review entries for you to decide by [[decision date + 2 working days]] ([[Campaign ID]]) |
Message | Dear [[System owner]], [[Reviewer name]] left [[n]] entries for [[System name(s)]] without a decision at the deadline, [[decision deadline, e.g. Tuesday 15 September]]. As the system owner, they are now yours to decide, by [[decision date + 2 working days]]. The list is attached. Access without a decision cannot be kept by default, and until it is decided, people who should no longer have access may still have it. Anything still undecided on [[decision date + 2 working days]] goes to the Head of Information Security, who decides it or has the access [[suspended]] until someone does. The reviewer is named in the campaign report. [[Name]], Campaign coordinator |
EXAMPLE — UAR-2026-Q3 | Unanswered entries to the system owner |
|---|---|
When | Tuesday 15 September 2026 (day 10, the decision deadline) |
To | Head of Logistics; copy Warehouse Manager, North site |
From | [[Name]], Information Security Manager (Campaign coordinator) |
Subject | 14 unanswered access-review entries for you to decide by Thursday 17 September 2026 (UAR-2026-Q3) |
Message | Dear Head of Logistics, Warehouse Manager, North site left 14 entries for the warehouse management system (SYS-02) without a decision at the deadline, Tuesday 15 September 2026. As the system owner, they are now yours to decide, by Thursday 17 September 2026. The list is attached. Access without a decision cannot be kept by default, and until it is decided, people who should no longer have access may still have it. Anything still undecided on Thursday 17 September 2026 goes to the Head of Information Security, who decides it or has the access [[suspended]] until someone does. The reviewer is named in the campaign report. [[Name]], Information Security Manager (Campaign coordinator) |
Escalation to the Head of Information Security
The second step: anything the system owner has not decided by then goes to the Head of Information Security, who decides it or has the access suspended until someone does.
Template | Escalation to the Head of Information Security |
|---|---|
When | Day [[12]] — working days from the extract date (day 0) |
To | Head of Information Security; copy [[System owner]] |
From | [[Name]], Campaign coordinator |
Subject | Access-review entries still undecided: [[System name(s)]] ([[Campaign ID]]) |
Message | Dear Head of Information Security, [[n]] entries for [[System name(s)]], left without a decision by [[Reviewer name]] at the deadline and passed to [[System owner]], were still undecided on [[decision date + 2 working days]]. The list is attached. Please decide them, or have the access [[suspended]] until someone does. The reviewer will be named in the campaign report. [[Name]], Campaign coordinator |
EXAMPLE: not sent in UAR-2026-Q3. The Head of Logistics decided all 14 of the Warehouse Manager, North site's unanswered entries on 2026-09-16, before day 12 (2026-09-17).
Thank-you and closure note
Sent when the campaign is closed. It is the follow-up to the campaign: it reports what the review found, not only that it finished (AR-12), so reviewers see that their decisions mattered. The figures come from the Access Review Outcome Report Template.
Template | Thank-you and closure note |
|---|---|
When | Day [[20]], close — working days from the extract date (day 0) |
To | [[All reviewers and system owners in the campaign]] |
From | [[Name]], Campaign coordinator |
Subject | Access review [[Campaign ID]] is closed — what it found, and thank you |
Message | Dear colleagues, Thank you. [[n]] entries across [[n]] systems were reviewed, and every one has a decision. What it found: [[n]] pieces of access removed or reduced ([[n]] revoked, [[n]] modified). [[n]] accounts should not have existed at all — leavers, accounts unused for more than [[90]] days and accounts with no owner. [[n]] person could both set up and approve the same transaction. Removals: every one has been checked against a fresh extract. [[n]] were made later than their deadline; the report explains why. What changes: [[The process weaknesses found, each with its owner and date — or "none"]]. Next: [[date of the next campaign, and what it covers]]. The full results go to [[management forum]] in the Access Review Outcome Report. [[Name]], Campaign coordinator |
EXAMPLE — UAR-2026-Q3 | Thank-you and closure note |
|---|---|
When | Tuesday 29 September 2026 (day 20, close) |
To | All reviewers and system owners in the campaign |
From | [[Name]], Information Security Manager (Campaign coordinator) |
Subject | Access review UAR-2026-Q3 is closed — what it found, and thank you |
Message | Dear colleagues, Thank you. 495 entries across 5 systems were reviewed, and every one has a decision. What it found: 69 pieces of access removed or reduced (47 revoked, 22 modified). 36 accounts should not have existed at all — leavers, accounts unused for more than [[90]] days and accounts with no owner. 1 person could both set up and approve the same transaction. Removals: every one has been checked against a fresh extract. 4 were made later than their deadline; the report explains why. What changes: PW-01: warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner (owner: HR Director, due 2026-11-30); PW-02: the ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged (owner: Chief Financial Officer, due 2026-12-15). Next: the next campaign, for privileged and administrator access (reviewed every 3 months), starts with an extract on Tuesday 1 December 2026. The full results go to [[management forum]] in the Access Review Outcome Report. [[Name]], Information Security Manager (Campaign coordinator) |
Guidance — delete before approval
The EXAMPLE closure note quotes the campaign's own results: 495 entries reviewed; 69 removals (47 revoked, 22 modified); 36 leaver, dormant or orphan accounts; 1 segregation-of-duties conflict; 4 removals late. The process weaknesses are PW-01 and PW-02.
Required inputs with owners
What must be ready before the launch email is sent, and what each later message needs.
Input | Needed for | Owner |
|---|---|---|
The systems in scope, their owners and frequency (Access Review Scope & System Inventory) | Launch | Campaign coordinator |
One extract per system, complete and taken on a stated date (AR-03) | Launch | System administrator [[IT operations, or the supplier's support team]] |
Joiner, mover and leaver data at the extract date, matched to the extract | Launch: the Employment status column | HR [[for joiner, mover and leaver data]] |
Reviewer for each entry, checked so that nobody reviews their own access (AR-04) | Launch | Campaign coordinator |
The reviewer lists in the Access Review Campaign Workbook | Launch, reminders | Campaign coordinator |
Open entries per reviewer | Reminders, escalations | Campaign coordinator |
Each reviewer's manager | Second reminder (copied) | HR |
Revoke, Modify and Cannot decide lists by system | Removals note | Campaign coordinator |
The administrator for each system, and how removals are requested | Removals note | System owner |
Campaign results and process weaknesses (Access Review Outcome Report Template) | Closure note | Campaign coordinator |
Questions and escalations log
Reviewers' questions, reassignments, escalations and Cannot decide referrals, each with an owner and a date. Keep it with the campaign's evidence file (AR-10); the findings themselves go to the Access Review Findings & Revocation Tracker.
Ref | Date | From | Entries | Question or issue | Action | Owner | Due |
|---|---|---|---|---|---|---|---|
[[Q-01]] | [[YYYY-MM-DD]] | [[reviewer]] | [[Entry IDs]] | [[what was asked or went wrong]] | [[what was done or decided]] | [[role]] | [[YYYY-MM-DD]] |
Q-01 EXAMPLE | 2026-09-02 | Head of IT | 1 entry | Own administrator account on the SYS-03 list | Reassigned to the Head of Information Security (AR-04) | Campaign coordinator | 2026-09-03 |
Q-02 EXAMPLE | 2026-09-15 | Chief Financial Officer | 2 entries | 2 Cannot decide entries on SYS-01 | Referred to the system owner to decide | Chief Financial Officer | 2026-09-17 |
Q-03 EXAMPLE | 2026-09-15 | Campaign coordinator | 14 entries | Warehouse Manager, North site: 14 entries open at the deadline | Passed to the system owner; decided 2026-09-16 | Head of Logistics | 2026-09-17 |
Related documents
Document | Relationship |
|---|---|
Access Review Methodology | The rules quoted in the reviewer guide (AR-01 to AR-12) |
Access Review Campaign Operating Procedure | The campaign steps and dates the messages follow |
Access Review Scope & System Inventory | Which systems are reviewed, how often, and who owns them |
Access Review Campaign Workbook | Where reviewers record decisions; the source of the lists in each message |
Access Review Findings & Revocation Tracker | Where removals are tracked and confirmed, and findings recorded |
Access Review Evidence & Audit File Checklist | The evidence file the messages and log belong to |
Access Review Outcome Report Template | The results quoted in the closure note |
P02 Segregation of Duties Conflict Matrix | The conflicts a reviewer is asked to flag |
P06 Supplier Security Risk Register | Suppliers that run a system's removals, and their agreed removal times |
Adapting this template
Guidance — delete before approval
Small organisation: there may be only a handful of reviewers, and the coordinator may know each of them. Send the launch email and the final reminder; drop the first reminder; use the quick card in place of the guide. Where the coordinator or the head of IT holds administrator access, someone else must review it (AR-04) — the managing director or another director will do, with the system owner's help on what each permission means.
Regulated entity: NIS2 Article 21(2)(i) expects access control policies to be applied, not just written; this pack's messages and log show how they are. Under DORA Article 9(4)(c) and Delegated Regulation (EU) 2024/1774 Article 21(e), access to systems supporting critical or important functions is reviewed at least every six months and other access at least yearly, and removed without undue delay; Article 21(c) limits generic and shared accounts, so ask reviewers to flag each one. For PCI DSS: Requirement 7.2.4 expects user accounts in scope, including third-party accounts, to be reviewed at least every six months — tell reviewers supplier accounts are on their lists; application and system accounts (7.2.5.1) go to the system owner, not a line manager, at the frequency your targeted risk analysis sets; and inactive accounts are removed or disabled within 90 days (8.2.6), so for those systems do not set the dormant threshold above 90 days.
IT run by a service provider: the provider usually takes the extracts and makes the removals. Send the removals note to its service desk as tickets, with the Entry IDs, and agree its removal times before launch; in the EXAMPLE, the ERP provider's five working days caused late privileged removals (PW-02). Reviewers are still your own managers: a provider never reviews its own staff's access to your systems (AR-04).
Delete this section before approval.
Framework references
These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1.
Framework | Reference | Supported by |
|---|---|---|
ISO/IEC 27001:2022 | Annex A 5.18 — Access rights | Reviewer guide: the four decisions, removal windows and confirmation; removals note to system owners |
ISO/IEC 27001:2022 | Annex A 6.3 — Information security awareness, education and training | Reviewer guide and quick card: what people with a review role need to know |
NIST CSF 2.0 | PR.AT-01 — “Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind” | Reviewer guide and quick card: reviewers equipped to make access decisions with risk in mind |
NIST CSF 2.0 | PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties” | What to question: access that does not fit the role, privileged accounts and conflicting duties |
NIS2 — Directive (EU) 2022/2555 | Article 21(2)(i) — “human resources security, access control policies and asset management” | Campaign communications and the questions and escalations log: access control applied in practice |
PCI DSS v4.0.1 | Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six months | Timeline and launch email: every account in scope, including third-party accounts, reviewed on a schedule |
Definitions
Term | Meaning in this pack |
|---|---|
Campaign | One round of access review across the systems due, from extract to close, with its own ID (EXAMPLE: UAR-2026-Q3). |
Campaign coordinator | Runs the campaign and sends the messages: [[e.g. Information Security Manager]]. |
Decision date | The campaign's decision deadline. Removal windows count from it, in working days. |
Dormant account | An account with no sign-in for more than [[90]] calendar days, or never used. |
Extract | The list of accounts and permissions taken from a system on a stated date (AR-03). |
Generic or shared account | An account used by more than one person, or not tied to a named person. |
Leaver | Someone who has left the organisation, or whose contract has ended. |
Orphan account | An account that matches no current person and has no named owner. |
Privileged account | An account that can administer the system: change its settings, its users or its security. |
Removal window | The time allowed to carry out a Revoke or Modify: 1 working day for privileged access, 5 working days for all other access. |
Reviewer | The person who decides each entry: usually the line manager; the system owner for permissions and privileged or generic accounts. |
Rubber-stamping | Approving access without looking at it. The quality signals are designed to catch it. |
Segregation-of-duties conflict | One person holding two duties that should be split, so they could make and hide a wrong change or payment. |
Service account | An account used by software or a device, not by a person. |
AR-nn | Rule numbers in the Access Review Methodology. |