Independent thinking. Informed defence.

CISO Times

Intelligence for the people behind the defence.

The CISO Decision Brief

Reviewer Instruction Pack & Campaign Communications

Equips reviewers to make real decisions by telling them what they are looking at, what to question and what happens after they click.

Available soon

Format
Word
Size
62 KB
Length
22 pages
Version
1.0
Updated

What's inside

  • Purpose and audience
  • Reviewer guide
  • Quick card
  • Campaign communications
  • Required inputs with owners
  • Questions and escalations log
  • Related documents
  • Adapting this template
  • Framework references
  • Definitions

Preview

The document from section 1, as you will receive it. Highlighted [[text]] is for you to replace; shaded guidance boxes are for you to delete before approval. The cover and document control pages are in the file.

Purpose and audience

An access review is only as good as the decisions reviewers make. This pack gives reviewers what they need to make real ones — what they are looking at, what to question and what happens after they decide — and gives the campaign coordinator [[e.g. Information Security Manager]] the messages that run a campaign from launch to close.

It is used with the Access Review Campaign Operating Procedure, which sets the campaign steps, and the Access Review Campaign Workbook, where reviewers record their decisions. The rules it quotes (AR-nn) are in the Access Review Methodology.

Part

Audience

Use

Reviewer guide

Reviewers: line managers and system owners

Read once before the first campaign; sent with every launch email

Quick card

Every reviewer

One page to keep open while reviewing

Campaign communications

Campaign coordinator

Seven messages, each on its day of the campaign timetable, as a template and as an EXAMPLE

Required inputs; questions and escalations log

Campaign coordinator

What must be ready before launch, and the record of what reviewers asked

Guidance — delete before approval

Send the reviewer guide as it stands, with your placeholders filled in. Keep it short: a reviewer who has to read ten pages will not. The quick card is what most reviewers will actually use.

The EXAMPLE messages are for a wholesale distributor with about 900 staff, three warehouses and an online ordering service that takes 60% of its orders, running campaign UAR-2026-Q3 (extract 2026-09-01, decisions due 2026-09-15, closed 2026-09-29). The organisation, roles and figures are fictional.

Reviewer guide

You have been asked to review who has access to one or more of our systems. For each entry, decide whether that person still needs that access for the job they do today. It takes most reviewers about [[30]] minutes for [[40]] entries. Your decisions are acted on: access you revoke is removed.

What you are looking at

Your list is an extract from the system, taken on a stated date, with one row for each account and its permissions. The extract must be complete and taken on a stated date; the reviewer must see names, roles, permissions and last sign-in.

Column

What it shows

Entry ID

A unique number for the row. Quote it in any question.

Person

The name the account belongs to, taken from HR records — or "No match in HR" if the account matches nobody.

Job title and department

The person's current job, from HR, on the extract date.

Employment status

Active, leaver (with leaving date), on long-term leave, contractor (with end date), third party, or "No match in HR".

Account

The user name in the system.

Account type

Personal, privileged (administrator), generic or shared, service (used by software, not a person), or third-party (a supplier's staff).

Permissions

The roles or groups the account holds, in the system's own words, with a plain description where the system gives one.

Last sign-in

The date the account last signed in, and the number of calendar days since the extract date. Blank means never.

Decision

Where you choose Keep, Modify, Revoke or Cannot decide.

Reason

Required for Modify, Revoke and Cannot decide: what should change, or what you do not know.

If a column is missing or clearly wrong — for example, every last sign-in is blank — stop and tell the campaign coordinator. A decision made on a wrong extract is not a decision.

The four decisions

Every entry must get one of the four decisions; nothing is kept by default when a reviewer does not answer. Choose one of these for every entry:

Decision

What it means

Example

Keep

Access is needed and the permissions are right.

A warehouse team leader with pick-and-dispatch permissions in the warehouse management system, who signed in yesterday.

Modify

Access is needed but some permissions are not: remove the excess.

An accounts assistant who moved to credit control still holds the supplier-payments role in the ERP. Keep the account; remove the payments role. Say which permission goes in the Reason column.

Revoke

Access is not needed: remove it.

A picker who left in July still has a warehouse system account: Employment status shows leaver.

Cannot decide

The reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default.

An account called "scanner-03" that you do not recognise. Say so in the Reason column; the system owner (for the warehouse system, the Head of Logistics) decides.

Guidance — delete before approval

Replace the examples with ones from your own systems. Keep one per decision: reviewers remember an example better than a definition.

What to question

Most access that should not exist hides in five places. Look for each one on every list.

Look for

How it shows in your list

What to do

Leavers

Employment status: leaver; or Person: "No match in HR".

Revoke. It will also be raised as a finding (AR-08) so the leaver process can be fixed; you have done nothing wrong by finding it.

Dormant accounts

Last sign-in more than [[90]] calendar days before the extract date, or blank.

Revoke, unless there is a known reason — long-term leave, seasonal work — and then Keep with that reason written in.

Access that does not fit the role

Permissions that do not match the job title or department, or that belong to a job the person used to do.

Modify: remove what does not fit. If you do not know what a permission does, choose Cannot decide.

Privileged and generic accounts

Account type: privileged, generic or shared, or service.

Keep only if a named person owns it and it is still needed. Privileged, generic and service accounts must each have a named owner and must be reviewed by the system owner and information security.

Segregation-of-duties conflicts

One person who can both set something up and approve it — for example, create or change a supplier's bank details and also approve payments.

Modify, and say in the Reason column which two permissions clash. Information security checks it against the P02 Segregation of Duties Conflict Matrix.

What happens after you decide

Every Revoke or Modify must be carried out within its removal window and confirmed against a fresh extract. Removal windows count in working days from the campaign's decision date.

Your decision

What happens

By when

Keep

Nothing changes. Information security samples Keep decisions for quality.

—

Modify or Revoke, privileged access

The system administrator removes the permission or the account; the removal is confirmed against a fresh extract.

1 working day from the decision date

Modify or Revoke, all other access

As above.

5 working days from the decision date

Cannot decide

The entry goes to the system owner, who decides it.

[[2]] working days

Leaver, dormant, no owner, conflict

Removed as above, and also raised as a finding (AR-08). If it shows a process is failing, that process's owner gets a fix and a date (AR-11).

With the removal

You will not be asked to confirm removals yourself. You may be asked why you chose a decision: the Reason column is your answer.

Why "Keep all" is noticed

Campaign quality must be checked for rubber-stamping before the campaign is closed. Before a campaign closes, information security looks for these signs of a review that was clicked through rather than done:

  • A reviewer keeps 100% of a large list (more than [[25]] entries) in one sitting
  • Decisions made faster than [[5]] seconds each on average
  • Leavers or dormant accounts (no sign-in for [[90]] days) marked Keep
  • Privileged or generic accounts marked Keep without a named owner

Being noticed is not an accusation. Information security looks at a sample of your decisions and may ask you to look again. A list where everything genuinely should be kept is fine — say so in the Reason column for the entries that looked doubtful.

You never review your own access

Nobody may review their own access or the access of anyone who reviews theirs. If your own name, or the name of someone who reviews your access, appears on your list, do not decide that entry. Tell the campaign coordinator and it will be reassigned. The same applies to an account you use but that is not in your name, such as a shared administrator account.

Your deadline, and who to ask

Decide every entry by [[decision deadline]]. Your manager is copied on the second reminder. Entries without a decision are not kept by default: at the deadline they go to the system owner to decide, and then to the Head of Information Security, and you are named in the campaign report. Questions go to [[access-review mailbox or named contact]].

Quick card

One page for every reviewer. Print it, or attach it to the launch email. Replace the placeholders first.

Access review — quick card

[[Campaign ID]] · decide by [[decision deadline]]

Your job

For each entry: does this person still need this access for the job they do today?

Decide

Keep — access is needed and the permissions are right.

Modify — access is needed but some permissions are not: remove the excess.

Revoke — access is not needed: remove it.

Cannot decide — the reviewer does not know the person or the permission: it goes to the system owner within [[2]] working days, never to Keep by default.

Question

• Leavers, and anyone with no match in HR

• No sign-in for more than [[90]] days, or never

• Permissions that do not fit the job title or department

• Privileged, generic and shared accounts: who owns them?

• One person who can both set up and approve the same thing

Then

Revoke and Modify are carried out within 1 working day (privileged) or 5 working days (all others), and checked against a fresh extract.

Never

Keep something because you are unsure — choose Cannot decide.

Decide your own access, or the access of anyone who reviews yours.

Keep a whole list in one go without looking.

Help

[[access-review mailbox or named contact]]

Campaign communications

Seven messages run a campaign. Each has a template, with placeholders, and an EXAMPLE for UAR-2026-Q3. Each is sent on a day of the campaign timetable in the Access Review Campaign Operating Procedure, counted in working days from the extract date (day 0); change the days there, and here to match.

Timeline

EXAMPLE dates are for UAR-2026-Q3: extract 2026-09-01 (day 0), decision deadline 2026-09-15 (day 10), close 2026-09-29 (day 20).

Message

When

To

From

EXAMPLE date

Launch email

Day [[2]]

Every reviewer

Campaign coordinator

2026-09-03

First reminder

Day [[5]]

Reviewers with entries still open

Campaign coordinator

2026-09-08

Second reminder

Day [[8]]

Reviewers with entries still open, copied to each one's own manager

Campaign coordinator

2026-09-11

Removals note to system owners

Day [[10]], the decision deadline

Each system owner and system administrator

Campaign coordinator

2026-09-15

Unanswered entries to the system owner

Day [[10]], the decision deadline

The system owner, for entries left without a decision at the deadline

Campaign coordinator

2026-09-15

Escalation to the Head of Information Security

Day [[12]]

Head of Information Security, for entries the system owner has not decided

Campaign coordinator

2026-09-17 — not needed

Thank-you and closure note

Day [[20]], close

Every reviewer and system owner

Campaign coordinator

2026-09-29

Guidance — delete before approval

Send from a named person, not a no-reply address: reviewers answer the person, and their answers are part of the campaign's record.

Keep every message sent, with its date and recipients, in the campaign's evidence file (AR-10). The escalations and the removals notes are what an auditor asks for first.

Where the removal windows (1 working day privileged, 5 working days other) cannot be met by a system's administrator — often a supplier-run system — agree that before launch, not after the decision date.

Launch email

Sent to every reviewer once the extracts are loaded and checked. It carries the reviewer guide, or the quick card, as an attachment.

Template

Launch email

When

Day [[2]] — working days from the extract date (day 0)

To

[[Reviewer name]]

From

[[Name]], Campaign coordinator

Subject

Action needed by [[decision deadline, e.g. Tuesday 15 September]]: review who has access to [[System name(s)]] ([[Campaign ID]])

Message

Dear [[Reviewer name]],

You are asked to review [[n]] entries: the people who have access to [[System name(s)]], as recorded on [[extract date]]. For each entry, decide whether that person still needs that access for the job they do today.

What to do

1. Open your list: [[where the review is done: the workbook, tool or form, and how to open it]].

2. Give every entry one decision: Keep, Modify, Revoke or Cannot decide. For anything other than Keep, say why in the Reason column.

3. Finish by [[decision deadline, e.g. Tuesday 15 September]]. Most reviewers need about [[30]] minutes for [[40]] entries.

Look hard at leavers, accounts not used for more than [[90]] days, access that does not fit the person's job, administrator and shared accounts, and anyone who can both set something up and approve it.

What happens next: every Revoke and Modify is carried out within 1 working day for administrator access and 5 working days for everything else, then checked. If you do not know a person or a permission, choose Cannot decide — do not keep it to be safe.

If your own name is on your list, do not decide it: tell us and it will be reassigned. The one-page reviewer guide is attached.

Questions: [[access-review mailbox or named contact]].

Thank you,

[[Name]], Campaign coordinator

EXAMPLE — UAR-2026-Q3

Launch email

When

Thursday 3 September 2026 (day 2)

To

Warehouse Manager, North site

From

[[Name]], Information Security Manager (Campaign coordinator)

Subject

Action needed by Tuesday 15 September 2026: review who has access to the warehouse management system (SYS-02) (UAR-2026-Q3)

Message

Dear Warehouse Manager, North site,

You are asked to review 41 entries: the people who have access to the warehouse management system (SYS-02), as recorded on Tuesday 1 September 2026. For each entry, decide whether that person still needs that access for the job they do today.

What to do

1. Open your list: [[Access Review Campaign Workbook — your tab, on the shared site]].

2. Give every entry one decision: Keep, Modify, Revoke or Cannot decide. For anything other than Keep, say why in the Reason column.

3. Finish by Tuesday 15 September 2026. Most reviewers need about [[30]] minutes for [[40]] entries.

Look hard at leavers, accounts not used for more than [[90]] days, access that does not fit the person's job, administrator and shared accounts, and anyone who can both set something up and approve it.

What happens next: every Revoke and Modify is carried out within 1 working day for administrator access and 5 working days for everything else, then checked. If you do not know a person or a permission, choose Cannot decide — do not keep it to be safe.

If your own name is on your list, do not decide it: tell us and it will be reassigned. The one-page reviewer guide is attached.

Questions: [[access-review mailbox or named contact]].

Thank you,

[[Name]], Information Security Manager (Campaign coordinator)

First reminder

Sent only to reviewers with entries still open. Give the number: it is more persuasive than a general reminder.

Template

First reminder

When

Day [[5]] — working days from the extract date (day 0)

To

[[Reviewer name]]

From

[[Name]], Campaign coordinator

Subject

Reminder: [[n]] access-review entries still open, due [[decision deadline, e.g. Tuesday 15 September]] ([[Campaign ID]])

Message

Dear [[Reviewer name]],

[[n]] of your [[n]] entries for [[System name(s)]] have no decision yet. The deadline is [[decision deadline, e.g. Tuesday 15 September]].

An entry without a decision is not kept by default: it is escalated. Please finish your list: [[where the review is done: the workbook, tool or form, and how to open it]].

If you are unsure about an entry, choose Cannot decide and say what you do not know. It goes to the system owner, and it counts as done for you.

Questions: [[access-review mailbox or named contact]].

Thank you,

[[Name]], Campaign coordinator

EXAMPLE — UAR-2026-Q3

First reminder

When

Tuesday 8 September 2026 (day 5)

To

Warehouse Manager, North site

From

[[Name]], Information Security Manager (Campaign coordinator)

Subject

Reminder: 23 access-review entries still open, due Tuesday 15 September 2026 (UAR-2026-Q3)

Message

Dear Warehouse Manager, North site,

23 of your 41 entries for the warehouse management system (SYS-02) have no decision yet. The deadline is Tuesday 15 September 2026.

An entry without a decision is not kept by default: it is escalated. Please finish your list: [[Access Review Campaign Workbook — your tab, on the shared site]].

If you are unsure about an entry, choose Cannot decide and say what you do not know. It goes to the system owner, and it counts as done for you.

Questions: [[access-review mailbox or named contact]].

Thank you,

[[Name]], Information Security Manager (Campaign coordinator)

Second reminder

To reviewers with entries still open, copied to each one's own manager. It says what happens after the deadline, plainly.

Template

Second reminder

When

Day [[8]] — working days from the extract date (day 0)

To

[[Reviewer name]]; copy [[Reviewer's manager]]

From

[[Name]], Campaign coordinator

Subject

Second reminder: your access review is due [[decision deadline, e.g. Tuesday 15 September]] ([[Campaign ID]])

Message

Dear [[Reviewer name]],

[[n]] of your [[n]] entries for [[System name(s)]] still have no decision, and the deadline is [[decision deadline, e.g. Tuesday 15 September]]. Your manager, [[Reviewer's manager]], is copied.

Entries still open at the deadline go to the system owner to decide, and then to the Head of Information Security; you are named in the campaign report. Nothing is kept without a decision.

It usually takes under a minute an entry. The quick card attached lists what to look for.

[[Name]], Campaign coordinator

EXAMPLE — UAR-2026-Q3

Second reminder

When

Friday 11 September 2026 (day 8)

To

Warehouse Manager, North site; copy Head of Logistics

From

[[Name]], Information Security Manager (Campaign coordinator)

Subject

Second reminder: your access review is due Tuesday 15 September 2026 (UAR-2026-Q3)

Message

Dear Warehouse Manager, North site,

14 of your 41 entries for the warehouse management system (SYS-02) still have no decision, and the deadline is Tuesday 15 September 2026. Your manager, Head of Logistics, is copied.

Entries still open at the deadline go to the system owner to decide, and then to the Head of Information Security; you are named in the campaign report. Nothing is kept without a decision.

It usually takes under a minute an entry. The quick card attached lists what to look for.

[[Name]], Information Security Manager (Campaign coordinator)

Removals note to system owners

Sent on the decision date to each system owner, with the list of Revoke and Modify decisions for their system from the Access Review Campaign Workbook. The removal windows start today.

Template

Removals note to system owners

When

Day [[10]], the decision deadline — working days from the extract date (day 0)

To

[[System owner]]; copy [[system administrator]]

From

[[Name]], Campaign coordinator

Subject

Access to remove on [[System name]]: privileged by [[decision date + 1 working day]], all others by [[decision date + 5 working days]] ([[Campaign ID]])

Message

Dear [[System owner]],

Reviewers' decisions for [[System name]] are in. The attached list has [[n]] Revoke and [[n]] Modify decisions to carry out, [[n]] of them privileged.

Deadlines count from today, the decision date: privileged access by [[decision date + 1 working day]] (1 working day); everything else by [[decision date + 5 working days]] (5 working days).

Please:

1. Pass the list to [[IT operations, or the supplier's support team]] today.

2. Record the date each change was made against its Entry ID.

3. When the last change is made, send us a fresh extract, so that every removal can be confirmed against it.

4. Tell us at once if a change cannot be made in time, so it is tracked rather than missed.

Also yours to decide: [[n]] Cannot decide entries, by [[decision date + 2 working days]]. Leavers, dormant accounts, accounts with no owner and segregation-of-duties conflicts are raised as findings as well as removed; you will hear about any on your system separately.

[[Anything particular to this system, e.g. the supplier runs removals and needs a ticket]]

[[Name]], Campaign coordinator

EXAMPLE — UAR-2026-Q3

Removals note to system owners

When

Tuesday 15 September 2026 (day 10, the decision deadline)

To

Chief Financial Officer; copy Head of IT

From

[[Name]], Information Security Manager (Campaign coordinator)

Subject

Access to remove on the ERP (SYS-01): privileged by Wednesday 16 September 2026, all others by Tuesday 22 September 2026 (UAR-2026-Q3)

Message

Dear Chief Financial Officer,

Reviewers' decisions for the ERP (SYS-01) are in. The attached list has 12 Revoke and 11 Modify decisions to carry out, 3 of them privileged.

Deadlines count from today, the decision date: privileged access by Wednesday 16 September 2026 (1 working day); everything else by Tuesday 22 September 2026 (5 working days).

Please:

1. Pass the list to the ERP provider's support team (P06 SUP-004), by ticket today.

2. Record the date each change was made against its Entry ID.

3. When the last change is made, send us a fresh extract, so that every removal can be confirmed against it.

4. Tell us at once if a change cannot be made in time, so it is tracked rather than missed.

Also yours to decide: 2 Cannot decide entries, by Thursday 17 September 2026. Leavers, dormant accounts, accounts with no owner and segregation-of-duties conflicts are raised as findings as well as removed; you will hear about any on your system separately.

SYS-01 is run by the ERP provider (P06 SUP-004). Its removals are made by ticket: raise the tickets today, and ask the provider to confirm each removal the day it is made. The 3 privileged removals (finance administrator roles) are due in 1 working day.

[[Name]], Information Security Manager (Campaign coordinator)

Unanswered entries to the system owner

The first step of the escalation ladder in the Access Review Campaign Operating Procedure: entries still without a decision at the deadline go to the system owner, who decides them within [[2]] working days. Short and factual.

Template

Unanswered entries to the system owner

When

Day [[10]], the decision deadline — working days from the extract date (day 0)

To

[[System owner]]; copy [[Reviewer name]] and [[Reviewer's manager]]

From

[[Name]], Campaign coordinator

Subject

[[n]] unanswered access-review entries for you to decide by [[decision date + 2 working days]] ([[Campaign ID]])

Message

Dear [[System owner]],

[[Reviewer name]] left [[n]] entries for [[System name(s)]] without a decision at the deadline, [[decision deadline, e.g. Tuesday 15 September]]. As the system owner, they are now yours to decide, by [[decision date + 2 working days]]. The list is attached.

Access without a decision cannot be kept by default, and until it is decided, people who should no longer have access may still have it.

Anything still undecided on [[decision date + 2 working days]] goes to the Head of Information Security, who decides it or has the access [[suspended]] until someone does. The reviewer is named in the campaign report.

[[Name]], Campaign coordinator

EXAMPLE — UAR-2026-Q3

Unanswered entries to the system owner

When

Tuesday 15 September 2026 (day 10, the decision deadline)

To

Head of Logistics; copy Warehouse Manager, North site

From

[[Name]], Information Security Manager (Campaign coordinator)

Subject

14 unanswered access-review entries for you to decide by Thursday 17 September 2026 (UAR-2026-Q3)

Message

Dear Head of Logistics,

Warehouse Manager, North site left 14 entries for the warehouse management system (SYS-02) without a decision at the deadline, Tuesday 15 September 2026. As the system owner, they are now yours to decide, by Thursday 17 September 2026. The list is attached.

Access without a decision cannot be kept by default, and until it is decided, people who should no longer have access may still have it.

Anything still undecided on Thursday 17 September 2026 goes to the Head of Information Security, who decides it or has the access [[suspended]] until someone does. The reviewer is named in the campaign report.

[[Name]], Information Security Manager (Campaign coordinator)

Escalation to the Head of Information Security

The second step: anything the system owner has not decided by then goes to the Head of Information Security, who decides it or has the access suspended until someone does.

Template

Escalation to the Head of Information Security

When

Day [[12]] — working days from the extract date (day 0)

To

Head of Information Security; copy [[System owner]]

From

[[Name]], Campaign coordinator

Subject

Access-review entries still undecided: [[System name(s)]] ([[Campaign ID]])

Message

Dear Head of Information Security,

[[n]] entries for [[System name(s)]], left without a decision by [[Reviewer name]] at the deadline and passed to [[System owner]], were still undecided on [[decision date + 2 working days]]. The list is attached.

Please decide them, or have the access [[suspended]] until someone does. The reviewer will be named in the campaign report.

[[Name]], Campaign coordinator

EXAMPLE: not sent in UAR-2026-Q3. The Head of Logistics decided all 14 of the Warehouse Manager, North site's unanswered entries on 2026-09-16, before day 12 (2026-09-17).

Thank-you and closure note

Sent when the campaign is closed. It is the follow-up to the campaign: it reports what the review found, not only that it finished (AR-12), so reviewers see that their decisions mattered. The figures come from the Access Review Outcome Report Template.

Template

Thank-you and closure note

When

Day [[20]], close — working days from the extract date (day 0)

To

[[All reviewers and system owners in the campaign]]

From

[[Name]], Campaign coordinator

Subject

Access review [[Campaign ID]] is closed — what it found, and thank you

Message

Dear colleagues,

Thank you. [[n]] entries across [[n]] systems were reviewed, and every one has a decision.

What it found: [[n]] pieces of access removed or reduced ([[n]] revoked, [[n]] modified). [[n]] accounts should not have existed at all — leavers, accounts unused for more than [[90]] days and accounts with no owner. [[n]] person could both set up and approve the same transaction.

Removals: every one has been checked against a fresh extract. [[n]] were made later than their deadline; the report explains why.

What changes: [[The process weaknesses found, each with its owner and date — or "none"]].

Next: [[date of the next campaign, and what it covers]].

The full results go to [[management forum]] in the Access Review Outcome Report.

[[Name]], Campaign coordinator

EXAMPLE — UAR-2026-Q3

Thank-you and closure note

When

Tuesday 29 September 2026 (day 20, close)

To

All reviewers and system owners in the campaign

From

[[Name]], Information Security Manager (Campaign coordinator)

Subject

Access review UAR-2026-Q3 is closed — what it found, and thank you

Message

Dear colleagues,

Thank you. 495 entries across 5 systems were reviewed, and every one has a decision.

What it found: 69 pieces of access removed or reduced (47 revoked, 22 modified). 36 accounts should not have existed at all — leavers, accounts unused for more than [[90]] days and accounts with no owner. 1 person could both set up and approve the same transaction.

Removals: every one has been checked against a fresh extract. 4 were made later than their deadline; the report explains why.

What changes: PW-01: warehouse leavers are not removed from the warehouse system: HR's leaver notice does not reach its owner (owner: HR Director, due 2026-11-30); PW-02: the ERP provider takes 5 working days to remove users; our window is 5 for standard access and 1 for privileged (owner: Chief Financial Officer, due 2026-12-15).

Next: the next campaign, for privileged and administrator access (reviewed every 3 months), starts with an extract on Tuesday 1 December 2026.

The full results go to [[management forum]] in the Access Review Outcome Report.

[[Name]], Information Security Manager (Campaign coordinator)

Guidance — delete before approval

The EXAMPLE closure note quotes the campaign's own results: 495 entries reviewed; 69 removals (47 revoked, 22 modified); 36 leaver, dormant or orphan accounts; 1 segregation-of-duties conflict; 4 removals late. The process weaknesses are PW-01 and PW-02.

Required inputs with owners

What must be ready before the launch email is sent, and what each later message needs.

Input

Needed for

Owner

The systems in scope, their owners and frequency (Access Review Scope & System Inventory)

Launch

Campaign coordinator

One extract per system, complete and taken on a stated date (AR-03)

Launch

System administrator [[IT operations, or the supplier's support team]]

Joiner, mover and leaver data at the extract date, matched to the extract

Launch: the Employment status column

HR [[for joiner, mover and leaver data]]

Reviewer for each entry, checked so that nobody reviews their own access (AR-04)

Launch

Campaign coordinator

The reviewer lists in the Access Review Campaign Workbook

Launch, reminders

Campaign coordinator

Open entries per reviewer

Reminders, escalations

Campaign coordinator

Each reviewer's manager

Second reminder (copied)

HR

Revoke, Modify and Cannot decide lists by system

Removals note

Campaign coordinator

The administrator for each system, and how removals are requested

Removals note

System owner

Campaign results and process weaknesses (Access Review Outcome Report Template)

Closure note

Campaign coordinator

Questions and escalations log

Reviewers' questions, reassignments, escalations and Cannot decide referrals, each with an owner and a date. Keep it with the campaign's evidence file (AR-10); the findings themselves go to the Access Review Findings & Revocation Tracker.

Ref

Date

From

Entries

Question or issue

Action

Owner

Due

[[Q-01]]

[[YYYY-MM-DD]]

[[reviewer]]

[[Entry IDs]]

[[what was asked or went wrong]]

[[what was done or decided]]

[[role]]

[[YYYY-MM-DD]]

Q-01

EXAMPLE

2026-09-02

Head of IT

1 entry

Own administrator account on the SYS-03 list

Reassigned to the Head of Information Security (AR-04)

Campaign coordinator

2026-09-03

Q-02

EXAMPLE

2026-09-15

Chief Financial Officer

2 entries

2 Cannot decide entries on SYS-01

Referred to the system owner to decide

Chief Financial Officer

2026-09-17

Q-03

EXAMPLE

2026-09-15

Campaign coordinator

14 entries

Warehouse Manager, North site: 14 entries open at the deadline

Passed to the system owner; decided 2026-09-16

Head of Logistics

2026-09-17

Related documents

Document

Relationship

Access Review Methodology

The rules quoted in the reviewer guide (AR-01 to AR-12)

Access Review Campaign Operating Procedure

The campaign steps and dates the messages follow

Access Review Scope & System Inventory

Which systems are reviewed, how often, and who owns them

Access Review Campaign Workbook

Where reviewers record decisions; the source of the lists in each message

Access Review Findings & Revocation Tracker

Where removals are tracked and confirmed, and findings recorded

Access Review Evidence & Audit File Checklist

The evidence file the messages and log belong to

Access Review Outcome Report Template

The results quoted in the closure note

P02 Segregation of Duties Conflict Matrix

The conflicts a reviewer is asked to flag

P06 Supplier Security Risk Register

Suppliers that run a system's removals, and their agreed removal times

Adapting this template

Guidance — delete before approval

Small organisation: there may be only a handful of reviewers, and the coordinator may know each of them. Send the launch email and the final reminder; drop the first reminder; use the quick card in place of the guide. Where the coordinator or the head of IT holds administrator access, someone else must review it (AR-04) — the managing director or another director will do, with the system owner's help on what each permission means.

Regulated entity: NIS2 Article 21(2)(i) expects access control policies to be applied, not just written; this pack's messages and log show how they are. Under DORA Article 9(4)(c) and Delegated Regulation (EU) 2024/1774 Article 21(e), access to systems supporting critical or important functions is reviewed at least every six months and other access at least yearly, and removed without undue delay; Article 21(c) limits generic and shared accounts, so ask reviewers to flag each one. For PCI DSS: Requirement 7.2.4 expects user accounts in scope, including third-party accounts, to be reviewed at least every six months — tell reviewers supplier accounts are on their lists; application and system accounts (7.2.5.1) go to the system owner, not a line manager, at the frequency your targeted risk analysis sets; and inactive accounts are removed or disabled within 90 days (8.2.6), so for those systems do not set the dormant threshold above 90 days.

IT run by a service provider: the provider usually takes the extracts and makes the removals. Send the removals note to its service desk as tickets, with the Entry IDs, and agree its removal times before launch; in the EXAMPLE, the ERP provider's five working days caused late privileged removals (PW-02). Reviewers are still your own managers: a provider never reviews its own staff's access to your systems (AR-04).

Delete this section before approval.

Framework references

These references show where this document supports an external framework. They indicate relevance only and do not reproduce the text of any standard. Editions referenced: ISO/IEC 27001:2022 incl. Amd 1:2024; NIST CSF 2.0; Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Delegated Regulation (EU) 2024/1774; PCI DSS v4.0.1.

Framework

Reference

Supported by

ISO/IEC 27001:2022

Annex A 5.18 — Access rights

Reviewer guide: the four decisions, removal windows and confirmation; removals note to system owners

ISO/IEC 27001:2022

Annex A 6.3 — Information security awareness, education and training

Reviewer guide and quick card: what people with a review role need to know

NIST CSF 2.0

PR.AT-01 — “Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind”

Reviewer guide and quick card: reviewers equipped to make access decisions with risk in mind

NIST CSF 2.0

PR.AA-05 — “Access permissions, entitlements, and authorizations are defined in a policy, managed, enforced, and reviewed, and incorporate the principles of least privilege and separation of duties”

What to question: access that does not fit the role, privileged accounts and conflicting duties

NIS2 — Directive (EU) 2022/2555

Article 21(2)(i) — “human resources security, access control policies and asset management”

Campaign communications and the questions and escalations log: access control applied in practice

PCI DSS v4.0.1

Requirement 7.2.4 — user accounts and their access privileges, including third-party accounts, reviewed at least every six months

Timeline and launch email: every account in scope, including third-party accounts, reviewed on a schedule

Definitions

Term

Meaning in this pack

Campaign

One round of access review across the systems due, from extract to close, with its own ID (EXAMPLE: UAR-2026-Q3).

Campaign coordinator

Runs the campaign and sends the messages: [[e.g. Information Security Manager]].

Decision date

The campaign's decision deadline. Removal windows count from it, in working days.

Dormant account

An account with no sign-in for more than [[90]] calendar days, or never used.

Extract

The list of accounts and permissions taken from a system on a stated date (AR-03).

Generic or shared account

An account used by more than one person, or not tied to a named person.

Leaver

Someone who has left the organisation, or whose contract has ended.

Orphan account

An account that matches no current person and has no named owner.

Privileged account

An account that can administer the system: change its settings, its users or its security.

Removal window

The time allowed to carry out a Revoke or Modify: 1 working day for privileged access, 5 working days for all other access.

Reviewer

The person who decides each entry: usually the line manager; the system owner for permissions and privileged or generic accounts.

Rubber-stamping

Approving access without looking at it. The quality signals are designed to catch it.

Segregation-of-duties conflict

One person holding two duties that should be split, so they could make and hide a wrong change or payment.

Service account

An account used by software or a device, not by a person.

AR-nn

Rule numbers in the Access Review Methodology.