Introduction
Every organization accumulates access debt: the analyst who moved teams but kept the old finance system role, the contractor whose account outlived the contract, the service account nobody can explain. A user access review procedure is the periodic recertification process that finds and removes this debt before an attacker — or an auditor — does. The Verizon Data Breach Investigations Report has for years placed stolen or misused credentials among the top vectors in confirmed breaches, and excessive standing access is what turns one compromised account into a serious incident.
Access reviews are also one of the most commonly failed audit controls. ISO 27001 control A.5.18 and the SOC 2 logical access criteria both expect periodic review of access rights, and auditors routinely find reviews that were late, incomplete, rubber-stamped, or impossible to evidence. This SOP fixes that.
Why Access Reviews Need a Documented Procedure
Without a procedure, access reviews happen the way most companies do them: someone exports a user list into a spreadsheet the week before the audit, emails it to managers with "please confirm," and files whatever comes back. That process produces exactly the findings auditors write up — no defined population, no evidence of reviewer scrutiny, revocations agreed but never executed.
A documented user access review procedure defines the review population, frequency, reviewers, workflow, and evidence standard in advance, so every cycle runs the same way and every decision leaves a trail.
Key Elements of a User Access Review Procedure
1. Scope: The Review Population
List every system in scope: identity provider, core business applications, cloud consoles, databases, VPN, code repositories, and any system holding regulated data. The SOP should define how the population itself is maintained — a review of the wrong system list passes nothing. Include all account types: employees, contractors, vendors, and non-human accounts.
2. Review Frequency by Risk Tier
Not everything needs the same cadence. A common model: privileged access and financially significant systems quarterly, standard access to sensitive systems semi-annually, low-risk applications annually. Write the tiering criteria down so scoping decisions are defensible, and let major changes — an acquisition, a breach, a reorganization — trigger out-of-cycle reviews.
3. Reviewer Assignment: Managers and System Owners
Decide who certifies what. Line managers are best placed to answer "does this person still need this for their job?" System owners are best placed to answer "is this role appropriate for this system?" Mature programs use both: managers review their direct reports' access, system owners review roles, admins, and anomalies. The SOP must prohibit self-review — nobody certifies their own access, including the IT staff running the review.
4. The Recertification Workflow
Document the cycle end to end: generate access reports from the source systems (not from a stale HR extract), distribute to assigned reviewers with a deadline, reviewers mark each line approve or revoke with a reason, revocations are executed by IT within a defined SLA — typically five business days — and execution is verified and evidenced. The cycle is not complete when reviews are returned; it is complete when every revocation is confirmed removed.
5. Joiner-Mover-Leaver Triggers vs Periodic Review
Periodic review is a safety net, not the primary control. The SOP should reference event-driven deprovisioning: leavers lose access on their end date, movers get a role-change access reset rather than accumulating entitlements. Then use review findings as a health check — if quarterly reviews keep catching leavers with live accounts, the JML process is broken and the SOP should require a corrective action, not just a revocation.
6. Privileged Access and Service Accounts
Privileged accounts get stricter treatment: quarterly minimum frequency, review of both membership and usage (dormant admin rights are the first thing to remove), and validation against a maintained privileged-access register. Service accounts need a named human owner, a documented purpose, and an owner attestation each cycle — orphaned service accounts with static credentials are a standing invitation.
7. Segregation-of-Duties Conflicts
The review should test combinations, not just individual entitlements. Define your SoD ruleset — the classic examples are creating vendors and approving payments, or writing code and approving your own deployment to production — and have the review flag any user holding a conflicting combination. Where a conflict is unavoidable in a small team, require a documented compensating control and management sign-off.
8. Evidence Packaging for Auditors
Auditors need to see four things per cycle: the population report with a generation date, the reviewer attestations with names and dates, the revocation list, and proof of execution — tickets or screenshots showing access removed. The SOP defines where this evidence lives, how it is named, and its retention period (align to your certification cycle; three years is a common floor). A review you cannot evidence is, for ISO 27001 A.5.18 and SOC 2 purposes, a review that did not happen.
9. Automation Options
Identity governance tools can generate campaigns, route line items to reviewers, execute revocations through provisioning connectors, and archive evidence automatically. The SOP should describe your current state honestly — many mid-size companies run on exports and forms, and that passes audits when done rigorously — while defining what gets automated first: population generation and revocation verification, the two most error-prone manual steps.
10. Common Audit Findings to Design Against
Write the procedure to pre-empt the findings auditors raise most: reviews performed late or skipped for a quarter, in-scope systems missing from the population, bulk approvals completed minutes after distribution (rubber-stamping), revocations approved but never executed, and no evidence of who reviewed what. Each of these maps to a specific control in the workflow above.
Step-by-Step: Building Your Access Review SOP
- Inventory systems and rank by risk. Data sensitivity, financial impact, and privileged capability set the tier.
- Set frequency per tier. Quarterly for privileged and high-risk, semi-annual or annual below that.
- Assign reviewers by name and role. Managers for people, system owners for roles and anomalies. Ban self-review.
- Define the workflow and SLAs. Report generation, review deadline, revocation SLA, verification step.
- Build the evidence template. One folder structure per cycle, populated as the cycle runs — not reconstructed before the audit.
- Run one cycle, then tune. Measure completion rate, revocation rate, and time-to-revoke, and fix the slowest step.
Common Mistakes to Avoid
Rubber-stamp approvals. A manager approving 200 line items in four minutes is a finding, not a review. Sample completed reviews and challenge implausible turnaround.
Reviewing a stale export. If the population report was generated three weeks before reviewers saw it, leavers and movers slip through the gap.
Stopping at "approved for removal." The most common gap between review and reality is revocations that were agreed and never executed. Verification is part of the procedure.
Forgetting non-human accounts. Service accounts, API keys, and shared mailboxes outlive their creators. Every one needs an owner who re-attests each cycle.
How AI Accelerates SOP Creation
WorkProcedures generates a user access review procedure tailored to your systems, team size, and certification targets from a plain-language description. Compliance projects map the SOP to ISO 27001 controls, and acknowledgement tracking shows auditors exactly who has read and accepted the current procedure.
Conclusion
Access reviews are where security policy meets reality: either standing access shrinks every quarter, or it grows until an incident or an audit exposes it. A documented user access review procedure — scoped, tiered, assigned, and evidenced — makes recertification routine instead of a pre-audit scramble. Visit WorkProcedures to build your access review SOPs today.