Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
Category: Identity & Access

Access Review

Also known as: User Access Review, UAR, Access Certification, Certification Campaign
Simply put

An access review is a process by which an organization checks who has access to its systems, applications, and data, and confirms whether that access is still appropriate. It helps identify and remove permissions that people no longer need, reducing the risk of unauthorized access. Access reviews are typically carried out on a routine or recurring basis rather than only once.

Formal definition

An access review is a structured process of monitoring, assessing, and validating the access privileges and permissions granted to users or other principals, with the aim of attesting that each principal's continued access to a given resource is warranted. Reviews commonly target group memberships and access to enterprise or other applications, and may be configured as one-time or recurring (periodic) campaigns, sometimes termed access certifications. The output typically drives remediation actions such as revoking or maintaining access. Access review is an operational control practice; it is not itself a regulation or certification scheme, though it may support obligations arising under specific frameworks, contractual requirements, or laws. Scope, cadence, and reviewer assignment vary by organization and by the tooling used, and application to particular compliance obligations requires professional judgment. Readers should verify implementation details against current authoritative product and regulatory documentation.

Why it matters

Access rights tend to accumulate over time. As people change roles, join projects, or leave the organization, permissions that were once appropriate can persist long after the underlying need has ended. This phenomenon, often described as privilege creep, expands the attack surface and increases the risk that an unauthorized or no-longer-authorized principal can reach sensitive systems and data. Access reviews are the operational control that periodically tests whether existing access remains warranted and drives the removal of what is no longer needed.

Beyond risk reduction, access reviews frequently serve as evidence that an organization is actively governing who can access what. Many security frameworks, contractual arrangements, and sector-specific legal obligations expect some form of recurring validation of access rights, and a documented review process can help demonstrate that such expectations are being met. It is important to be precise here: an access review is an operational practice, not a regulation or a certification scheme in itself. Whether and how it supports a particular obligation depends on the applicable framework, contract, or law, and on how the review is scoped and executed.

The value of a review depends heavily on execution. Reviews that are performed by reviewers without adequate context, or that conclude without acting on their findings, can create a false sense of assurance while leaving inappropriate access in place. The meaningful outcome of a review is remediation — revoking access that is no longer justified and knowingly retaining access that is — rather than the completion of the review as a formality.

Who it's relevant to

Identity and access management teams
IAM practitioners design, configure, and operate access review campaigns, including defining scope, setting cadence, assigning reviewers, and ensuring that decisions to revoke or retain access are actually applied. They also select and manage the tooling, such as identity governance platforms, that supports one-time and recurring reviews.
Compliance officers and auditors
These roles rely on access reviews as evidence that access rights are being validated on a recurring basis. Because an access review is an operational control rather than a regulation or certification scheme, they must assess how a given review supports specific framework, contractual, or legal obligations — a determination that is fact-specific and requires professional judgment.
Application and data owners
Owners of enterprise applications, systems, and data are frequently assigned as reviewers because they have the context to judge whether a principal's continued access is appropriate. Their attestation decisions directly drive remediation, making their engagement central to the review's effectiveness.
Information security teams
Security teams treat access reviews as a control for reducing unauthorized access risk and countering the accumulation of unnecessary permissions over time. They are typically concerned with ensuring that findings lead to timely revocation rather than remaining unaddressed.

Inside Access Review

Scope of Access Rights
The set of user accounts, roles, entitlements, and permissions examined during the review. Scope typically covers who has access to which systems, applications, and data, and at what privilege level. The breadth of scope is generally determined by risk, data sensitivity, and organizational context rather than a single universal standard.
Reviewers and Accountability
The individuals responsible for evaluating and attesting to the appropriateness of access, often data or system owners, managers, or line-of-business supervisors. A defined accountable party is a common element, though titles and responsibilities vary by organization.
Recertification and Attestation
The formal confirmation that existing access remains appropriate for a user's current role and business need. Attestation records generally document who approved continued access, when, and on what basis.
Remediation Actions
The steps taken when access is found to be excessive, outdated, or unauthorized, such as revoking entitlements, adjusting roles, or escalating for investigation. Effective reviews generally include a defined process for acting on findings, not merely identifying them.
Frequency and Triggers
The cadence of periodic reviews (for example quarterly or annually) and event-based triggers such as role changes, terminations, or transfers. Appropriate frequency is typically risk-based and may be shaped by contractual, regulatory, or framework expectations.
Evidence and Records
The documentation retained to demonstrate that a review occurred, what was examined, and what decisions were made. Such records may support audits or assessments against contractual or regulatory obligations, depending on context.

Common questions

Answers to the questions practitioners most commonly ask about Access Review.

Is an access review the same as an audit?
No. An access review is an operational control activity in which an organization periodically examines who has access to which systems and data to confirm that access remains appropriate. An audit is a distinct, typically more formal evaluation—often conducted by internal or external parties against defined criteria—that may test whether access reviews are performed and effective, among other things. An access review may serve as evidence within an audit, but the two are not interchangeable: one is a recurring internal process, the other is an evaluative examination. Application to a particular program depends on organizational context and professional judgment.
Does completing access reviews mean an organization is compliant or certified?
Not by itself. Access reviews are one control among many and their presence does not equate to overall compliance with any given regulation, nor to certification against a standard. Certification schemes assess a broader control environment, and legal compliance depends on the specific obligations, jurisdiction, data categories, and risk profile that apply. Access reviews may support compliance or certification efforts as one contributing element, but they should not be presented as demonstrating either on their own. Readers should verify specific requirements against the current authoritative text of the applicable regulation or standard.
How often should access reviews be conducted?
Frequency generally depends on factors such as the sensitivity of the data or systems involved, the level of risk, regulatory or contractual expectations, and organizational size. Higher-risk or highly privileged access is commonly reviewed more frequently than lower-risk access. Some frameworks and contractual arrangements specify or imply review cadences, while others leave the interval to be determined on a risk basis. Because expectations differ across schemes and jurisdictions, organizations should determine cadence with reference to applicable requirements and their own risk assessment rather than to any universal interval.
Who should perform an access review?
Responsibility is generally allocated across roles: system or data owners, or line managers, are often positioned to judge whether access remains appropriate for individuals, while security, IT, or identity and access management functions typically facilitate the process and compile the underlying access data. Separating the person who grants access from the person who validates it can support segregation-of-duties objectives in many cases. The specific allocation depends on organizational structure and any applicable requirements, and application to particular circumstances requires professional judgment.
What should be documented when performing an access review?
Documentation generally supports the ability to demonstrate that a review took place and that its outcomes were acted upon. This may include the scope reviewed, the data source used, who performed and who approved the review, the date it was conducted, decisions to retain, modify, or revoke access, and evidence that revocations or changes were completed. Retained records can serve as evidence in later audits or assessments. The appropriate level of detail depends on the organization's risk profile and any applicable regulatory or contractual expectations, which should be verified against current authoritative sources.
How should findings from an access review be remediated?
Where a review identifies inappropriate, excessive, or stale access, remediation generally involves revoking or adjusting the access and, in some cases, investigating how it arose. Tracking remediation to closure—rather than only identifying issues—is commonly emphasized so that findings are demonstrably resolved. Timeliness of remediation may be shaped by the risk associated with the access and by applicable requirements. The suitable remediation approach is fact-specific and depends on organizational context and professional judgment rather than a fixed procedure.

Common misconceptions

An access review is a certification that proves an organization is compliant.
An access review is an internal control activity, not a certification. It may provide evidence supporting compliance efforts or a third-party audit or assessment, but performing reviews does not by itself confer any formal certification or attest to compliance with a standard or regulation. Certification, where it exists, is a separate process governed by its own scheme.
Access reviews are required by a single, universal legal rule.
There is no single global mandate. Depending on jurisdiction and sector, access review expectations may arise from regulations, contractual commitments, or voluntary frameworks and standards. Specific obligations differ across the EU, the United States, the United Kingdom, and other jurisdictions, and requirements are generally fact-specific and risk-based. Readers should verify applicable obligations against the current authoritative text.
Reviewing access once a year is always sufficient.
A fixed annual cadence is not universally adequate. Appropriate frequency generally depends on risk level, data sensitivity, and the rate of organizational change, and event-based triggers such as role changes or terminations often warrant review outside the standard cycle. What is sufficient is context-dependent and may be subject to specific contractual or regulatory expectations.

Best practices

Define review scope and cadence on a risk basis, giving greater frequency and scrutiny to privileged accounts and access to sensitive data, and document the rationale for the chosen approach.
Assign clear accountability by designating appropriate data or system owners as reviewers, so attestation decisions are made by parties who understand the business need for access.
Incorporate event-based triggers, such as role changes, transfers, and terminations, alongside periodic cycles rather than relying on scheduled reviews alone.
Establish and track a defined remediation process so that identified excessive or unauthorized access is revoked or adjusted promptly, and confirm that actions are completed.
Retain sufficient evidence of each review, including what was examined, who attested, and what decisions resulted, to support potential audits or assessments.
Verify specific review obligations against the current applicable contractual, regulatory, or framework requirements for the relevant jurisdiction and sector, recognizing that these change over time and that application to particular circumstances requires professional judgment.
Promotional banner for the Pentest Readiness checklist download