- Owner
- IT Security Manager
- Effective date
- September 15, 2026
- Review cycle
- Every 6 months
1.Purpose
To periodically verify that user access to systems and data remains appropriate, removing excess or stale permissions and confirming access still matches each person's current role.
2.Scope
Applies to scheduled reviews of user accounts, group memberships and application access across in-scope systems, including leavers and role changes. Initial account creation and password resets are covered by separate procedures.
Definitions
- Access review cycle
- A scheduled point-in-time review of who has access to a given system.
- Entitlement
- A specific permission or group membership granted to a user account.
- Segregation of duties
- A control that prevents one person from holding two conflicting entitlements, such as creating and approving the same transaction.
- Stale account
- An account with no recent login activity that may no longer be needed.
3.Responsibilities
- System Administrator
- Generates access reports, revokes or adjusts access, and disables stale accounts.
- IT Security Manager
- Coordinates the review cycle, resolves flagged conflicts, and reports results.
- Application Owner
- Certifies whether each user's access to their application is still needed.
- People Manager
- Confirms which team members still need access based on current role and team changes.
RACI matrix
| Activity | System Administrator | IT Security Manager | Application Owner | People Manager |
|---|---|---|---|---|
| Generate and distribute the access review | R | R/A | I | I |
| Certify user access decisions | I | C | R/A | R |
| Revoke or adjust access | R/A | C | I | I |
| Resolve segregation of duties conflicts | C | R/A | C | I |
| Report review completion to leadership | I | R/A | I | I |
R = Responsible, A = Accountable, C = Consulted, I = Informed
4.Materials and PPE
Materials, tools and systems
- โIdentity provider reporting tool
- โAccess review spreadsheet or template
- โSegregation of duties matrix
- โReview calendar
- โReviewer sign-off or attestation record
5.Procedure
- 5.1
Generate the access review report
System AdministratorThe System Administrator exports a list of users and their entitlements for each system in scope from the identity provider.
- 5.2
Distribute the review to reviewers
IT Security ManagerThe IT Security Manager sends each access list to the relevant Application Owner or People Manager, with a deadline for completing the certification.
- 5.3
Certify each user's access
Application OwnerThe Application Owner or People Manager reviews the list and marks each user's access as still needed, to be modified, or to be removed.
Checkpoint: Every account on the list receives an explicit decision; none are left blank or skipped.
- 5.4
Flag segregation of duties conflicts
IT Security ManagerThe IT Security Manager reviews certified decisions against the segregation of duties matrix and flags any user holding conflicting entitlements.
- 5.5
Identify leavers and role changes
System AdministratorThe System Administrator cross-checks the access list against recent departures and internal role changes to catch access that should already have been removed.
Warning: Any active account for a departed employee is a priority removal and should not wait for the next scheduled review.
- 5.6
Revoke or adjust access
System AdministratorThe System Administrator implements each reviewer's decision, removing or adjusting entitlements as certified.
- 5.7
Disable stale accounts
System AdministratorThe System Administrator disables or removes accounts with no recent login activity, after confirming the account is not a required service account.
Checkpoint: Each stale account is confirmed as not a required service account before it is disabled.
- 5.8
Document review decisions
IT Security ManagerThe IT Security Manager records each reviewer's decisions and any supporting notes in the access review record.
- 5.9
Escalate contested decisions
IT Security ManagerThe IT Security Manager reviews and makes the final call on any decision the reviewer and account holder disagree about.
- 5.10
Compile completion and sign-off
IT Security ManagerThe IT Security Manager compiles the completed review results and collects sign-off confirmation from each reviewer.
- 5.11
Report to leadership
IT Security ManagerThe IT Security Manager reports the review's completion rate and notable findings, such as segregation of duties conflicts, to leadership.
- 5.12
Schedule the next cycle
IT Security ManagerThe IT Security Manager schedules the next access review cycle and updates the review calendar.
6.Quality checks
- โEvery account on the review list receives an explicit reviewer decision.
- โAccess for departed employees is revoked promptly rather than waiting for the next cycle.
- โSegregation of duties conflicts are documented and resolved.
- โEach review cycle has a signed-off completion record.
7.Records
- โAccess review report
- โReviewer certification or sign-off
- โSegregation of duties exception log
- โRevocation confirmation
8.KPIs
- โAccess review completion rate
- โAverage time to revoke access after a role change or departure
- โNumber of stale or excess access findings per cycle
- โPercentage of accounts with no reviewer response
9.Common mistakes
- โRubber-stamping the review without checking each account individually.
- โMissing internal role changes because the focus is only on leavers.
- โLeaving a flagged segregation of duties conflict unresolved after the review closes.
- โNot revoking access promptly once a reviewer marks it for removal.
10.Revision history
| Revision | Date | Description | Reviewed by |
|---|---|---|---|
| 1.0 | September 15, 2026 | Initial release | Ilia Pirozhenko |
This is a template. Adapt it to your organization, equipment and local regulations before use.